LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Non-*NIX Forums > General
User Name
Password
General This forum is for non-technical general discussion which can include both Linux and non-Linux topics. Have fun!

Notices


Reply
  Search this Thread
Old 06-24-2003, 08:42 PM   #1
green_dragon37
Member
 
Registered: Oct 2002
Location: Lower Alabama
Distribution: Slackware, OpenBSD 3.9
Posts: 344

Rep: Reputation: 31
Question Code Red--Should I Even Bother?


Recently, I have been seeing tons of evidence pointing towards a Code Red infected machine in my Apache logs, and the question I have to ask is:

Should I even bother trying to track down the admins of the server in question, so as to notify them of the infection? Or, is it just a big waste of time? I have already tracked down the offending IP to the speakeasy network. Should i just mail abuse@speakeasy.net , or should I try to take it further in than that??

Any opinions will be appreciated.

Ian

Last edited by green_dragon37; 06-24-2003 at 10:08 PM.
 
Old 06-24-2003, 09:03 PM   #2
green_dragon37
Member
 
Registered: Oct 2002
Location: Lower Alabama
Distribution: Slackware, OpenBSD 3.9
Posts: 344

Original Poster
Rep: Reputation: 31
My correspondence - Part 1

So, I went ahead and fired off an email to speakeasy, and I was surprised at the response. the correspondence follows:

Quote:
To: abuse@speakeasy.net
Subject: Possible Code Red Worm infected server

Greetings,

Lately I have been noticing symptoms of code red infected servers in my
logs, particularly, over 50 such requests from an IP in your
network(216.231.41.198). I just would like to bring this to your
attention, and request that you look into this. I have included one such
line from my logs. I am not worried about being infected, as I run Apache
on Linux, but I find it a nuisance to try to sift through my logs with
this garbage in my way.

If I can help you in any way, by providing more logs, etc., please
feel free to contact me.

Regards,

Clifton I Barr

---
216.231.41.198 - - [22/Jun/2003:04:44:34 -0400] "GET
/default.ida?XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
X%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u68
58%ucbd3%u7801%u9090%u9090%u8190%u00c3%u0003%u8b00%u531b%u5
3ff%u0078%u0000%u00=a HTTP/1.0" 404 362 "-" "-"
And the reply:

Quote:
From abuse@speakeasy.net Tue Jun 24 21:01:04 2003
Date: Tue, 24 Jun 2003 18:47:51 -0700 (PDT)
From: abuse@speakeasy.net
To: cibarr@centuroncomputers.staticcling.org
Subject: [Incident 030624-000273] Possible Code Red Worm infected server


Thank you for contacting Speakeasy Network!

Speakeasy Members: Please DO NOT reply to this email, as we will not be
able to respond to it or provide additional support.

We will update this with status or resolution via the Customer Support
tool in TAC. If you need to make updates or close your support request,
please go to MySpeakeasy (http://www.speakeasy.net/myspeak). Select
Customer Support from the navigation menu and go to the My Info tab to
view.

If your original request was made via email to any of the below addresses,
you can continue to correspond or add information to your inquiry by
sending a copy of this message to the email address originally contacted
with updated information:

abuse@speakeasy.net
dsl@speakeasy.net
ispswitch@speakeasy.net
collections@speakeasy.net

Please keep the Question Reference number in the subject line of that
email.


For your convenience, we have included a summary of the inquiry
details below.

Thanks!

The Speakeasy Crew



Subject
---------------------------------------------------------------
Possible Code Red Worm infected server

Suggested Answer
---------------------------------------------------------------
At 06/24/2003 06:47 PM we wrote -

Greetings,

According to the headers you sent us, this spam is not going through Speakeasy's mail servers. We therefore have no control over this spam. We suggest you contact the service provider that is indicated in the headers, as this spam is going through their mail server.

They should be able to help you resolve this problem of unsolicited email.

