Brian <lxy at cloudnet.com> wrote:
> 
> 
> Holy Shit!!!
> 
> As I posted my last message to the list I was tweaking my Code Red page
> to also grep -c access_log for cmd.exe.  The counter was at 507 when I
> wrote the script, two minutes later it was at 535.  This thing is still
> in it's infancy too... prepare for DDoS's :-)
> 
> Hmm.. got 15 while I was writing this.  Keep in mind I'm on an @home
> network so these numbers could be inflated if it's similar to CR2.

Note that the worm tries 16 different URLs at a time.

-- 
 _  _  _  _ _  ___    _ _  _  ___ _ _  __   I have an inferiority 
/ \/ \(_)| ' // ._\  / - \(_)/ ./| ' /(__   complex. But it's not a  
\_||_/|_||_|_\\___/  \_-_/|_|\__\|_|_\ __)  very good one. 
[ Mike Hicks | http://umn.edu/~hick0088/ | mailto:hick0088 at tc.umn.edu ]
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 232 bytes
Desc: not available
Url : http://shadowknight.real-time.com/pipermail/tclug-list/attachments/20010918/0c311eb8/attachment.pgp