Using NT/2k/XP/2k3? Now is a good time to patch.
#22
Quote:In my opinion, NOTHING should by default be "on" in your OS when you install it, that communicate from the outside, especially one that accept input from the outside.

Agreed. There is no reason whatsoever that port 135 (netbios) should be world accessible by default. It boggles my mind why MS did that. :/

For the record, if you're using a firewall, blocking access to the following ports should keep ya safe:

* tcp/69 (used by the TFTP process)
* tcp/135 (used by RPC remote access)
* tcp/4444 (used by this worm to connect)

It's also recommended that you rename tftp.exe, which the worm uses to be downloaded.

Again, credit for the info to www.sophos.com.

http://sophos.com/support/disinfection/blastera.html
Reply


Messages In This Thread
Using NT/2k/XP/2k3? Now is a good time to patch. - by Zedd - 08-13-2003, 11:48 AM

Forum Jump:


Users browsing this thread: 9 Guest(s)