Network Security Department
Speakeasy, Inc.
206.728.9770
800.556.5829
abuse@speakeasy.net

Question
---------------------------------------------------------------
Greetings,

Lately I have been noticing symptoms of code red infected servers in my
logs, particularly, over 50 such requests from an IP in your
network(216.231.41.198). I just would like to bring this to your
attention, and request that you look into this. I have included one such
line from my logs. I am not worried about being infected, as I run Apache
on Linux, but I find it a nuisance to try to sift through my logs with
this garbage in my way.

If I can help you in any way, by providing more logs, etc., please
feel free to contact me.

Regards,

Clifton I Barr

---
216.231.41.198 - - [22/Jun/2003:04:44:34 -0400] "GET
/default.ida?XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
X%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u68
58%ucbd3%u7801%u9090%u9090%u8190%u00c3%u0003%u8b00%u531b%u5
3ff%u0078%u0000%u00=a HTTP/1.0" 404 362 "-" "-"




Question Reference #030624-000273
---------------------------------------------------------------
Product: Tech Support
Sub-Product: Security and Abuse
Contact: cibarr@centuroncomputers.staticcling.org
Date Created: 06/24/2003 06:30 PM
Last Updated: 06/24/2003 06:47 PM
Elapsed Time: 0 Minutes
Status: Closed
OS:




Tell me what you think.

Ian
 
Old 06-24-2003, 09:57 PM   #3
green_dragon37
Member
 
Registered: Oct 2002
Location: Lower Alabama
Distribution: Slackware, OpenBSD 3.9
Posts: 344

Original Poster
Rep: Reputation: 31
Correspondence - Part 2

My reply follows:

Quote:
To: abuse@speakeasy.net
Subject: [Incident 030624-000273] Possible Code Red Worm infected server

To elaborate:

I am not, as you reply suggests, receiving any spam e-mail. In fact I am
merely notifying you of a server on your network that is infected with the
Code Red worm, which infects Microsoft IIS servers, which in turn attempt
to infect other servers. I am merely requesting that you contact the
owner of the IP address, or put me in contact with the owner.

Regards,

Clifton I Barr
I am waiting for a reply from speakeasy.

Ian

Last edited by green_dragon37; 06-24-2003 at 10:13 PM.
 
Old 06-24-2003, 10:38 PM   #4
mcleodnine
Senior Member
 
Registered: May 2001
Location: Left Coast - Canada
Distribution: s l a c k w a r e
Posts: 2,731

Rep: Reputation: 45
Before you go pounding on their door you would be wise to make sure all your ducks are in a row. ie: does your ISP allow you to run http/mail servers on your network?

I am curious about how far they (Speakeasy) are willing to go to enforce their terms on their own customers.
 
Old 06-25-2003, 04:06 AM   #5
MasterC
LQ Guru
 
Registered: Mar 2002
Location: Salt Lake City, UT - USA
Distribution: Gentoo ; LFS ; Kubuntu ; CentOS ; Raspbian
Posts: 12,613

Rep: Reputation: 69
Let's hope not too far, for (I'm sure) some of our users probably run "httpd" servers from their lines "unofficially"

But I'm curious as well, please keep us posted

Cool
 
Old 06-25-2003, 04:23 AM   #6
mcleodnine
Senior Member
 
Registered: May 2001
Location: Left Coast - Canada
Distribution: s l a c k w a r e
Posts: 2,731

Rep: Reputation: 45
Sorry MasterC - I should clarify. I'm really interested in how far this complaint gets on the other end (where the nimda/codered bxes are). But yeah I don't want to see an LQ member in hot water either
 
Old 06-25-2003, 10:55 AM   #7
green_dragon37
Member
 
Registered: Oct 2002
Location: Lower Alabama
Distribution: Slackware, OpenBSD 3.9
Posts: 344

Original Poster
Rep: Reputation: 31
Well, my ISP is probably the best out there. Their TOS says that I can do whatever I like, just as long as it's not illegal. They even go as far as state on their site that the Static IP that I pay $10/month for can be used for "Online gaming, VPN, and running a server."

