RE: [iwar] Why do you track Code Red attempts?

From: Glenn Williamson (Glenn_Williamson@ottawa.com)
Date: 2001-08-09 04:30:41


Return-Path: <sentto-279987-1568-997356701-fc=all.net@returns.onelist.com>
Delivered-To: fc@all.net
Received: from 204.181.12.215 by localhost with POP3 (fetchmail-5.1.0) for fc@localhost (single-drop); Thu, 09 Aug 2001 04:34:08 -0700 (PDT)
Received: (qmail 19382 invoked by uid 510); 9 Aug 2001 10:33:49 -0000
Received: from n27.groups.yahoo.com (216.115.96.77) by 204.181.12.215 with SMTP; 9 Aug 2001 10:33:49 -0000
X-eGroups-Return: sentto-279987-1568-997356701-fc=all.net@returns.onelist.com
Received: from [10.1.4.52] by fh.egroups.com with NNFMP; 09 Aug 2001 11:31:41 -0000
X-Sender: glenn.williamson@sympatico.ca
X-Apparently-To: iwar@yahoogroups.com
Received: (EGP: mail-7_3_1); 9 Aug 2001 11:31:41 -0000
Received: (qmail 21017 invoked from network); 9 Aug 2001 11:31:40 -0000
Received: from unknown (10.1.10.27) by m8.onelist.org with QMQP; 9 Aug 2001 11:31:40 -0000
Received: from unknown (HELO tomts6-srv.bellnexxia.net) (209.226.175.26) by mta2 with SMTP; 9 Aug 2001 11:31:40 -0000
Received: from home ([209.226.118.182]) by tomts6-srv.bellnexxia.net (InterMail vM.4.01.03.16 201-229-121-116-20010115) with SMTP id <20010809113139.BAIK3759.tomts6-srv.bellnexxia.net@home> for <iwar@yahoogroups.com>; Thu, 9 Aug 2001 07:31:39 -0400
To: <iwar@yahoogroups.com>
Message-ID: <NEBBJBJAILHONFLOGCKJOELLCLAA.glenn.williamson@sympatico.ca>
X-Priority: 1 (Highest)
X-MSMail-Priority: High
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2911.0)
In-Reply-To: <20010809031117.59191.qmail@web14509.mail.yahoo.com>
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2314.1300
Importance: High
X-eGroups-From: "Glenn Williamson" <glenn.williamson@sympatico.ca>
From: "Glenn Williamson" <Glenn_Williamson@ottawa.com>
Mailing-List: list iwar@yahoogroups.com; contact iwar-owner@yahoogroups.com
Delivered-To: mailing list iwar@yahoogroups.com
Precedence: bulk
List-Unsubscribe: <mailto:iwar-unsubscribe@yahoogroups.com>
Date: Thu, 9 Aug 2001 07:30:41 -0400
Reply-To: iwar@yahoogroups.com
Subject: RE: [iwar] Why do you track Code Red attempts?
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 7bit


To those that read my first answer;

 *ER* then I stand humbly corrected, the why and the who plays a very vital
part in trying to figure out the where and how of Code Red, but the number
of attempts on a server(S) will not always provide that answer. If I count
the amount of buffer overflow attempts and pass that on, it does not always
provide the answer or solution to the problem. We all know the magnitude of
this but by passing numbers, does it not then place emphasis on the count
vice emphasis on the who and why. I love statistical analysis, but simply
looking at numbers does not provide the needed in-depth analysis, it points
to a problem but not to the overall solution.

 Well for Rob, that was my 2 cents worth, and now I will go back to my
darkened corner, and once again watch what goes by. *ER*, I am not against
your answer and nor do I disagree with it, but by simply counting and
providing in detail the number does not provide the who and why, it provides
a statistic of amount, if it provides the who and why then great, but by
simply counting attempts it will not always provide the
who/what/where/when/why and how, if it did then we would count every single
malformed packet that touched our servers as that alone would provide the
needed answer.

Glenn


Did perhaps the thought that people were trying to understand  the "why
and who behind Code Red ever dawn on you?  That will find you far more
than just looking at the Code.  The answers are only there, in part. As
who and why now-then you will start to understand the problem far
better,



------------------------ Yahoo! Groups Sponsor ---------------------~-->
Small business owners...
Tell us what you think!
http://us.click.yahoo.com/vO1FAB/txzCAA/ySSFAA/kgFolB/TM
---------------------------------------------------------------------~->

------------------
http://all.net/ 

Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/ 



This archive was generated by hypermail 2.1.2 : 2001-09-29 21:08:39 PDT