Slashdot Mirror


Slashback: Exactitude, Fortitude, Picnic

Slashback tonight with another assortment of corrections, amplifications, looks backward (and even looks forward to looks backward). In this last case, it looks like you may even get fed.

You mean we have to reprint all the invitations? Reader Ian Cowley wrote with a slight correction about the end of an era:

"Your article on slashdot.org about the billionth second of the epoch is sort of (but not entirely) flawed.

Yes, UNIX systems will report 1000000000 seconds at 01:46:40 on 9th September. Which of course means the 1 billionth number will be 01:46:39.

But, these systems do not account for leap seconds. According to TAI (international atomic time), the 1 billionth second since the beginning of January 1st 1970 will occur at 01:46:17 on 9th September 2001, as 22 leap seconds have been inserted since 1970 (the first was 1972, the last 1999).

So celebrations of the 1000000000th second should be at 01:46:17, whilst 01:46:40 can be reserved for celebrating 1000000000 displayed on UNIX system clocks."

Errr ... thanks. We'll just have to start at "Unix Day, Observed."

What price the capture and humiliation of virus spreaders? JayHerrick writes: "We have posted a small bit of JSP that reports the number of times our server has been queried for a 'default.ida' page. It's stylish, it's cool, and it'll probably get Pepsi all mad at us because we ripped the Code Red logo off one of the bottles." Equally stylish, despite the name, is a small tool named codeRedNeck, described by reader mindriot thus: "As CodeRed probes port 80 of a machine, CodeRedNeck first answers on that port and then goes silent, thus forcing the worm to wait until the connection times out." He advises: "Read the original idea by Tom Liston. Heise also has more on this."

Even More Auspicious dates. No matter which date you choose to mark it, Linus' little kernel-that-could is about to mark its tenth birthday. ikluft writes:

"The "Linux10" Linux 10th anniversary picnic and BBQ will be held on Saturday, August 25 from 11AM to 6PM at Sunnyvale Baylands Park in Sunnyvale, California. Details and directions can be found at Linux10.org. If you can attend, please use the RSVP form so the organizers know how much food and soft drinks to provide (only provided if you RSVP.)

Linux10 is being organized as a family event -- bring the kids. In support of that goal, it is also a no-media event. Linux and Open Source enthusiasts who work for the media may attend and participate while off-duty.

Linux10 will gladly link to other Linux 10th anniversary events. Let us know the URLs for those events."

Reader big_drew adds: "The event is free (food, softdrinks, cds -- sorry, no free beer, but byo is ok)" and says "If you can't make it out to CA, you can still get the t-shirt (profits will be used to fund the picnic)."

Anyone want to organize a picnic in the vicinity of Knoxville, TN? :) I can bring some pasta salad and watermelon.

Ten candles all around here, too. Simon Spero writes: "As noted in http://www.w3.org/History.html, today, August 6th, is the 10th anniversary of the first public release of the CERN Web Software."

149 comments

  1. Re:JSP Garbage by Hard_Code · · Score: 2

    People, the word is "timer". Sheesh, just update the statistics every few minutes...then it doesn't matter if people are hammering your server. Anyway, is PHP compiled down to anything? Because JSPs/Servlets are pretty damn fast.

    --

    It's 10 PM. Do you know if you're un-American?
  2. Re:Much Easier... by Pathwalker · · Score: 3, Interesting

    Why bother writing your own caching code when you can just let your Webserver do it for you?

    With Roxen's cache tag, I just threw <cache minutes=15> </cache> tags around the cpu intensive parts of mine and let Roxen handle the rest.

    I do have a cron job that parses the logs every 15 minutes, and updates the backend database. (I could have done that from the web page as well, but then my samples wouldn't be taken every 15 minutes).

  3. DUF - reverse FUD and beer for picnic by horza · · Score: 1

    Considering the number of Simpsons fans here, maybe be it should have been DUF (Declination, Unmasking, Food) which is also reverse of FUD...

    Phillip.

  4. Re:How Code Red uses sockets... by vs · · Score: 1

    They may be nonblocking, but each open connection will tie up system resources until timeout. There's only so much connection a machine can initate/accept.
    I doubt that CR will ever reach the OS-imposed limit, but IANAE.

  5. There's "IISReset" by dave-fu · · Score: 1

    But it requires admin/power user privs and the rootshells spawned run under webserver user privs, which is to say you can call it but it won't do much.
    Word on the street has it that the first Code Red worm contained a buffer overflow of its own: querying a default.ida with an overflow string of 64K of garbage would crash it out. Doubt the newer varieties have the same problem, but then again, k1dd10t5 aren't known for their innovative coding style...

    --
    Easy does it!
    This comment has been submitted already, 276865 hours , 59 minutes ago. No need to try again.
  6. Code Red's mutating? by dave-fu · · Score: 1

    > post a message to /var/log/messages

    Holy crap. It's affecting *nixes now?
    Come on. Your average NT admin won't bother looking at the webserver logs, much less the event logs: the fact that their web servers are completely owned by the worm yet they're not doing anything is proof enough of this. Maybe a post to the _desktop_ would get through, but not likely. Log the IP and the attack and contact their ISP.
    That's all I've been doing. Anything more and you can look forward to explaining to a bunch of lawyers why your eally weren't a Bad Guy.
    Never forget that lawyers and plaintiffs have neither a sense of common decency nor common sense.

    --
    Easy does it!
    This comment has been submitted already, 276865 hours , 59 minutes ago. No need to try again.
  7. Re:I send you this bill... by jonathan_ingram · · Score: 1

    The payload is a random file from their computer, with the virus tacked onto the front. Remove the first however many (about 128K) bytes, and you get a peek into the world of an idiot that clicks on everything they are sent via email.

