Hello everyone,
First, I know that my SME V5 server is secure from Nimda, since it's running Apache - so please don't just respond saying "Don't worry, that's an IIS thing." (Even though, yes it is an IIS problem and yes I'm happy that I don't have to worry about it.)
Okay, so now my question: Are your e-smith/SME servers being hit with as much Nimda as one of mine - 5,863 hits this week! Here's my link to show you if you're interested:
http://64.3.180.188/apache-hits.php(Thanks to Darrell for creating this, and thanks to Dan for showing me how this could be done. It looks like Dan's seeing Nimda hits on his server as well - 1,176.
Based on what I know about Nimda, the compromised IIS machines will attempt to hit a randomly generated IP address. If this is true, wouldn't most systems see roughly the same amount of Nimda hits? With that number increasing/decreasing at roughly the same amount across the board as more IIS machines became compromised or were patched?
I'm more curious about other's experiences, and your thoughts on the whole thing. Has anyone attempted to contact their ISP for help - or (my heavens) tried to locate/contact the individual or business with compromised machines?
Bottom line - I'm shocked by the sheer number of hits my server has seen just this week. Last week it was around 6000 total. Based on the amount of hits so far this week, it will be even higher. So Nimda is alive and well, and appears to be spreading again!
Regards,
Patrick