[iwar] New worm spreading, @home coming back, etc.

From: Fred Cohen (fc@all.net)
Date: 2001-12-04 11:32:04


Return-Path: <sentto-279987-4008-1007494188-fc=all.net@returns.groups.yahoo.com>
Delivered-To: fc@all.net
Received: from 204.181.12.215 [204.181.12.215] by localhost with POP3 (fetchmail-5.7.4) for fc@localhost (single-drop); Tue, 04 Dec 2001 11:33:07 -0800 (PST)
Received: (qmail 28015 invoked by uid 510); 4 Dec 2001 19:30:12 -0000
Received: from n13.groups.yahoo.com (216.115.96.63) by all.net with SMTP; 4 Dec 2001 19:30:12 -0000
X-eGroups-Return: sentto-279987-4008-1007494188-fc=all.net@returns.groups.yahoo.com
Received: from [216.115.97.188] by n13.groups.yahoo.com with NNFMP; 04 Dec 2001 19:22:15 -0000
X-Sender: fc@red.all.net
X-Apparently-To: iwar@onelist.com
Received: (EGP: mail-8_0_1_2); 4 Dec 2001 19:29:47 -0000
Received: (qmail 88013 invoked from network); 4 Dec 2001 19:29:46 -0000
Received: from unknown (216.115.97.171) by m2.grp.snv.yahoo.com with QMQP; 4 Dec 2001 19:29:46 -0000
Received: from unknown (HELO red.all.net) (12.232.125.69) by mta3.grp.snv.yahoo.com with SMTP; 4 Dec 2001 19:29:46 -0000
Received: (from fc@localhost) by red.all.net (8.11.2/8.11.2) id fB4JW4N26988 for iwar@onelist.com; Tue, 4 Dec 2001 11:32:04 -0800
Message-Id: <200112041932.fB4JW4N26988@red.all.net>
To: iwar@onelist.com (Information Warfare Mailing List)
Organization: I'm not allowed to say
X-Mailer: don't even ask
X-Mailer: ELM [version 2.5 PL3]
From: Fred Cohen <fc@all.net>
X-Yahoo-Profile: fcallnet
Mailing-List: list iwar@yahoogroups.com; contact iwar-owner@yahoogroups.com
Delivered-To: mailing list iwar@yahoogroups.com
Precedence: bulk
List-Unsubscribe: <mailto:iwar-unsubscribe@yahoogroups.com>
Date: Tue, 4 Dec 2001 11:32:04 -0800 (PST)
Subject: [iwar] New worm spreading, @home coming back, etc.
Reply-To: iwar@yahoogroups.com
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 7bit

It is a very interesting week, and I thought I would comment on it. 
I'll be brief, but I am interested in other views.

1) There is a war on and many participants are seeking to attack
information infrastructures for things ranging from public relations to
critical infrastructure attacks.

2) 4.1 Million people were summarily kicked off the Internet and are
slowly being put back on under increased restrictions on use - including
that AT&T owns copy and distribution rights to all content passing out
from their network - including not having 'services' on computers in
their network - including knowing how many individuals are users and
charging per individual.  The current cable performance is far higher
than before - probably because of very light loads.  Many have moved to
other services - I have always had redundancy and used it well - but
others who have to chose have now opted out of @home. 

3) The only things that were happening in the @home network while the
service was down but the modems were still turned on was that viruses
were continuing to spread - yes the viruses persisted without routing or
DNS or anything else - finding their way to any IP address they coud
reach.

4) As the @home network came back up, it revealed many many UIDs and
passwords because the modems were not brought up in a restricted enough
operating mode.  For those who recorded the traffic, it is a goldmine.

5) A new and destructive virus is said to be spreading rapidly in the
Internet.

6) It's only Tuesday.

FC

--This communication is confidential to the parties it is intended to serve--
Fred Cohen		Fred Cohen & Associates.........tel/fax:925-454-0171
fc@all.net		The University of New Haven.....http://www.unhca.com/
http://all.net/		Sandia National Laboratories....tel:925-294-2087


------------------------ Yahoo! Groups Sponsor ---------------------~-->
See What You've Been Missing!
Amazing Wireless Video Camera.
Click here
http://us.click.yahoo.com/75YKVC/7.PDAA/ySSFAA/kgFolB/TM
---------------------------------------------------------------------~->

------------------
http://all.net/ 

Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/ 



This archive was generated by hypermail 2.1.2 : 2001-12-31 21:00:00 PST