>Ok, I thought I was not on glue. I am right now rebuilding the server. I
>have moved all the websites off to another server that seems to be
>unaffected by the attacks.
"Seems" may not be good enough. With 1/2 million servers infected, there
are like 100,000 or so people who are telling their bosses "It seems to be
fine". Make sure that they all have the patch. If you aren't sure,
reapply it. Also make sure that they aren't already infected; if so,
disinfect them.
>I have one other server that seems to have this problem every now and
>then but not as bad as the main server.
That almost certainly means that the server is 100% vulnerable to the Code
Reds, and probably already has the back door installed on it.
>I also have seen in the log files
>
>GET /x.ida XXXXXXXX
>GET /default.ida aaaaaaaa
That's what the infected servers will send to yours.
If your machine is patched, you shouldn't have to worry about those. It
just means that someone is trying to attack you -- but doesn't mean they
succeeded. We have several hundred of those in the log files on one of our
servers, but it is running our own web server, and not vulnerable to the
attack.
>I have done so many repatches just incase I missed something but it is no
>good.
If you were infected by any of the newest Code Red's, you may need to do a
complete reinstall. But remember that the presence of the code in the logs
doesn't necessarily mean you were infected.
-Scott
Declude: Anti-virus, Anti-spam and Anti-hijacking solutions for
IMail. http://www.declude.com
Please visit http://www.ipswitch.com/support/mailing-lists.html
to be removed from this list.
An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/