Blocking port 135?

Sean Donelan sean at donelan.com
Fri Aug 1 18:51:18 UTC 2003


On Fri, 1 Aug 2003, Adi Linden wrote:
> http://www.cert.org/advisories/CA-2003-19.html
>
> Would blocking port 135 at the network edge be a prudent preventative
> measure?

It depends.

  Do you have a network edge?
  Do you have the resources to block it?
  Do you need it for anything else?
  Have you left other holes open?

In reality blocking port 135 is almost never sufficient.  Its slightly
better than waving a dead chicken over your PC.




More information about the NANOG mailing list