RE: Virus Outbreak Attacking MS05-039

"Semerjian, Ohanes" <[email protected]>
Newsgroups gmane.comp.security.virus
Message-ID <236F299EFC6A884190A7704906FAC06E0AEEF700@c205960s16>
You should never allow vendors/third party partners to be connected to your
internal data network, that is just a bad practice and if you do so you are
asking for a trouble. 

They can be on a segment owned by your company but firewalled.

Best Regards
Ohanes Semerjian
 
-----Original Message-----
From: Ziots, Edward [mailto:[email protected]] 
Sent: Tuesday, 16 August 2005 3:58 AM
To: 'Meni Milstein'; 'Mike'
Cc: [email protected]
Subject: RE: Virus Outbreak Attacking MS05-039

Well think of other avenues of attack, VPN, Dial-up unpatches systems being
connected to your systems by vendors, just many many ways around the fun
"firewall will protect us from everything"

Z

Edward Ziots
Network Engineer
Windows/Citrix Administrator
Lifespan Organization
MCSE,MCSA,MCP+I,M.E,CCA, Security +, Network +
[email protected]
401-639-3505 (Cell)
401-444-6926 (Office)
401-350-5284 (Pager)


-----Original Message-----
From: Meni Milstein [mailto:[email protected]]
Sent: Monday, August 15, 2005 2:00 PM
To: 'Mike'
Cc: [email protected]
Subject: RE: Virus Outbreak Attacking MS05-039


As far as I know, if you are firewalled correctly and have your 445 tcp port
shut to the outside - this thing should NOT be able to get in. 
Am I wrong?

Meni Milstein.
http://www.lcs-guides.com



-----Original Message-----
From: Mike [mailto:[email protected]] 
Sent: Monday, August 15, 2005 3:41 PM
To: [email protected]
Subject: Virus Outbreak Attacking MS05-039

Hi List,
Yesterday one of my customers was hit hard by what appears to be a variant
of zotob.
http://securityresponse.symantec.com/avcenter/venc/data/w32.zotob.b.html

This one was very (noisy) crashing services.exe and forcing re-boots on
unpatched WIN2K machines. The boxes we've had a chance to look at were not
infected, but were unpatched. We hope to have samples today from the same
network and have a closer look.

It's time to get patching!

Regards
Mike

Mike 

Information Security and Logistics
www.infosec.co.nz






**************   IMPORTANT MESSAGE  **************
This e-mail message is intended only for the addressee(s) and contains information which may be confidential. 
If you are not the intended recipient please advise the sender by return email, do not use or disclose the contents, and delete the message and any attachments from your system. Unless specifically indicated, this email does not constitute formal advice or commitment by the sender or the Commonwealth Bank of Australia (ABN 48 123 123 124) or its subsidiaries. 
We can be contacted through our web site: commbank.com.au. 
If you no longer wish to receive commercial electronic messages from us, please reply to this e-mail by typing Unsubscribe in the subject line.
***************************************************************
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.