New (More) Annoying Microsoft Worm Hits Net
Here are examples of the requests it's sending:
GET /scripts/..%%35%63../winnt/system32/cmd.exe?/c+dir
GET /msadc/..%255c../..%255c../..%255c/..%c1%1c../..%c1%1c../
..%c1%1c../winnt/system32/cmd.exe?/c+dir
GET /_vti_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir
While writing this story I was hit a total of 4 times, 16 GET attempts per attack. In only 4 minutes. Also of interest, My desktop has now been hit about 500 times today, all from 208.x.x.x IPs. This might be really bad. I still haven't read anything about this anywhere else, so you heard it here first ;)
Update Web servers compromised by this worm apparently attach a "readme.eml" to all web pages served... and due to a bug in IE5, it will automatically execute the file! Yay Internet Explorer!
I heard some Hacker groups where planning cyberwar against Afganistan and Iraq, then they will be needing loads of machines.
Dont know but this could be related.
Quazion.
Well, that was their take on Code Red (and all the other MS viruses), in their press releases, right? "We have saved the internet, and the world from the evil viruses!".
:)
Not a word on who created, not really the problem, but the possibility, as usual.
There was even a term, wasn't there? Something like MSTD - MicroSoft Transmittable Disease or something... anybody remember?
You really are an illiterate half-wit, aren't you? No wonder you post as Anonymous Coward. Are you a actually a stupid adult or just some short-bus kid from special ed?