Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 10 Jul 2002 11:40:07 -0700 (PDT)
From:      Dan Busarow <dan@dpcsys.com>
To:        Duncan Patton a Campbell <campbell@neotext.ca>
Cc:        security@FreeBSD.ORG
Subject:   Re: FYI report: Reflected Distributed Denial of Service Attack
Message-ID:  <Pine.BSF.4.21.0207101129190.49440-100000@java2.dpcsys.com>
In-Reply-To: <200207101828.g6AIS3403268@localhost.neotext.ca>

next in thread | previous in thread | raw e-mail | index | archive | help
On Jul 10, Duncan Patton a Campbell wrote:
> This could be.  But since I nuked /tmp... early on...  The apache
> stuff says it does Windows98, but we have no apache on Windows and ...

The worm generates the DOS, possibly as a side affect of it
trying to infect other machines.  The DOS is directed at the
IP address of the infected machine(s) and continues even after
removing the worm or unplugging the machine.  We had 2 T1's
effectively shut down.

Or it could just be that the win98 box has any one of the many
windows viruses

Dan
-- 
 Dan Busarow                                                  949 443 4172
 Dana Point Communications, Inc.                            dan@dpcsys.com
 Dana Point, California  83 09 EF 59 E0 11 89 B4   8D 09 DB FD E1 DD 0C 82


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.4.21.0207101129190.49440-100000>