[56490] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: Port 445 issues (was: Port 80 Issues)

daemon@ATHENA.MIT.EDU (james)
Sun Mar 9 18:16:24 2003

From: "james" <hackerwacker@cybermesa.com>
To: <nanog@merit.edu>
Date: Sun, 9 Mar 2003 16:15:26 -0700
Errors-To: owner-nanog-outgoing@merit.edu


> So far the Deloder worm appears to be responding to normal congestion
> feedback controls, limiting its network impact.  Like CodeRed, Nimda, etc
> some edge providers may need to implement network controls due to
> scanning activities causing cache busting, but I suspect most network
> backbones will not need to do anything.


I agree this is not a backbone issue. Since we are an ISP and at the edge,
it is a good place to drop this. Traffic is not as large, as of yet, as the
SQL worm.
Blocking port 445, for us, means far less $$ in support time to deal with
abuse reports
and infected users.


home help back first fref pref prev next nref lref last post