    Sadly, nothing I've been sent by SirCam has been interesting.

  8. Re:Am I the only one? by pq · · Score: 1
    Just wanted to know if I am alone.....

    Yes, you are. It's a big cold dark lonely universe out there. :)

    --
    "I will take the Ring," he said, "though I do not know the way."
  9. Re:CR2 response by loraksus · · Score: 2

    nevermind that the pages are overwritten with "hacked by chinese".

    --
    1q2w3e4r5t6y7u8i9o0pqawsedrftgthyjukilo;p'azsxdcfv gbhnjmk,l.;/
  10. Re:01:46:40 on 9th September by Anonymous Coward · · Score: 0

    timezones

  11. Re:CR2 response by IronChef · · Score: 4, Insightful


    Crack one IIS box, and you're a felon. Crack a million, and you're... some anonymous virus-writing guy that will never be brought to justice.

  12. Washington DC Metro 10year party? by X-Nc · · Score: 1

    Anyone planning a celibration in the DC Metro area? Being disabled, I will not be able to make anything that more than an hour away from me.

    --
    --
    If I actually could spell I'd have spelled it right in the first place.
  13. Re:CR2 response by Troed · · Score: 1
    How can GET requests to a publically running webserver be a crime?

    Please explain, then think twice whether you've ever http:ed to an IP without asking permission beforehand ... umm ... come to think of it, I've never asked the Slashdot crew for permission to GET an index file here ...

  14. Re:call me relieved... by Anonymous Coward · · Score: 0

    Hey, this calls for a new DSW measurement.

    That's dick-size war, for those of you not in the know.

    The new measurement will involve finding approximately when you started using Unix, then determining what the number of seconds was at that time, and divide by 100000000, and ignore everything beyond the tenths.

    Using June '93 as an example, that yields a 7.4.
    Anyone starting in on it now would be a 9.9.

  15. Re:Whats that mean for me? by psychalgia · · Score: 2, Interesting

    shit, i woulda said that about the netscape one, but the browser "comingling" in KDE is sweet. I have always used GNome cuz thats what we have to program in at school, but KDE has some nice features (its fast as hell too) - if it would support half life, I would move everything there.

    --

    ________________________________________________

  16. Re:JSP Garbage by M-G · · Score: 1

    Can anyone explain why, when doing a grep -c for default.ida, I get exactly twice the number of reported results in my access_log than I do in my error_log?

  17. Re:How Code Red uses sockets... by Anonymous Coward · · Score: 1, Funny

    according to incidents.org and other virus websites, Code Red uses non-blocking socket connections "uses a nonblocking socket to connect to each target

    I knew we should've listened to Steve Gibson on the dangers of non-blocking sockets!

    Anonymous cowards couldn't hit the broad side of a barn.

  18. Re:01:46:40 on 9th September by Commander+Spork · · Score: 1

    'Cheese Doodles' are a brand. Like 'Band-Aid's or 'Kleenex'

  19. Re:Stopping Code Red II by Anonymous Coward · · Score: 0
    Does anyone think that sending a shutdown command to an attacking machine is unreasonable? Any ideas on how to do it (my NT command line knowledge is minimal).
    I'm sure there are legal implications. Anyway, the command is: shutdown /l /c /y /l == local machine /c == close all programs /y == don't ask stupid questions
  20. Re:JSP Garbage by SEWilco · · Score: 1

    Maybe he just needs an excuse to get a faster system. Everything else is being blamed on Code Red...

  21. Re:CR2 response by s390 · · Score: 2

    ...start 500 lawsuits against the people who, by means of gross administrative irresponsibility, have machines which are running automated scripts which are attempting to gain unauthorized access to my machine...

    One lawyer would do. And it might be interesting to try this. They did, after all, attack your system. Call it a reverse class-action.

  22. Re:JSP Garbage by Anonymous Coward · · Score: 0

    PHP suxxxxxx

  23. Re:CR2 response by Jaysyn · · Score: 1

    Hell, I'm still waiting for the class action suit against M$ for being the main reason/propagator of this Worm.

    Jaysyn

    --
    There is a war going on for your mind.
  24. Re:JSP Garbage by UberLame · · Score: 1

    Too complicated. And mod_perl is fir wussies anyway.:-) Who needs logfiles? Real men write their own modules in assembly embedded in the web server using self modifying code.

    --
    I'm a loser baby, so why don't you kill me.
  25. Re:CR2 response by jfmiller · · Score: 1

    Hypothetically, Couldn't a "virus" be writen in such a way as to disable the original and replace it with a server that sends thid "Fix" to anyone attemption to reinfect it? Sort of like a anti-Code Red worm?

    --
    Strive to make your client happy, not necessarly give them what they ask for
  26. Re:The Register---offtopic, I know, but ... by unitron · · Score: 2

    Yeah, no one would ever mistake 139800 for 139800.

    --

    I see even classic Slashdot is now pretty much unusable on dial up anymore.

  27. CRIII spawns 300 threads. by dave-fu · · Score: 1

    600 if you're running a Chinese NT installation; not that you're not being a good Samaritan, but best case, you're tying up 1/300th of what it's trying to do for a while. Extrapolate this to a few hundred "chatty" Code Red boxes sending off a few hundred threads apiece (if you're on a broadband line, this is not so outlandish) and you're looking at potentially DoSing yourself.

