[61552] in North American Network Operators' Group
Automatic shutdown of infected network connections
daemon@ATHENA.MIT.EDU (Sean Donelan)
Fri Aug 29 21:47:23 2003
Date: Fri, 29 Aug 2003 21:44:11 -0400 (EDT)
From: Sean Donelan <sean@donelan.com>
To: nanog@merit.edu
Errors-To: owner-nanog-outgoing@merit.edu
Some universities such as Vanderbilt University are automatically
shutting down network ports when they detected signature worm traffic.
Almost 25% of the students' computers were detected as infected when they
connected to the university network.
http://www.vanderbilthustler.com/vnews/display.v/ART/2003/08/29/3f4eb4b3537e0
How many ISPs disconnect infected computers from the network? Do you
leave them connected because they are paying customers, and how else
could they download the patch from microsoft?