>Ok, I thought I was not on glue.  I am right now rebuilding the server.  I
>have moved all the websites off to another server that seems to be
>unaffected by the attacks.

"Seems" may not be good enough.  With 1/2 million servers infected, there 
are like 100,000 or so people who are telling their bosses "It seems to be 
fine".  Make sure that they all have the patch.  If you aren't sure, 
reapply it.  Also make sure that they aren't already infected; if so, 
disinfect them.

>I have one other server that seems to have this problem every now and 
>then  but not as bad as the main server.

That almost certainly means that the server is 100% vulnerable to the Code 
Reds, and probably already has the back door installed on it.

>I also have seen in the log files
>
>GET /x.ida  XXXXXXXX
>GET /default.ida aaaaaaaa

That's what the infected servers will send to yours.

If your machine is patched, you shouldn't have to worry about those.  It 
just means that someone is trying to attack you -- but doesn't mean they 
succeeded.  We have several hundred of those in the log files on one of our 
servers, but it is running our own web server, and not vulnerable to the 
attack.

>I have done so many repatches just incase I missed something but it is no
>good.

If you were infected by any of the newest Code Red's, you may need to do a 
complete reinstall.  But remember that the presence of the code in the logs 
doesn't necessarily mean you were infected.


                                                            -Scott

Declude: Anti-virus, Anti-spam and Anti-hijacking solutions for 
IMail.  http://www.declude.com



Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/

Reply via email to