about the only reason i go to VOS is to check out the refurb shop.  what
really got me is they're still selling a 3c905b if the refurb shop for $60
(or somewhere in that neighborhood...)  at least i can get golden orbs for
$5 there...

the people at VOS seem to know the basics, but i don't think they have the
motivation to learn beyond that because they're so haughty and full of
themselves.  and they tend to look at you funny when you're "price-shopping"


-----Original Message-----
From: Dennis Soper [mailto:[EMAIL PROTECTED]]
Sent: Sunday, August 12, 2001 9:37 AM
To: [EMAIL PROTECTED]
Cc: [EMAIL PROTECTED]
Subject: [EUG-LUG:2087] Re: Is CodeRed affecting Linux or FreeBSD
machines?


On Saturday 11 August 2001 19:40, you wrote:

> Robert at VOS told me The CodeRed is affecting Linux and FreeBSD and some
> other Unixes.  I tend not to believe him untill I have some facts.  He
said
> I haven't done my research.  I thought someone on the list would know.  I
> don't see how it could.  I could see it flooding one of the ports but
> that's about it.  He said it was written in machine language.  I would
> think that would be assembler.  If this is true or not could you show me
> it's not.  I'd like to print it up and show him.

I have 2 production Linux web servers at the U of O.  The only thing Code
Red 
has done is fill my log files full of garbage.  Code Red only works on IIS--

as the logs show it looks for specific files, which are not present when 
using the Apache server, whether in *nix or Windoze.  However, the traffice 
Code Red generates on a network could slow down response time of a *nix box 
running Apache (but not as much as installing Windoze on the machine).
And, 
as a properly *nix configured box doesn't run Apache as root, it's going to 
be rather diffucult to install a trojan.  Apache hasn't had a major security

flaw, such as Code Red, since 1997.

<rant on>Robert at VOS should pull his head out of his backside and take a 
gander at what CERT says about this Trojan.  My experience with the people
at 
VOS is that they are not very knowledgeable or IMHO, honest.  I've seen 
Soundblaster 128 PCI sound cards in the store packaged (and priced) as 
Soundblaster Live! Value cards.  They sold me a computer with a flaky 
motherboard and wouldn't repair it (this is before I started building my 
own).  They've also screwed over a number of other people who I know-- so 
much so that I recommend that people I know who ask me where to buy clones
to 
steer clear of their business, and to go to Stan's instead.</rant off>

Cheers,
Dennis

Reply via email to