Quantcast

Forums | MacLife

You are not logged in.

#1 2003-01-25 2:34 am

oolatec
Member
From: USA
Registered: 2001-08-12
Posts: 4057

Damn, here we go again... Nimda/Code Red pt.2

Check your firewall logs everybody... seems there is a new exploit... UDP port 1434... mySQL instead of IIS this time... ouch...

http://www.dslreports.com/forum/remark, … at#5772389

Offline

 

#2 2003-01-25 2:42 am

Cynic
I've got my propaganda
From: A cold city by a big lake
Registered: 2001-10-19
Posts: 2622

Re: Damn, here we go again... Nimda/Code Red pt.2

How do you "check firewall logs" for the built-in OSX firewall, and what should I look for?

Offline

 

#3 2003-01-25 4:28 am

cyberwolf
Member
Registered: 2001-05-25
Posts: 1460
Website

Re: Damn, here we go again... Nimda/Code Red pt.2

Crazy stuff, UUNet seems to be dead.   eek


to run OS X, you gotta mount your computer on it.

Offline

 

#4 2003-01-25 4:32 am

MTM84
You had me at zugzug
From: P Town, California
Registered: 2000-11-26
Posts: 3393
Website

Re: Damn, here we go again... Nimda/Code Red pt.2

Crazy stuff, UUNet seems to be dead.   eek

http://www.internetpulse.net/1/


I am neither the Alpha or the Omega, I am the instrument of your destruction.
[MA]MTM84
><}}}@>

Offline

 

#5 2003-01-25 4:37 am

Freezer mac
iPod scroll wheel
From: next to a big cold lake.
Registered: 2001-01-06
Posts: 7373

Re: Damn, here we go again... Nimda/Code Red pt.2

ouch looks like the dallas connection is dead


http://www.internetpulse.net/1/UUNet_to_UUNet/

Offline

 

#6 2003-01-25 4:39 am

MTM84
You had me at zugzug
From: P Town, California
Registered: 2000-11-26
Posts: 3393
Website

Re: Damn, here we go again... Nimda/Code Red pt.2

freezer, about 10 minutes ago dallas to sanfran was 1000+!  Seems most ly the Dallas node that is getting hit the hardest.


I am neither the Alpha or the Omega, I am the instrument of your destruction.
[MA]MTM84
><}}}@>

Offline

 

#7 2003-01-25 4:41 am

Freezer mac
iPod scroll wheel
From: next to a big cold lake.
Registered: 2001-01-06
Posts: 7373

Re: Damn, here we go again... Nimda/Code Red pt.2

yeah.... jeez.. that hit fast, didnt it?

Offline

 

#8 2003-01-25 4:51 am

NoExit
NINJ4
From: Surf City USA
Registered: 2001-02-12
Posts: 6250
Website

Re: Damn, here we go again... Nimda/Code Red pt.2

god damn, i hate this hacking crap!! mad  mad  mad


[MA]NoExit|X| - The good man scorns the wicked.

Offline

 

#9 2003-01-25 4:57 am

Freezer mac
iPod scroll wheel
From: next to a big cold lake.
Registered: 2001-01-06
Posts: 7373

Re: Damn, here we go again... Nimda/Code Red pt.2

god damn, i hate this hacking crap!! mad  mad  mad

its cracking, not hacking, nox tongue

Offline

 

#10 2003-01-25 5:12 am

NoExit
NINJ4
From: Surf City USA
Registered: 2001-02-12
Posts: 6250
Website

Re: Damn, here we go again... Nimda/Code Red pt.2

yea but hacking sounds better, just like the moive big_smile


[MA]NoExit|X| - The good man scorns the wicked.

Offline

 

#11 2003-01-25 7:35 am

ukimalefu
4 8 15 16 23 42
Moderator
From: time loop
Registered: 2002-09-09
Posts: 9739
Website

Re: Damn, here we go again... Nimda/Code Red pt.2

are you talking about this?
Internet traffic broadly affected by electronic attack

Chris FOM: Edited to add URL tags

Offline

 

#12 2003-01-25 8:04 am

Gary Patterson
    
Registered: 2000-09-19
Posts: 4732

Re: Damn, here we go again... Nimda/Code Red pt.2

Interesting...

http://news.bbc.co.uk/1/hi/technology/2693925.stm

http://slashdot.org/articles/03/01/25/1 … ml?tid=109

Some quotes from SlashDot...
"This has effectively disabled 5 of the 13 root nameservers."

"This could have been a lot lot harder to filter out. I expect we'll see ThisWorm v2 soon."

"Microsoft released a patch for this 24th July, 2002."

http://www.boredom.org/~cstone/worm-annotated.txt

"SQL is easy to secure, and the guidelines are well known "

"...this (once again) brings to the fore the problem of admins who don't look after their systems/networks..."

http://www.digitaloffense.net/worms/mssql_udp_worm/

... (and so it goes) ...

