Virus.Org  IT Security News and Information Portal. We offer the latest IT security news, updates, product reviews, books, and articles for all you IT security professionals out there. Enter and get the best IT security information on the Internet.

 

. Welcome to the Virus.Org Mailing List Archive  
.
.


[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]


ISP reacts against Lovsan (alias: MSBlast, Poza, Blaster, W32/Msblast, Lovesun) WAS: RE: [Dshield] DCOM morning after
.

  • Subject: ISP reacts against Lovsan (alias: MSBlast, Poza, Blaster, W32/Msblast, Lovesun) WAS: RE: [Dshield] DCOM morning after
  • From: peter.stendahl-juvonen at welho.com (Peter Stendahl-Juvonen)
  • Date: Wed Aug 13 08:24:48 2003
  • In-reply-to: <[EMAIL PROTECTED]>
.
 
RE: ISP reacts against Lovsan (alias: MSBlast, Poza, Blaster,
W32/Msblast, Lovesun) WAS: RE: [Dshield] DCOM morning after

[EMAIL PROTECTED] <mailto:[EMAIL PROTECTED]> wrote on
Wednesday, August 13, 2003 4:17 AM: on behalf of: Craig Shaw
[EMAIL PROTECTED]

Craig,

Right you are.

| -snip-
| Still, if they were blocking internal traffic but leaving the outside
| stuff still wide open, I would expect you to still see a lot of
| traffic on your firewall.
| -snip-


1) Traffic on firewall (during an eleven hrs period after ISP's
"internal traffic" filtering applied) show:

120 hits targeted to port 135 (Service: RPC Remote Procedure Call,
Transport: TCP (flags:S)).

11 hits targeted to port 445 (Service: MSFT DS, SMB Server Message
Block, Transport: TCP (flags:S)).

6 hits targeted to port 139 (NETBIOS Session Service, Transport: TCP
(flags:S)).


2) Not a single one hit attempt originates from other subscribers of
this same ISP.
(Number of subscribers several tens of thousands.)


When ISP applies this kind of filtering, fellow [ISP] subscribers no
longer reported to DShield in my logs.  ;=)

Thanks again
Pete


        "Ask a question and you are a fool for one minute. 
        Don't ask a question and you are a fool forever." 
                        Chinese Proverb. 


 
.
.
 
Copyright (c) Virus.Org 1997-2006.
All Trademarks Acknowledged.
Please view our Terms and Conditions and our Privacy Policy.