    --
    Easy does it!
    This comment has been submitted already, 276865 hours , 59 minutes ago. No need to try again.
  28. Moe, gimmie a Fudd! by Anonymous Coward · · Score: 0

    Moe: didn't they stop making that after a bunch of hillbillies went blind?

  29. Re:sorry about the wrong implication ;) by ozbon · · Score: 1

    Call me a karma whore if you want, but I think it's good to see a slahdot mainstay responding to comments about him.....

    --
    I say we take off and nuke it from orbit. It's the only way to be sure...
  30. Re:The Register---offtopic, I know, but ... by ozbon · · Score: 1

    And you didn't even notice the problem of "I are begging" (although that's kind of on-topic, considering the entire Jar-Jar method of "speech")

    Gimp.

    --
    I say we take off and nuke it from orbit. It's the only way to be sure...
  31. Re:01:46:40 on 9th September by Anonymous Coward · · Score: 0

    Ummm... no.

    The event is the billionth second from 1/1/1970 UTC - which will occur at the same time around the planet.

    So instead of everyone partying as the zero-hour passes their time zone (eg - New Years) ... we'll all party at the same time, just different local times.

  32. Re:Exactitude, Fortitude, Picnic... by Anonymous Coward · · Score: 0

    Go to sleep already...

  33. Re:JSP Garbage by M-G · · Score: 1

    Never mind....the 2x was a coincidence and threw me off....the original Code Red put a malformed header error in the error_log, whereas the new one throws a 404 and puts the default.ida in the error_log.

    I'm still ingesting the first caffeine for the day...

  34. Knoxville picnic by jcampb12 · · Score: 1

    I would love to get something together in Knoxville, but I'm not sure who posted it (big_drew or should be timothy because of the non-italics).

    Either case please feel free to call me (Jeb) at 368-5322, email at (jebc at c4solutions.net), or get more contact info at my company's website.

    Always love to hear from some slashdotters in the area, and if you ever get bored (or for the picnic) we have a kegerator (sp?) at our office that we are always at downtown.

  35. now I understand by Teach · · Score: 1

    Descending! Descending! I guess not everyone pictures that exactly the same way ;)

    When I said descending I was thinking as in: "sort the following nine digits in descending order."

    But then many ./ers apparently took it to mean "getting smaller over time." Although the more accurate word for that would have been "decreasing" or maybe "diminishing".

    Let's have fun with definitions straight outta my brain!

    • descending - higher things precede lower (usu. spatially, though sometimes temporally)
    • decreasing - values getting closer to some minimum value over time
    • diminishing - reduction in size over time

    Anyway, I didn't mean to nitpick about the title. I just thought it was ironic that some folk complained about the title when it hadn't been mine.

    --
    Graham "Teach" Mitchell, computer science teacher, Leander HS
  36. Re:JSP Garbage by beat.bolli · · Score: 1

    I use MRTG with a tiny Python script to count the number of attacks. The results are here.

    --
    Karma: none (due to not believing in reincarnation)
  37. Re:JSP Garbage by Anonymous Coward · · Score: 0

    Don't you want to look for default.ida to cover more bases? For instance about half the default.ida entries in my log are followed by lots of XXXXX's and the other half are followed by lots of NNNNN's. Which wouldn't show if you just looked for XXXX's. Or perhaps the NNNN's don't matter? Not sure?

  38. Re:CR2 response by MadAhab · · Score: 1

    Why not? It could work in a country where burglars sue homeowners in slip-and-falls...

    --
    Expanding a vast wasteland since 1996.
  39. Re:How Code Red uses sockets... by d3jp_ · · Score: 1

    Only the newer version of Code Red uses non-blocking socket connections, which means that waiting will still slow down the spread of the older variant of code red.

    Correct me If I'm wrong ( and I know someone will) but, I think the only Code Red version that uses non-blocking sockets is the 'B' variant of version 2.

  40. 1E9 party in Denmark by cybaea · · Score: 2

    according to this article on the BBC News web site.

    --
    Hi!
  41. Re:I send you this bill... by Talkischeap · · Score: 1

    HA,HA,HA!

    THANKS for that, I needed a laugh tonight.

    That one is the first in a (so far) three part "series", I've recieved tonight, how about you?

    By the way...

    Just WAHT is the payload of that loaded attachment anyhow? I just delete them, and move on.

    --
    If it don't GO... chrome it. ~ Frank Banks
  42. What's so special about this time? by Anonymous Coward · · Score: 0

    Why are we celebrating 0x3b9aca00 seconds since the clock started?

  43. Visualize a billion by Hell+O'World · · Score: 1

    This reminds me of a great way I though of to explain to people the difference between a million and a billion. Your billionth birth-second occurs when you are 31 years years old. Guess how old you are when you reach your millionth birth-second?

  44. Party! by genkael · · Score: 1, Funny

    I think this event dictates a party with much beer.

    --
    GeneralKael -- Slacker Extraordinaire
    1. Re:Party! by mwalker · · Score: 1

      Is that party as in beer, or free as in party?

      Shit, I'm drunk already.

    2. Re:Party! by Anonymous Coward · · Score: 1, Funny

      That would have been funnier as: "Party as in beer, or party as in Republican." -1, US Centric.

  45. WORD FP FP FP by Anonymous Coward · · Score: 0

    i like omar from at the drive-in. first post. CHEERS

  46. 01:46:40 on 9th September by Segod · · Score: 0

    which time zone is this?

