October 28, 2002

Furnace out, web virii attacks

Posted by Scott at 10:03 PM

As nightfall approached, it seemed to be getting a bit chilly. I went over to the thermostat and saw that it was trying to heat but when I felt the vents I saw that they were just blowing unheated air. A more detailed investigation seems to be showing that at the furnace either the control module or the pressure sensor are defective. I opted to have the tech come first thing in the morning. It's going to be a chilly night. Thanks to chasing the root cause down, I didn't get to work on the photos I had hoped to tonight. On the plus side, Michelle got some Christmas season shopping done.

I mentioned a few days ago that I enabled the Apache web server on my home mac. Today for grins I decided to check out the web access logs. I saw a lot of accesses trying to execute "cmd.exe" on a Windows subdirectory. Laughable since I don't run Windows! At first I thought it was hackers trying to crack in, but then further investigation (ya' gotta love Google) showed that it is either the "code red" or "nimda" virus that causes those. People's PCs get infected with this virus and don't know it. Those virii look around networks to attack Microsoft NIS (the competitor to Apache) web servers, take them over, and spread the virus further. In all cases my little web server returned a classic "404" error back to the virus. From what I could tell, all the accesses were from infected PCs on broadband providers, in particular ComCast, Cox, Charter and Adelphia. Noticably absent was ATT broadband. Perhaps as a provider they are checking their customers machines and watching for such infections. I did some early research to see how I could get those virus probes from filling my access logs with useless junk. I may work on it more later this week. It's interesting to get a taste of what it must be like to be a web master.

Comments