Re: MSIISProbes.pm v1.03

2001-10-01 Thread Mike Schienle
On Friday, September 28, 2001, at 08:49 AM, Nick Tonkin wrote: On Fri, 28 Sep 2001, Ask Bjoern Hansen wrote: On Thu, 20 Sep 2001, Mike Schienle wrote: thanks to patches from Brice D. Ruth and others, a new version of MSIISProbes.pm is available at http://www.tonkinresolutions.com

Re: MSIISProbes.pm v1.03

2001-09-28 Thread DeWitt Clinton
On Fri, Sep 28, 2001 at 08:49:22AM -0700, Nick Tonkin wrote: Cache::FileCache defaults to using /tmp for the location of its cache; does the system have /tmp (not sure what Cache::FileCache does if there's no /tmp, hafta look at the code). You can manually override the temp directory by

Re: MSIISProbes.pm v1.03

2001-09-28 Thread Ask Bjoern Hansen
On Thu, 20 Sep 2001, Mike Schienle wrote: thanks to patches from Brice D. Ruth and others, a new version of MSIISProbes.pm is available at http://www.tonkinresolutions.com/MSIISProbes.pm.tar.gz Hi all - Can anyone provide a couple hints on getting this going with Tenon's iTools

Re: MSIISProbes.pm v1.03

2001-09-28 Thread Nick Tonkin
On Fri, 28 Sep 2001, Ask Bjoern Hansen wrote: On Thu, 20 Sep 2001, Mike Schienle wrote: thanks to patches from Brice D. Ruth and others, a new version of MSIISProbes.pm is available at http://www.tonkinresolutions.com/MSIISProbes.pm.tar.gz Hi all - Can anyone provide a couple

[Announce] MSIISProbes.pm v1.03

2001-09-20 Thread Nick Tonkin
Hello, thanks to patches from Brice D. Ruth and others, a new version of MSIISProbes.pm is available at http://www.tonkinresolutions.com/MSIISProbes.pm.tar.gz Changes: v1.03 Added code to get e-mail for the SOA of the host (Brice D. Ruth) Cut the DNS Resolver's timeout to 20 seconds

Re: [Announce] MSIISProbes.pm v1.03

2001-09-20 Thread Paul DuBois
Hello, thanks to patches from Brice D. Ruth and others, a new version of MSIISProbes.pm is available at http://www.tonkinresolutions.com/MSIISProbes.pm.tar.gz Changes: v1.03 Added code to get e-mail for the SOA of the host (Brice D. Ruth) Cut the DNS Resolver's timeout to 20

Re: [Announce] MSIISProbes.pm v1.03

2001-09-20 Thread Jan Jungnickel
Hallo, thanks to patches from Brice D. Ruth and others, a new version of MSIISProbes.pm is available at http://www.tonkinresolutions.com/MSIISProbes.pm.tar.gz Changes: v1.03 Added code to get e-mail for the SOA of the host (Brice D. Ruth) Cut the DNS Resolver's timeout to 20

Re: [Announce] MSIISProbes.pm v1.03

2001-09-20 Thread Nick Tonkin
version of MSIISProbes.pm is available at http://www.tonkinresolutions.com/MSIISProbes.pm.tar.gz Changes: v1.03Added code to get e-mail for the SOA of the host (Brice D. Ruth) Cut the DNS Resolver's timeout to 20 seconds v1.02Moved the URL for info for each worm

Re: MSIISProbes.pm v1.03

2001-09-20 Thread Mike Schienle
On Thursday, September 20, 2001, at 09:41 AM, Nick Tonkin wrote: Hello, thanks to patches from Brice D. Ruth and others, a new version of MSIISProbes.pm is available at http://www.tonkinresolutions.com/MSIISProbes.pm.tar.gz Hi all - Can anyone provide a couple hints on getting

NIMDA worm; MSIISProbes.pm

2001-09-19 Thread Nick Tonkin
Hello, Now that Micro$oft has finally put out some information about their latest trick I have posted a new version of MSIISProbes.pm. Version 1.02 changes include putting the URL to a page containing info about each worm into a PerlSetVar ... this means that once you have configured

Re: NIMDA worm; MSIISProbes.pm

2001-09-19 Thread Bruce Albrecht
Nick Tonkin writes: Now that Micro$oft has finally put out some information about their latest trick I have posted a new version of MSIISProbes.pm. Version 1.02 changes include putting the URL to a page containing info about each worm into a PerlSetVar ... this means that once you have

Re: NIMDA worm; MSIISProbes.pm

2001-09-19 Thread Nick Tonkin
On Wed, 19 Sep 2001, Bruce Albrecht wrote: I was looking at your Apache::MSIISProbes module, and I didn't understand the part about the nimda rewrite rules, mostly because I haven't used the rewrite rules. Do the following rules RewriteCond %{REQUEST_URI} !nimda RewriteCond

MSIISProbes.pm

2001-09-18 Thread Nick Tonkin
PerlSetVar worm_name Nimda /LocationMatch BDuplicates Although rumor has it that CodeRed and other similar worms only attack a given IP once from a given host, experience shows this to be false. You can control the behavior of MSIISProbes.pm when

Re: MSIISProbes.pm

2001-09-18 Thread Nick Tonkin
On Tue, 18 Sep 2001, Emad Fanous wrote: any reason why the private address spaces between 172.16.0.0-172.31.255.255 wasn't in your list of ignored ips? Thanks Emad That came from the original author's CodeRed.pm. But it's considered a configurable variable. ~~~ Nick Tonkin

Re: MSIISProbes.pm

2001-09-18 Thread Ask Bjoern Hansen
On Tue, 18 Sep 2001, Nick Tonkin wrote: I used a real ugly mod_rewrite hack to grab the requests (I didn't want to lump all reqs for root.exe or cmd.exe into the same 'worm') ... I'm sure others can improve on that. (BTW am I right in thinking that RewriteEngine on needs to be specified for

Re: MSIISProbes.pm

2001-09-18 Thread Nick Tonkin
On Tue, 18 Sep 2001, Ask Bjoern Hansen wrote: On Tue, 18 Sep 2001, Nick Tonkin wrote: I used a real ugly mod_rewrite hack to grab the requests (I didn't want to lump all reqs for root.exe or cmd.exe into the same 'worm') ... I'm sure others can improve on that. (BTW am I right in