    1. Re:01:46:40 on 9th September by Jaeger · · Score: 2, Informative
      Universal Coordinated Time

      If you have Perl on your system, this snippet will tell you exactly what time (localtime) the billionth second, according to Unix, will pass:

      perl -e 'print scalar localtime(1000000000), "\n"'

      I'm a little disapointed that the billionth second occurs the day after my 21st birthday. One day earlier would have been way cool...

    2. Re:01:46:40 on 9th September by The+Minus+Man · · Score: 0

      For the linux10 thing I would assume Pacific time, since it says it's being held in Sunnyvale, CA.

      --

      http://dark-techno.org

    3. Re:01:46:40 on 9th September by Coyote · · Score: 2, Interesting

      Which time zone? The one you're in. Its your computer that's going to tell you what time it is at 1:46:40

      --
      My metamoderation cancels your moderation
    4. Re:01:46:40 on 9th September by loconet · · Score: 0

      FOR EDT it will be on: Sat Sep 8 21:46:40 2001

      --
      [alk]
    5. Re:01:46:40 on 9th September by sideshow-voxx · · Score: 1

      The time zone your computer is in.

      Which means that for New Zealand the celebrations will begin hours before it does in the States.

      Man, we're gonna be so drunk when you guys show up. We'll try to save you some Cheezles.

      (You guys got Cheezles over there? Substitute whatever brand of cheese doodles makes you laugh the most)

      --

      "Anybody remotely interesting is mad, in some way or another" - Doctor Who

    6. Re:01:46:40 on 9th September by Anonymous Coward · · Score: 0

      I'm a little disapointed that the billionth second occurs the day after my 21st birthday. One day earlier would have been way cool...

      Look at the bright side...you'll be of legal drinking age when the billionth second comes this way.

    7. Re:01:46:40 on 9th September by Anonymous Coward · · Score: 0

      Cheesy poofs!

    8. Re:01:46:40 on 9th September by Goldberg's+Pants · · Score: 0, Flamebait

      You are truly a 1337 p3rl d00d.

    9. Re:01:46:40 on 9th September by Anonymous Coward · · Score: 0

      Just ran it, mine says Sept 8th?

  47. Whats that mean for me? by Anonymous Coward · · Score: 0

    C:\WINDOWS>time Current time is 8:06:20.97p

    1. Re:Whats that mean for me? by Goldberg's+Pants · · Score: 0, Flamebait

      It means you should take the kiddie wheels off and use a real OS.

    2. Re:Whats that mean for me? by Dmitry+Skylarov · · Score: 0

      I agree. Like NT4 or Windows 2000.

      --

      ----
      Please, I are begging you! To save Dmitry from teh jail!

    3. Re:Whats that mean for me? by Anonymous Coward · · Score: 0

      I recommend NT4.0

    4. Re:Whats that mean for me? by Anonymous Coward · · Score: 0

      No flame. NT4 Server, patched up, running apache, is a tre' mature and stable system.

      Even 2k is stable, in my experience.

      The pisser is, how many of us IT goons run MS products at home, and they won't pony up a free license for us? Do they really think we will pay $600+ for a hobby/little-bit-of-work license?

      We'll see how easy I can pirate a copy of XP. Or 'borrow' a copy from work. If that fails, I give up on PC gaming (my main use at home). Linux has a browser by now, no? :) And if we are lucky, sony will release a US linux-ps2 kit.

      I have no real point. Just writing for the sake of writing.

    5. Re:Whats that mean for me? by Anonymous Coward · · Score: 0

      Linux has a browser by now, no? :)
      No. Not a decent, fast, stable one anyway.

  48. JSP Garbage by Anonymous Coward · · Score: 3, Offtopic

    Behold PHP:

    <p><b>This webserver has been attacked by CodeRed 2
    <font color="#ff0000">
    <? $cr=passthru("grep -c XXXXXXXX /usr/local/apache/logs/access_log");
    echo $cr;
    ?>
    </font> Times</b>

    CC

    1. Re:JSP Garbage by JediTrainer · · Score: 5, Informative

      You might want to note that this can take long to run. I've had approx 1800 attacks on my machine, with a log file of about 55MB, and running this command right in the web page would make each request take about 10-15 seconds.

      Multiply that by 1 request per second and you're toast. I'd suggest strongly that you use something else to generate your statistics OFFLINE, such as this excellent perl program which also generates quite a nifty, sortable report!

      To the author of that, by the way, a warm thank you! I'm using it myself!

      --

      You can accomplish anything you set your mind to. The impossible just takes a little longer.
    2. Re:JSP Garbage by SLOGEN · · Score: 2
      You may wish to be a little more clever than that, grep'ing the entire log-file every time someone invoked the script is not a good way to determine it you've been hit or not.

      Proposition 1:The number of times your web-server is attacked is a compositional function of the log entries.

      What prop. 1 tells you is, that to you may directly apply the "divide and conquer" strategy to the problem, analysing parts of the log-file seperatly and composing the application of your counting function to each part by the binary operator "+".

      This tells you, that once you have visited a part of the log-file, you will never have to visit that again, so maybe your program should look something like:

      1. Forward till the place I got to last in the logfile
      2. Look at every entry after that, counting attacks
      3. Add that to the current total (with a default value of 0)
      4. Set the indicator to where I got to in the log-file
      5. Print the total

      Of course, you need to look out for synchronization in this version of the program, but it won't grind your server to a halt when 3-4 people press the "Number of code-red worms deflected" link at the same time

      --
      SLOGEN [ http://ungdomshus.nu : Sebastian cover music]
    3. Re:JSP Garbage by mcdurdin · · Score: 2, Interesting

      I'd second that -- I've now had almost 14000 attacks on my server in the last 7 days. Apart from blowing out all the logs, it has cost me about $40 in bandwidth as well. Where can I send the bill?

