North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: Operational impact of filtering SMB/NETBIOS traffic?

  • From: David Avery
  • Date: Sun Nov 19 23:26:44 2000

I would hope leased line/colo machines would be better set up, but I am probably
dreaming.

Just for referance I an one of the net/security admins at distributed.net
and there are a number of win* worms running arounf in the wild carrying
the distributed.net client as part of their payload.

So far in the past 3 months ( since the worms appeared) I have logged
over 400,000 unique IP addresses returning data to distributed.net 
from installs created by the worms. We have spot checked a number of 
these IPs and find win9x boxes with open C shares and signs on multiple
infestation including QAZ and other DDoS payloads.

daa
[email protected]