Worm attacks

Chris Newton newton at unb.ca
Mon Jul 23 09:41:31 EDT 2001

I saw massive quantities... but, anyone who has seen my previous posts will 
have expected the network I monitor to have seen lots of this. :)  
Unfortunatly, I dont think I have any left (my scripts automatically 
rotate/delete older logs).

  We had 10 machines infected, and they were touching approximatly 10,000 
external machines every few minutes.  The incoming barrage was even bigger.  
Quite fun.


>===== Original Message From <carter at qosient.com> =====
>Gentle people,
>   Did any one catch any worm traffic this past week?
>I'd love to see the first 64 bytes, if anyone has any
>logs.  I'm guessing that Argus would have been the only
>technology to automatically audited worm traffic from the
>last wave.
>Carter Bullard
>QoSient, LLC
>300 E. 56th Street, Suite 18K
>New York, New York  10022
>carter at qosient.com
>Phone +1 212 588-9133
>Fax   +1 212 588-9134


Chris Newton, Systems Analyst
Computing Services, University of New Brunswick
newton at unb.ca 506-447-3212(voice) 506-453-3590(fax)

"The best way to have a good idea is to have a lot of ideas."
Linus Pauling (1901 - 1994) US chemist

More information about the argus mailing list