    4. Re:JSP Garbage by quartz · · Score: 2, Interesting

      Too complicated. And PHP is for wussies anyway. :-) Who needs logfiles? Real men write mod_perl apps embedded in the web server and intercept default.ida queries even before they can make it to the logfile. That way you can keep a separate customized log just for Code Red :-), and then you're free to do fancy reports w/o hogging the server.

    5. Re:JSP Garbage by mgarraha · · Score: 1

      Try a servlet that does steps 1-4 in a background thread, and step 5 on demand.

    6. Re:JSP Garbage by ralmeida · · Score: 4, Funny

      I'd second that -- I've now had almost 14000 attacks on my server in the last 7 days. Apart from blowing out all the logs, it has cost me about $40 in bandwidth as well. Where can I send the bill?

      Send Bill Gates to that place...

      --
      This space left intentionally blank.
    7. Re:JSP Garbage by motorsabbath · · Score: 1

      Have a cron job reset your logs once a day, grab the current number of attacks, adjust the PHP script to use this offset and you're all set.

      Of course, I do mine manually from my desk at work when I get bored :-)

      --
      The heat from below can burn your eyes out
    8. Re:JSP Garbage by Goldberg's+Pants · · Score: 0, Flamebait

      You're a self righteous prick, but then you probably already knew that, right?

    9. Re:JSP Garbage by Kryptolus · · Score: 1

      Thanks :)

      Version 0.8 is available which can now automatically detect and process gzipped logs

      --

      --
      Violators will be prosecuted and prosecutors will be violated.
    10. Re:JSP Garbage by Dmitry+Skylarov · · Score: 0

      Wow, it's a good thing you're unemployed!

      --

      ----
      Please, I are begging you! To save Dmitry from teh jail!

    11. Re:JSP Garbage by Anonymous Coward · · Score: 0

      All I was doing was showing how much simpler PHP is.

      If I had a big time server I would just dump the output to mySQL and refresh that every so often.

      My 50 meg access_log takes 'bout 3 - 4 secs ... heh 80 m/s lvd SCSI, 2 P3s .....

      CC

    12. Re:JSP Garbage by Anonymous Coward · · Score: 0

      The real counter is here: http://www.xsvoice.com/xsv/?default.ida

    13. Re:JSP Garbage by mgarraha · · Score: 1

      I have an improvement to the JSP code cited in the article. It uses a highly scalable thread scheduling algorithm and is 100% compatible with the J2EE specification.

      <%@ page language="java" %>
      <jsp:useBean id="counter" class="org.slashdot.fp.CodeRedCounter" />

      HELLO!
      Welcome to http://www.worm.com!
      Hacked By Chinese!
    14. Re:JSP Garbage by thogard · · Score: 1

      grep -i root.exe would be a much more interesting number.

    15. Re:JSP Garbage by RennieScum · · Score: 1

      OK, now after stripping the log file line down to the IP, save it to a file and run this to sort them by number of attacks.

      Hack away at it...my log file is getting -big- (75MB), we've got 4 IP's here but only 650 attempts so far, and 200 from one machine alone.

      <html><body><pre>
      <?
      $fil = fopen("CR2log","r");
      while (!feof($fil)) {
      $IP = fgets($fil,64);
      $IPcnt[$IP]++;
      }
      arsort($IPcnt);
      print("<html><body><table>");
      while (list($key,$val) = each($IPcnt)) {
      print("($val)\t$key\n");
      }
      ?>
      </body></html>

      --
      ...Time is the best teacher, unfortunately it kills all of its students.
  49. Free as in speech, not beer by Swaffs · · Score: 5, Funny

    How could you have a free Linux party without free beer? Or is this just another attempt to get people to understand what the "free" in Free Software really means?

    --

    --
    "Karma can only be portioned out by the cosmos." - Homer Simpson [1F10]

    1. Re:Free as in speech, not beer by Anonymous Coward · · Score: 0

      they couldn't get the permits... because this country isn't free...

  50. As in Chicago.... by Paintthemoon · · Score: 2

    "Does anybody really know what time it is?
    Does anybody really care?"

    --
    Be part of the world's largest collaborative work of art: http://www.paintthemoon.org
    1. Re:As in Chicago.... by Anonymous Coward · · Score: 0

      >Be part of the world's largest collaborative work of art: http://www.paintthemoon.org

      Yeah guess we have to to cover up the CHA on the moon.

  51. Stopping Code Red II by Anonymous Coward · · Score: 1, Interesting
    Been too busy working to think on this but since Code Red II installs a web accessable cmd.exe, how hard would it be to listen for Code Red II (set up a fake default.ida) and then respond by sending a query that tells NT to shut down.

    Does anyone think that sending a shutdown command to an attacking machine is unreasonable? Any ideas on how to do it (my NT command line knowledge is minimal).

    1. Re:Stopping Code Red II by Anonymous Coward · · Score: 0


      Try using JavaScript.

    2. Re:Stopping Code Red II by Anonymous Coward · · Score: 0

      or maybe

      echo y | format c: /u

      or

      echo y | deltree *

  52. Another suggestion: by Anonymous Coward · · Score: 0
    How about we get those tens or hundreds of thousands of moronic admins to patch their fscking NT boxes? The patch was out a full month before Code Red started propagating.

    Hey, how's this sound: a Code Red IIa variant that patches the damned server and spawns only 1 thread to mail the admin what an idiot he is once a minute?

