Sobig.f surprise attack today

Dan Hollis goemon at anime.net
Thu Aug 28 19:54:54 UTC 2003


On Thu, 28 Aug 2003, Owen DeLong wrote:
> Alternatively, perhaps we could, instead, publish an INFECTED SYSTEMS 
> blacklist
> based on such connections to a honeypot.  Any system which made the correct
> request could then have it's address published via BGP or DNS for ISPs and
> the like to do as they wish.

an infected host dnsrbl doesnt sound like a bad idea...

-Dan
-- 
[-] Omae no subete no kichi wa ore no mono da. [-]




More information about the NANOG mailing list