[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Apache (Linux?) Worm



On Mon, 16 Sep 2002, Richard Welty wrote:

> at all.  it shouldn't ever even reach the point of actually executing any
> code; at most it'll crash the particular httpd process it is attacking. the
> only exception to this i can think of is if by some mischance one of the
> offsets actually matches, and it decides to attack a *bsd system with the
> matching offset. the odds of this happening are tiny at best.

What are the odds of someone taking the source, adding a few more offsets
that are appropriate for BSD, and turning it loose?

The worm is not the product of spontaneous generation.  There is a
somebody who wrote it, and many somebodies who can edit it.


--
Mediocrity is a sin.