I checked out a couple of boxes in the 24.x.x.x range that had bounced port 80 requests off of my firewall. They were running Win2K/IIS and had their index.htm replaced with a black page whose source contained derogatory comments concerning the "USA Government" and "PoizonBOx". Is this a function of the worm or were they 0wned post-infection?
I checked out a couple of boxes in the 24.x.x.x range that had bounced port 80 requests off of my firewall. They were running Win2K/IIS and had their index.htm replaced with a black page whose source contained derogatory comments concerning the "USA Government" and "PoizonBOx". Is this a function of the worm or were they 0wned post-infection?