Snort mailing list archives
MSBLASTER DOS a fizzle shanizzle!
From: "larosa, vjay" <larosa_vjay () emc com>
Date: Sat, 16 Aug 2003 00:49:24 -0400
FYI, If you do an nslookup of windowsupdate.com, you will see that M$ pulled the IP today (also sent an advisory out). I did some testing in the lab and the DOS will not trigger because the infected box can not resolve windowsupdate.com (not www.windowsupdate.com or windowsupdate.microsoft.com, just plain old windowsupdate.com). H:\>nslookup Default Server: mice.emc.com Address: 10.10.10.10
windowsupdate.com
Server: mice.emc.com Address: 10.10.10.10 Name: windowsupdate.com
See nothing, but just wait until the next version when the DOS target is all of the M$ sites. Okay, now everyone back to patching!!! vjl V.Jay LaRosa EMC Corporation Information Security 4400 Computer Dr. (508)898-7433 Office Westboro, MA 01580 (508)962-1482 Cell www.emc.com <http://www.emc.com> 888-799-9750 Pager vjl () emc com
Current thread:
- MSBLASTER DOS a fizzle shanizzle! larosa, vjay (Aug 15)
