nanog mailing list archives
Re: management interface accessability (was Re: Worm / UDP1434)
From: Chris Lloyd <strawberry () toth org uk>
Date: Sun, 26 Jan 2003 19:06:50 +0000
On Sun, Jan 26, 2003 at 06:50:36PM +0000, Stephen J. Wilcox wrote:
My observation was that the target IPs are not random and that local IPs were hit more often (same /16 more than /8 more than all /0) .. a la Codered.
The worm calls gettickcount to get a pseudorandom seed, and always uses that seed to create random addresses. It's possible the random address generator isn't very good and creates addresses that are too similar. Check out http://www.eeye.com/html/Research/Flash/AL20030125.html - Chris -- strawberry () toth org uk http://www.toth.org.uk/~strawberry
Current thread:
- Re: management interface accessability (was Re: Worm / UDP1434) Steven M. Bellovin (Jan 26)
- Re: management interface accessability (was Re: Worm / UDP1434) Johannes Ullrich (Jan 26)
- Re: management interface accessability (was Re: Worm / UDP1434) Rob Thomas (Jan 26)
- Re: management interface accessability (was Re: Worm / UDP1434) Chris Lloyd (Jan 26)
- Re: management interface accessability (was Re: Worm / UDP1434) Stephen J. Wilcox (Jan 26)
- Re: management interface accessability (was Re: Worm / UDP1434) Chris Lloyd (Jan 26)
- Re: management interface accessability (was Re: Worm / UDP1434) Iljitsch van Beijnum (Jan 26)
- Re: management interface accessability (was Re: Worm / UDP1434) Rob Thomas (Jan 26)
- Re: management interface accessability (was Re: Worm / UDP1434) Christopher L. Morrow (Jan 26)
- Re: management interface accessability (was Re: Worm / UDP1434) Rob Thomas (Jan 26)
- Re: management interface accessability (was Re: Worm / UDP1434) Christopher L. Morrow (Jan 26)
- Re: management interface accessability (was Re: Worm / UDP1434) Rob Thomas (Jan 26)
- Re: management interface accessability (was Re: Worm / UDP1434) E.B. Dreger (Jan 26)
- Re: management interface accessability (was Re: Worm / UDP1434) Christopher L. Morrow (Jan 26)
- Re: management interface accessability (was Re: Worm / UDP1434) Johannes Ullrich (Jan 26)
- Re: management interface accessability (was Re: Worm / UDP1434) alex (Jan 27)
- Re: management interface accessability (was Re: Worm / UDP1434) Christopher L. Morrow (Jan 27)