Turns out that the customer was infected with Blaster.Worm (lovsan). So, it
sure seems that it's doing more than initially indicated.
Does anyone know exactly what protocol is being used by this
"msblaster.exe" or this other shell program created? Any easy way to sniff
and log via our Cisco router?
Any advice would help. We've currently got another property with 1352
packets/second leaving a T-1 serial interface that only at 128/255, or
half-used. We never see that kind of pps.
Thanks in advance.
Alavan
Received on Tue Aug 12 20:09:46 2003
This archive was generated by hypermail 2.1.8
: Wed Aug 23 2006 - 14:02:16 EDT