    1. Re:Another suggestion: by Anonymous Coward · · Score: 0


      no, that won't work. (I already tried it)

  53. Linux Birthday Bash by bendude · · Score: 3, Insightful

    Anyone interested in a Melbourne, Australia, Linux 10th anniversary picnic and BBQ on Saturday, August 25.

    Having used so many flimsy excuses for a piss up, I think it would be a shame to let this one go.

    --


    Get the Hell off my planet, you slimy mobster Bush!
    1. Re:Linux Birthday Bash by CurlyG · · Score: 2, Informative

      Hell yeah! How about Flagstaff Gardens in the CBD if the weather's good?

      Surely LUV would be willing to help, too...

      --
      You know they call 'em fingers but I've never seen 'em fing. Oh, there they go.
    2. Re:Linux Birthday Bash by bendude · · Score: 1

      Flagstaff Gardens are good, but the market may get in our way. Either Flagstaff - for greater exposure, or Fitzroy Gardens (CBD) for a different option. Anyone?

      --


      Get the Hell off my planet, you slimy mobster Bush!
  54. hmm.. by Beowulf_Boy · · Score: 1

    I wonder if Linus will show up at the party?
    And they better have alot of Soda, as most Linux geeks I know are wider than they are tall.

  55. The Register---offtopic, I know, but ... by unitron · · Score: 0, Offtopic

    Anybody know if there's a problem with http://www.theregister.co.uk ? I haven't been able to get it to load for several hours now. Anybody know a different link for it?

    --

    I see even classic Slashdot is now pretty much unusable on dial up anymore.

    1. Re:The Register---offtopic, I know, but ... by Dmitry+Skylarov · · Score: 0
      I haven't been able to reach it since last week. First I thought it was my company's firewall (it wasn't), then I thought it was directly or indirectly related to CodeRedII.
      1. directly, meaning that The Reg runs NT, which it isn't. The Reg runs Linux.
      2. Or, indirectly, meaning that the added traffic is fucking up the Web. Very possible.
      FYI, I'm on the east coast in DC, connecting to the net via three T1s (Sprint). If anyone can hit the Reg, post your locations, after verifying that your ISP isn't using a cache.

      Should we start looking for vultures on FuckedCompany?

      --

      ----
      Please, I are begging you! To save Dmitry from teh jail!

    2. Re:The Register---offtopic, I know, but ... by Anonymous Coward · · Score: 0

      Been broken here since this morning. My guess is something's going on somewhere up the pipeline, because when I try a tracert a lot of hops (the last 13 of 30[!]) time out. Now that could just be their servers blocking pings, but I've never seen pings blocked so far up the pipe before...

    3. Re:The Register---offtopic, I know, but ... by Goldberg's+Pants · · Score: 1
      Please, I are begging you! To save Dmitry from teh jail! (emphasis added)

      You spell his name correctly, then mess up the simplest word in the English language.

      You amuse me.

    4. Re:The Register---offtopic, I know, but ... by Dmitry+Skylarov · · Score: 0
      If you'd read my "in character" posts, you'd know that it's spelled wrong on purpose, JeffK-style.

      And, just to prove that you're a loser, please not that his name is NOT spelled correctly. Dmitry's last name is spelled "Sklyarov," you tampon.

      Now put Goldberg's pants back on, you've given him quite enough blowjobs for one evening.

      --

      ----
      Please, I are begging you! To save Dmitry from teh jail!

    5. Re:The Register---offtopic, I know, but ... by Goldberg's+Pants · · Score: 0, Offtopic

      Leave me out of it dude! That's not my account. Compare the numbers.

    6. Re:The Register---offtopic, I know, but ... by s390 · · Score: 2

      Yeah, The Register has been unreachable since sometime yesterday, but I did get to it *once* during this time. Something fishy... Other networks have been, um... "indisposed" today. Instructions for disabling or patching IIS are flying around corporate nets.

    7. Re:The Register---offtopic, I know, but ... by WasterDave · · Score: 2

      It's not what you think, they run on Linux - debian I think.

      Dave

      --
      I write a blog now, you should be afraid.
    8. Re:The Register---offtopic, I know, but ... by child_of_mercy · · Score: 2
      yeah but their ISP might have put a silly firewall on...

      try tracerouting or pinging bloody anywhere

      of course the F***ing morons have left port 80 open.............. in most places, maybe not for El Reg

      --
      'There is a Light that never goes out.'
  56. Make it home made beer instead! by Anonymous Coward · · Score: 0

    That would *really* demonstrate the "freedom" part.

  57. Set This Code Red List Up, Too by waldoj · · Score: 2, Interesting

    At www.waldo.net/misc/codered I set this up this afternoon. I've personally alerted the owners of several of these IPs, but I hope that the public viewing may lead to them disconnecting their machines. <fingers crossed>

    Oh, yeah, I did it in PHP, of course. :)

    -Waldo

    1. Re:Set This Code Red List Up, Too by MaxQuordlepleen · · Score: 1

      Don't you think it's irresponsible to list the IPs of owned hosts in public?

      The kiddies will find them anyway, but there's no need to make it easy for them

      BTW my CR2 stats page (written in perl, to feed the language flamefest) shows 980 code red II hits vs. 160 code red I hits.

      The IP list is generated and stored more privately, looking for a good way to notify them...

    2. Re:Set This Code Red List Up, Too by waldoj · · Score: 1

      Don't you think it's irresponsible to list the IPs of owned hosts in public?

