Snort mailing list archives

MSBLASTER DOS a fizzle shanizzle!


From: "larosa, vjay" <larosa_vjay () emc com>
Date: Sat, 16 Aug 2003 00:49:24 -0400

FYI,
 
If you do an nslookup of windowsupdate.com, you will see that M$ pulled the
IP today (also sent an advisory out). I did some testing in the lab and the
DOS will not trigger because the infected box can not resolve
windowsupdate.com (not www.windowsupdate.com or windowsupdate.microsoft.com,
just plain old windowsupdate.com).
 
H:\>nslookup
Default Server:  mice.emc.com
Address:  10.10.10.10
 
windowsupdate.com
Server:  mice.emc.com
Address:  10.10.10.10
 
Name:    windowsupdate.com
 

 
See nothing, but just wait until the next version when the DOS target is all
of the M$ sites. Okay, now everyone back to patching!!!
 
vjl
 
 
V.Jay LaRosa                  EMC Corporation
Information Security         4400 Computer Dr.
(508)898-7433 Office       Westboro, MA 01580
(508)962-1482 Cell           www.emc.com <http://www.emc.com> 
888-799-9750 Pager         vjl () emc com
 

Current thread: