RE: Virus Outbreak Attacking MS05-039
"Semerjian, Ohanes" <[email protected]>
| Newsgroups | gmane.comp.security.virus |
|---|---|
| Message-ID | <236F299EFC6A884190A7704906FAC06E0AEEF700@c205960s16> |
You should never allow vendors/third party partners to be connected to your internal data network, that is just a bad practice and if you do so you are asking for a trouble. They can be on a segment owned by your company but firewalled. Best Regards Ohanes Semerjian -----Original Message----- From: Ziots, Edward [mailto:[email protected]] Sent: Tuesday, 16 August 2005 3:58 AM To: 'Meni Milstein'; 'Mike' Cc: [email protected] Subject: RE: Virus Outbreak Attacking MS05-039 Well think of other avenues of attack, VPN, Dial-up unpatches systems being connected to your systems by vendors, just many many ways around the fun "firewall will protect us from everything" Z Edward Ziots Network Engineer Windows/Citrix Administrator Lifespan Organization MCSE,MCSA,MCP+I,M.E,CCA, Security +, Network + [email protected] 401-639-3505 (Cell) 401-444-6926 (Office) 401-350-5284 (Pager) -----Original Message----- From: Meni Milstein [mailto:[email protected]] Sent: Monday, August 15, 2005 2:00 PM To: 'Mike' Cc: [email protected] Subject: RE: Virus Outbreak Attacking MS05-039 As far as I know, if you are firewalled correctly and have your 445 tcp port shut to the outside - this thing should NOT be able to get in. Am I wrong? Meni Milstein. http://www.lcs-guides.com -----Original Message----- From: Mike [mailto:[email protected]] Sent: Monday, August 15, 2005 3:41 PM To: [email protected] Subject: Virus Outbreak Attacking MS05-039 Hi List, Yesterday one of my customers was hit hard by what appears to be a variant of zotob. http://securityresponse.symantec.com/avcenter/venc/data/w32.zotob.b.html This one was very (noisy) crashing services.exe and forcing re-boots on unpatched WIN2K machines. The boxes we've had a chance to look at were not infected, but were unpatched. We hope to have samples today from the same network and have a closer look. It's time to get patching! Regards Mike Mike Information Security and Logistics www.infosec.co.nz ************** IMPORTANT MESSAGE ************** This e-mail message is intended only for the addressee(s) and contains information which may be confidential. If you are not the intended recipient please advise the sender by return email, do not use or disclose the contents, and delete the message and any attachments from your system. Unless specifically indicated, this email does not constitute formal advice or commitment by the sender or the Commonwealth Bank of Australia (ABN 48 123 123 124) or its subsidiaries. We can be contacted through our web site: commbank.com.au. If you no longer wish to receive commercial electronic messages from us, please reply to this e-mail by typing Unsubscribe in the subject line. ***************************************************************