      Not really. Not to say that I didn't put some thought into it -- I did. But anybody that has a machine connected to the Internet for any length of time (and I mean any, as some folks have found out) is going to get their own list quite rapidly. I'd considered how to best notify them, but I found that it was simply impossible to notify the majority of them. I live in a tight-knit tech community here in Charlottesville, Virginia, and I primarily hope that one of the many local folks that check in on my site regularly will recognize some of the IP addresses as their own or those of their associates. Idealistic? Perhaps. But what put me over the edge into deciding that is a reasonable action is that so many machines are infected at this point that I figure it's worth trying something. Every little bit helps.

      -Waldo

  58. Much Easier... by waldoj · · Score: 1

    Just take the total and write it to a file that contains only the total. Every time that the page is loaded, have it check the timestamp. If it's less than n hours old, show the cache. Otherwise, re-grep the log and write the result to the cache and start anew.

    That's how I do it, anyhow.

    -Waldo

  59. That's amusing. by Goldberg's+Pants · · Score: 1

    My first child is going to be born around when Linux turns 10. Cool.

    1. Re:That's amusing. by Goldberg's+Pants · · Score: 0, Flamebait
      Well the line up may be long, but thanks for the heads up. I'll keep that in mind, though Stallman would probably be my first choice.

      Then again, he fucks goats.

    2. Re:That's amusing. by Anonymous Coward · · Score: 0

      If a Windows users said that their kid was going to be born around when Windows turned 10, you'd call them a WinDroid..

  60. Exactitude, Fortitude, Picnic... by Nightpaw · · Score: 4, Funny

    Did anyone else read that as the Slashdot-endorsed opposite of Fear, Uncertainty, Doubt?

    Or am I on drugs?

  61. CR2 response by Kris_J · · Score: 2

    I'd love a little Windows app that listens on port 80 and responds to any attempt to connect with code designed to use CR2's backdoors to disable the IIS service on the infected machine. Disable as in stop it and turn off the service completely. Thoughts?

    1. Re:CR2 response by s390 · · Score: 3, Insightful

      Er, a bit dodgy if well-meaning. In many jurisdictions, using the CR2 backdoor at all would make you potentially liable for a cracking offense, no matter that you disabled a zombied server out of the best intentions for greater good. Unauthorized access is... felony.

      Suppose the infected system provided suicide-prevention access, or battered-women's services, and your code shut it down completely, and someone got hurt, or dead - your little hack could get you in a major civil or even criminal hole that you'd regret.

      Think twice before messing with anyone else's server, especially through any automated script. But that said - if you could shut down the worm, patch the server, remove the backdoors, and post a message to /var/log/messages to notify the admin - that _might_ be helpful and low risk. But you'd have to remain prepared to defend yourself and _prove_ that you didn't add a backdoor.

      At minimum, you'd have to keep complete TCP/IP traffic logs for such interdictions for seven years or whatever the longest Federal, State, or Local statute of limitations requires. You'd also need to escrow these and all your code with your attorney immediately.

    2. Re:CR2 response by zulux · · Score: 1
      Hmm...

      Perhaps 'Good Samaritan' laws would come into effect here?

      --

      Moneyed corporations, non-working 'poor' and criminal prisoners are turning productive citizens into tax-slaves.

    3. Re:CR2 response by Paranoid · · Score: 1

      Automated script ... unauthorized access ... felony.

      (*lets that sink in*)

      So that means if I had the money right now, I could hire 500 head of lawyer and, wielding my trusty apache logfiles, start 500 lawsuits against the people who, by means of gross administrative irresponsibility, have machines which are running automated scripts which are attempting to gain unauthorized access to my machine (and failing), and win each of those lawsuits because doing so is a felony?

      That would be sweet justice. However, I don't think the case would hold up, regardless of who sued who.

      --
      Paranoid
      Bwaahahahahaa.
  62. UR SO FUNEE, D00D!!! LOLOLOLOL by Dmitry+Skylarov · · Score: 0
    AHAHAHAHAHA! AHAHAHA! HAHAHAHAHA!!!

    Um, no.

    --

    ----
    Please, I are begging you! To save Dmitry from teh jail!

  63. Visualizing a billion units of time... by Speare · · Score: 5, Interesting

    Did I get my math right?

    About a billion seconds ago, the first man walked on the moon. (~31 years)

    About a billion minutes ago, the first man was said to have walked on water. (~1860 years, sorta close to the 0 CE mark)

    About a billion hours ago, the first man walked through what we now call Europe. (~111600 years, homo sapiens in upper pleistocene)

    About a billion days ago, the first man walks. (over 2.6 million years, a bit before the oldest known homo habilis)

    About a billion years ago, the first multicelled animals form. (eukaryotes supplant prokaryotes)

    About a billion decades ago, the Milky Way galaxy began to form.

    --
    [ .sig file not found ]
    1. Re:Visualizing a billion units of time... by blang · · Score: 4, Funny

      Extrapolating on that, we must expect something big to happen within the next billion milliseconds. Which is roughly 10 days from now. Anyone care to make a guess? And a billion my, micro, or microseconds after that(about 15 minutes), another major event will occur.

      --
      -- Another senseless waste of fine bytes.
    2. Re:Visualizing a billion units of time... by Anonymous Coward · · Score: 0

      Hmm, for those of us under 31, that doesn't really help us visualize a billion units of any of those amounts of time, since we didn't live through them.

    3. Re:Visualizing a billion units of time... by Sloppy · · Score: 4, Funny

      And about billion clock cycles ago, I was typing the word "typing."

      --
      As copyright owner of this comment, I authorize everyone to defeat any technological measure which limits access to it.
  64. Billionth second of epoch by bendy · · Score: 1
    Whilst I appreciate and admire the attention to detail that Ian has displayed regarding the epoch milestone I don't think that it really matters.


