|
|||||||||||
|
FW: rpc dcom worm and windowsupdate
From: Alon Tirosh <atirosh(at)interactiveedge.com>
Date: Wed Aug 13 2003 - 11:00:57 EDT This solution might work, provided that the assessment that the worm is hitting per lookup is correct. However, it wouldn’t be a valid solution because you're failing to address the problem. In addition, depending on the number of infected machines you have, this plan could have a debilitating effect on your network. Better to actually patch and clean the systems, restore from backups, do whatever you have to do. If you're set on doing it this way, I would have a machine masquerade as windowsupdate.com and windowsupdate.microsoft.com via your DNS lookup servers, and also use your routers to shunt all traffic going to the IPs in question at the target machine. This way you have addressed both possible situations. Good luck, Alon
-----Original Message-----
Hey guys, Ok our company is owned by the msblaster worm, now we would like to keep the
ddos attack under control.
Now my question is, is the Worm looking for windowsupdate.com per Lookup or
has it a fix ip in the Source ?
PS:
regards Gruskovnjak Oliver Bundesamt für Informatik und Telekommunikation BIT Bereitstellung Netzdienste / BZBN Monbijoustrasse 74 3003 Bern Tel. +41 (0) 31 323 89 84 Fax +41 (0) 31 325 90 30 SMTP: oliver.gruskovnjak@bit.admin.ch WEB: www.bit.admin.ch Received on Wed Aug 13 20:49:00 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:02:16 EDT |
||||||||||
|
|||||||||||