Well, it seems we've got another case of useless sysadmins who aren't able to maintain patches to products. They're being caught out fully six months after the patch was released from MS. I'm not a big fan of MS, but they seem to be more or less in the clear on this one (why the hole existed in the first place is an issue for another topic).

Still... it seems to have been harmless enough, so it's a good, timely reminder that patches are put out for a reason. Maybe we'll see the slack sysadmins pick up their game now.

Offline

 

#13 2003-01-25 1:59 pm

jasontk
Member
From: San Francisco, CA
Registered: 2001-03-18
Posts: 684
Website

Re: Damn, here we go again... Nimda/Code Red pt.2

should i be worried that the log on my router shows this:
"Unrecognized access from 195.148.254.135:3144 to UDP port 1434"?

Offline

 

#14 2003-01-25 2:01 pm

ShnickyShnack
::: title edited due to Satanic influences :::
From: Rockin' out
Registered: 2001-05-25
Posts: 22237

Re: Damn, here we go again... Nimda/Code Red pt.2

PARANOIA!

I tried logging onto MacAddict, couldn't. Tried MacOSRumors, no dice. Macrumors, nothing. What's all this? Was there some super-juicy rumor? Did Steve Jobs have them all shut down? What's going on? What? What? What?

Aha ... check Yahoo! news. Worldwide Internet slowdown. Messiness. Unpleasantness.

Calm ... relax ... deep breaths ... okay, connecting to MacAddict now ... ahh ... the world is once again as it should be ...


Note: please delete this post.

Offline

 

#15 2003-01-25 2:11 pm

IcePenguin
Cool down
From: Antarctica. Brr.
Registered: 2001-05-16
Posts: 997
Website

Re: Damn, here we go again... Nimda/Code Red pt.2

I couldn't logon to the MAF for like 6 hours. It sucked.

Offline

 

#16 2003-01-25 2:14 pm

ShnickyShnack
::: title edited due to Satanic influences :::
From: Rockin' out
Registered: 2001-05-25
Posts: 22237

Re: Damn, here we go again... Nimda/Code Red pt.2

It's tough, eh? I had to be sedated.


Note: please delete this post.

Offline

 

#17 2003-01-25 2:26 pm

El Lombardo
Master Pixelator
From: Near Montréal
Registered: 2001-02-26
Posts: 695

Re: Damn, here we go again... Nimda/Code Red pt.2

Yes i was being sedated  too !!!
Otherwise it is just unbearable  wink


The surest way to corrupt a youth is to instruct him to hold in higher regard those who think alike than those who think differently.    --Friedrich Nietzsche

MacBook Pro 2.16 - 2GB Ram - 100GB 7200RPM HD

Offline

 

#18 2003-01-25 8:16 pm

Mazer Rackham
Member
From: St. Pete, Florida, United Stat
Registered: 2002-05-03
Posts: 1882
Website

Re: Damn, here we go again... Nimda/Code Red pt.2

I couldn't logon to the MAF for like 6 hours. It sucked.

Same here. I had to entertain myself with the second build of A+ for a couple hours smile


"Early to bed, early to rise makes a man stupid and blind in the eyes." -Mazer Rackham

Offline

 

#19 2003-01-25 8:17 pm

Mazer Rackham
Member
From: St. Pete, Florida, United Stat
Registered: 2002-05-03
Posts: 1882
Website

Re: Damn, here we go again... Nimda/Code Red pt.2

How do you "check firewall logs" for the built-in OSX firewall, and what should I look for?

Same question. No one's answered it...


"Early to bed, early to rise makes a man stupid and blind in the eyes." -Mazer Rackham

Offline

 

#20 2003-01-25 8:27 pm

Twisted Guy
President of the Galactic Confederacy
Registered: 1999-03-28
Posts: 15984
Website

Re: Damn, here we go again... Nimda/Code Red pt.2

I had to be sedated.

[ramones]
20...20...20...24 hours to gooooo, I wanna be sedated.
Nothing to do, nowhere to gooo-ooo-ooo, I wanna be sedated.
[/ramones]


All hail Xenu!
http://imagegen.last.fm/EtherealForest/artists/5/TwistedGuy.gif

Offline

 

#21 2003-01-26 8:31 am

~Coxy
Member
From: Perth, Western Australia
Registered: 2000-04-05
Posts: 8521
Website

Re: Damn, here we go again... Nimda/Code Red pt.2

I couldn't even get to MAF all yesterday. sad

Offline

 

Board footer

Powered by PunBB 1.2.6
© Copyright 2002–2005 Rickard Andersson