At 05:05 PM 8/4/01 +0100, Christian Jaeger wrote: >Just to the record: there seems to be a new variant of the worm, with >all 'N' being replaced with 'X'. The last 117 (er, now thei'r 119) >worm requests on my machine, starting 5 hours ago, were all except >one of the 'X' type. And all of them come from 62.2.x.x (well, I'm on >this subnet, too). Seems like someone wanting to kill this internet >providers clients has rewritten the worm to attack all ip's in this >subrange (instead of the semirandom ip's it used to select before). > >no fun for windows users > >christian. >
That's be Code Red 2.0, it's making as yet undocumented jumps but then really creaming it's subnet... moral of the story, don't allow windows NT on your subnet