Re: rlx blade server attacked

2002-09-22 Thread Tunggul A Siswoyo
On Fri, Sep 13, 2002 at 08:45:32PM +0200, Michael Renzmann wrote: Hi Jason. Jason Sopko wrote: The Apache worm you're infected with was posted on bugtraq earlier today. It exploits mod_ssl and can be identified by doing a ps -ax | grep bugtraq (it runs as the name .bugtraq). The source for

Re: rlx blade server attacked

2002-09-22 Thread Tunggul A Siswoyo
On Sun, Sep 22, 2002 at 08:13:39PM +0700, Tunggul A Siswoyo wrote: Is debian woody vulnerable to this exploits? AFAIK i didn't see any recent DSA (except DSA-135) mentioning this hole. Sorry, my stupidity :) didn't see other posts before asking please just ignore my previous post

Re: rlx blade server attacked

2002-09-22 Thread Tunggul A Siswoyo
On Sun, Sep 22, 2002 at 08:13:39PM +0700, Tunggul A Siswoyo wrote: Is debian woody vulnerable to this exploits? AFAIK i didn't see any recent DSA (except DSA-135) mentioning this hole. Sorry, my stupidity :) didn't see other posts before asking please just ignore my previous post

rlx blade server attacked

2002-09-13 Thread Michael Renzmann
Hi all. The rlx blade server rack (better: the management blade) where my own server is located in has been attacked. I phoned to my ISP some minutes ago, and he described that there was a huge packet storm fired from the internet towards the management blade. He described that there were

Re: rlx blade server attacked

2002-09-13 Thread Jason Sopko
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Michael Renzmann wrote: | Hi all. | | The rlx blade server rack (better: the management blade) where my own | server is located in has been attacked. I phoned to my ISP some minutes | ago, and he described that there was a huge packet storm fired

Re: rlx blade server attacked

2002-09-13 Thread Michael Renzmann
Hi Jason. Jason Sopko wrote: The Apache worm you're infected with was posted on bugtraq earlier today. It exploits mod_ssl and can be identified by doing a ps -ax | grep bugtraq (it runs as the name .bugtraq). The source for it is here: http://dammit.lt/apache-worm/apache-worm.c Thanks a lot