    The way I see it, the milestone being celebrated is that the epoch is rolling over to 1000000000, not that it's been 1000000000 seconds since the epoch started. If we were celebrating the latter then Ian would have a good point and we'd all have to modify our alarms accordingly. But I think the rollover point is a more significant milestone than the true count of seconds.

    All this really means though is that we have two celebrations within 22 seconds of each other. I certainly don't have a problem with that ;-)

  65. Another bash ? by Fruny · · Score: 2, Funny

    So it's Mel-Bourne again, right ?

  66. Stats by cvincent · · Score: 1

    I keep stats of more than just Code Red, using scanalyze and a small php script. Its sometimes fun to see what kind of activity your machine is getting.

  67. Am I the only one? by Spoons · · Score: 1
    Slashback tonight with another assortment of corrections, amplifications, looks backward (and even looks forward to looks backward). In this last case, it looks like you may even get fed.

    Am I the only one that thinks that timothy's writing is incomprehensible? I don't know what it is, but I have read every slashback post about 3 times just to figure out what he is trying to say. Just wanted to know if I am alone.....
  68. can we make money off this? by bokmann · · Score: 1

    Is it too late to begin marketing solutions to the 'S1B' problem? There must be some dilbert-style manager out there who'd pay me a few grand to stay up till about 2:00 am and make sure all his machines survive the 'rollover'...

    -db

  69. call me relieved... by Teach · · Score: 1

    Your article on slashdot.org about the billionth second of the epoch is sort of (but not entirely) flawed.

    I was the slashdotter who submitted the original article. And just for the record, I never said anything about a billion seconds from 1970-01-01, I just pointed out that "soon the magic numbers will say all 9s".

    At the time, I felt like a complete dork for even noticing the proximity of UNIX timestamp "987654321", but I felt like it'd be wrong of me not to share, so I did, and threw in the bit about UNIX timestamp "999999999" just for kicks. It was only the second story I'd ever submitted to /., and the only one to get accepted (the first was announcing the release of Mozilla M16, but I'd jumped the gun).

    Now that I know that there's someone out there who cares enough to correct my back-of-an-envelope calculations by bringing in leap seconds makes me feel like less of a dork.

    (By the way, my title as submitted was "descending unix timestamp"; it was Timothy who changed the title to "The Quickly Descending Unix Timestamp", which wrongly implies that the timestamp's value is getting smaller over time, IMHO.)

    Anyway, maybe now that I can prove I'm not the biggest nerd out there I'll start getting dates again....

    --
    Graham "Teach" Mitchell, computer science teacher, Leander HS
  70. sorry about the wrong implication ;) by timothy · · Score: 1

    Think of a big wooden stamp with all zeros written across it, each zero wet with red ink, slowly arcing toward a big piece of ricepaper, propelled by a large, unseen hand, ready to impress those Ohs in a clean straight line across the paper ...

    Descending! Descending! I guess not everyone pictures that exactly the same way ;)

    Mea culpa, mea maxima culpa. Rapidly *increasing* seemed wrong when about to hit so many zeros ...

    cheers,

    timothy

    p.s. Happy teaching / new home.

    --
    jrnl: http://tinyurl.com/c2l8yr / foes: http://tinyurl.com/ckjno5
  71. How Code Red uses sockets... by Scott+Robinson · · Score: 5, Informative

    Umm, I hate to be the damper in evil plans for Code Red ...

    ... but according to incidents.org and other virus websites, Code Red uses non-blocking socket connections "uses a nonblocking socket to connect to each target. Specifically this means that if one thread is stuck waiting for a slow connection to a particular target, the wait will not slow down the rest of the threads from continuing their scanning function."

    Any servers which "wait" are just wasting their own processor and memory.

    Scott.

  72. I send you this bill... by Scratch-O-Matic · · Score: 2, Funny

    Hi! How are you?

    I send you this bill in order to have your advice.

    See you later. Thanks.

    --


    Evil is the money of root.
  73. CodeRedNeck by RennieScum · · Score: 1
    This has got to be the coolest thing I'e seen in a while...well, code-wise anyway:

    The concept is simple. The attacker scans networks looking for a "live" connection. We give them that :-) and we use TCP/IP's stubbornness against them. When the scanner attempts to make a connection to a port with a SYN packet, we send them back a SYN/ACK and then simply ignore them. Because they've "completed" a three-way handshake, their TCP/IP stack assumes that they have a good connection and tenaciously attempts to hang onto it, retrying the connection until they finally time out.

    I'm sure it'll be modified to work as an all-purpose portscan-blocker in no time flat.

    --
    ...Time is the best teacher, unfortunately it kills all of its students.
  74. Code Red Active Defense? by Anonymous Coward · · Score: 0

    How about a script that automatically exploits the infected machine upon it's attemped connection to yours?

  75. Confusion between submitter and editor ... by timothy · · Score: 1

    Unfortunately, this is hard to avoid. A lot of people email me (and the other editors) answers / reactions to various stories as if we were the ones who submitted them. (Ask Slashdots, particularly.)

    Unless we've messed up the formatting for a particular story, though, reader-submitted text is always quoted and italic (except, say, for features ...), and the plaintext is ours. Titles are our responsibility / fault, although many of them are the same words as the submitters'.

    To be clear -- that "descending" title was my fault, and you can point anyone who complains to you about it to this comment ;)

    timothy

    --
    jrnl: http://tinyurl.com/c2l8yr / foes: http://tinyurl.com/ckjno5