Port 445 issues (was: Port 80 Issues)

james hackerwacker at cybermesa.com
Sun Mar 9 23:15:26 UTC 2003


> So far the Deloder worm appears to be responding to normal congestion
> feedback controls, limiting its network impact.  Like CodeRed, Nimda, etc
> some edge providers may need to implement network controls due to
> scanning activities causing cache busting, but I suspect most network
> backbones will not need to do anything.


I agree this is not a backbone issue. Since we are an ISP and at the edge,
it is a good place to drop this. Traffic is not as large, as of yet, as the
SQL worm.
Blocking port 445, for us, means far less $$ in support time to deal with
abuse reports
and infected users.




More information about the NANOG mailing list