|
|||||||||||
|
RE: rpc dcom worm and windowsupdate
From: Chris Barber <cbarber(at)stginc.com>
Date: Wed Aug 13 2003 - 11:24:25 EDT
-----Original Message-----
The worm does a lookup on windowsupdate.com so if you put in a record on your dns servers to point to, say, 127.0.0.1 you can redirect the attack to target the host computer loopback instead of taking out your network bandwidth. -Rich
-----Original Message-----
Hey guys, Ok our company is owned by the msblaster worm, now we would like to keep the ddos attack under control. Our Idea is, that we can make that one of our proxies will identify himself as windowsupdate.com. Now my question is, is the Worm looking for windowsupdate.com per Lookup or has it a fix ip in the Source ? Does someone know anything ? Haves some the sorce :)
PS:
regards Gruskovnjak Oliver Bundesamt für Informatik und Telekommunikation BIT Bereitstellung Netzdienste / BZBN Monbijoustrasse 74 3003 Bern Tel. +41 (0) 31 323 89 84 Fax +41 (0) 31 325 90 30 SMTP: oliver.gruskovnjak@bit.admin.ch WEB: www.bit.admin.ch Received on Wed Aug 13 20:23:38 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:02:16 EDT |
||||||||||
|
|||||||||||