I don't know if this is a ruse to get someone to open a virus or not, but here is a message that I recently received: . > I just want to first and foremost say that we are extremely sorry for . > inconvenience the virus that infected our computer in the Morro Bay . > Office has caused. We have been able to fix the problem and I have . > attached a fix to this email if you also accidentally open this virus. . > The email is very basic . > Hi! How are you? . > I send you this file in order to have your advice . > See you later. Thanks . > DO NOT OPEN THE ATTACHMENT!!! . > but please see the information provided by Pac Bell to get a better . > understanding of it. . > > For a complete description of this virus, please refer to the bulletin . > available at http://www.cert.org/advisories/CA-2001-22.html. . > Thank you. There *was* an attachment which required windoze to run, but I had not previously received the virus from the originator of this message. The contradictory nature of this message makes my suspicous mind think that this is a ruse to get the recipient to open the virus. Roger Turk Tucson, Arizona USA Steve wrote: . > On Fri, 3 Aug 2001, Steve wrote: . > > During this round of Code Red, I've been hit 53 . > > times already. 3 times in just the last 5 minutes. . > > Believe it or not, you're being hit too. It's just . > > that your machines don't log that fact. . > Code Red I was spreading at an increasing pace: . > 01 Aug - 15 . > 02 Aug - 23 . > 03 Aug - 30 . > 04 Aug - 36 . > But since Code Red II came out late yesterday, it . > seems to have taken another jump in its ability to . > reach more machines faster. On 05 Aug as of 10:52 am, . > I'd already had 27 hits consisting of 4 Code Red I . > hits and 23 Code Red II hits. . > Code Red II leaves a back door into the compromised . > machine, allowing almost anyone to have root access . > to it. . > http://www.incidents.org/diary/diary.php . > > There IS a MickeyMouseSoft patch for this worm. I . > > suppose after a few months enough people will have . > > downloaded and applied it, that the Code Red furor will . > > die down... but guess what. Another exploit in IIS . > > will be discovered by some other cracker, and the next . > > worm could be even more devastating. . > Wow, and so soon too. The patch for Code Red I is . > neatly sidestepped by Code Red II, so those dedicated . > M$ admins who applied the first patch must now apply . > yet another. It baffles me no end why any webmaster . > or any kind of sysadmin would put up with this . > security-by-patch mentality. . > Of course, being released on the weekend as it was, . > many webmins won't even realize they're compromised . > until Monday morning, giving this worm a really great . > 2-day window of spreading unabated.