Ian
 
Old 06-25-2003, 11:01 AM   #8
emence
Member
 
Registered: Jun 2003
Location: Springfield, MO
Distribution: RedHat/Slackware
Posts: 81

Rep: Reputation: 15
You could try to DDOS the ip, I imagine that would wake the admins at Speakeasy up.
 
Old 06-25-2003, 07:52 PM   #9
green_dragon37
Member
 
Registered: Oct 2002
Location: Lower Alabama
Distribution: Slackware, OpenBSD 3.9
Posts: 344

Original Poster
Rep: Reputation: 31
Talking Correspondence - Part 3

So I just got home and checked my email, and in it I found a response from Speakeasy, as follows:

Quote:
Greetings,

We have taken appropriate steps to insure that no further activity of this nature will occur from this ip address. Please do not hesitate to inform us if you detect any undesirable activity from any host within Speakeasy.net's IP space. We do not tolerate abuse of any kind on our network and make every attempt to swiftly correct problems that arise.

Network Security Department
Speakeasy, Inc.
206.728.9770
800.556.5829
abuse@speakeasy.net
All that I have to say is, Thank you Speakeasy! In all actuality, though, I would have much rather contacted the admins of this computer directly, so that I could inform them of the problem myself, because of the actions this implies...


Ian
 
Old 06-26-2003, 04:22 AM   #10
MasterC
LQ Guru
 
Registered: Mar 2002
Location: Salt Lake City, UT - USA
Distribution: Gentoo ; LFS ; Kubuntu ; CentOS ; Raspbian
Posts: 12,613

Rep: Reputation: 69
Whoa! Try shooting off an email to:
admin@1.2.3.4
Or
webmaster@1.2.3.4
Or the failsafe:
root@1.2.3.4
Where 1.2.3.4 is the IP of the computer you were getting it from.

Cool
 
Old 06-26-2003, 11:01 AM   #11
green_dragon37
Member
 
Registered: Oct 2002
Location: Lower Alabama
Distribution: Slackware, OpenBSD 3.9
Posts: 344

Original Poster
Rep: Reputation: 31
Well, I tried that at first, I even tried to see if there was a http server there, so that I might contact them directly, but there wasn't.

Ian
 
Old 06-29-2003, 11:27 AM   #12
Whitehat
Senior Member
 
Registered: Feb 2003
Location: The Cold North
Distribution: SuSE 9.1
Posts: 1,289

Rep: Reputation: 46
Code Red tastes great. I like regular Mountain Dew better however
 
Old 06-29-2003, 05:15 PM   #13
Robert0380
LQ Guru
 
Registered: Apr 2002
Location: Atlanta
Distribution: Gentoo
Posts: 1,280

Rep: Reputation: 47
Quote:
Originally posted by Whitehat
Code Red tastes great. I like regular Mountain Dew better however

lol, that's funny. I think it was just a bunch of hype though. And you can tell the people at Mtn. Dew knew it wasnt that great..that's why they are having out for "the summer only" to get the masses to buy it....that strategy worked on me i must say. i had to know what all the hype was about. maybe Mountain Dew Nimda or Moutain Dew Klez will be out next summer.

and just so this post is TOTALLY off topic....i have the same problem in my apache logs. i wonder who i could contact.

also, it's quite common to see the infection from a computer that isnt even really trying to run a web server. windows 2000 comes with that IIS crap and people just have it there and never use it. it happened to a computer at my old job. it was on a college campus though and detected almost immediatly and the port was locked...but there was no web server (or any kind of server for that matter) running on the machine.

Last edited by Robert0380; 06-29-2003 at 05:17 PM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Cygwin: should I bother? yekrahs Linux - Software 2 11-30-2005 04:53 AM
why bother with linux slantoflight General 80 11-25-2005 11:55 PM
the code name of red hat tukang_minta Linux - Newbie 2 08-15-2003 05:24 PM
Code Red g_goblin Linux - Security 3 11-14-2002 07:28 PM
should i bother with all this security adamezzer Linux - Security 3 01-05-2002 03:56 PM

LinuxQuestions.org > Forums > Non-*NIX Forums > General

All times are GMT -5. The time now is 02:39 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration