[80769] in North American Network Operators' Group
Re: Blocking port udp/tcp 1433/1434
daemon@ATHENA.MIT.EDU (Hank Nussbacher)
Wed May 11 17:20:51 2005
Date: Thu, 12 May 2005 00:17:59 +0300 (IDT)
From: Hank Nussbacher <hank@mail.iucc.ac.il>
To: Jeff Kell <jeff-kell@utc.edu>
Cc: nanog@merit.edu
In-Reply-To: <42824444.1080907@utc.edu>
Errors-To: owner-nanog@merit.edu
On Wed, 11 May 2005, Jeff Kell wrote:
> The SANS ISC currently gives an "Internet Survival Time" of 24 minutes
> for an unpatched windows box. I would give an unpatched Windows server
> with an old copy of MSSQL a considerably shorter lifespan :-)
See:
http://www.bbcworld.com/content/clickonline_archive_14_2005.asp?pageid=665&co_pageid=3
Took 8 seconds for an unprotected PC to get infected. I would give the
IST at under 1min from my personal experience - plus my firewall records 2
hits on port 445 every minute from external infected systems.
-Hank