-----Original Message-----
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]] 
Sent: Monday, February 10, 2003 4:24 AM
To: [EMAIL PROTECTED]; Schmehl, Paul L
Cc: [EMAIL PROTECTED]
Subject: RE: [Full-Disclosure] SQL Slammer - lessons learned
> 
>Code Red/Nimda have fizzled out (probably still some infected 
>machines out there), since it is possible to block ports below 
>1024.

Huh?  Our IDSes detect both Code Red I, II and III and Nimda every day,
as does my Wormcatcher.  I don't know *anyone* who is blocking port 80.
Do you?

Paul Schmehl ([EMAIL PROTECTED])
Adjunct Information Security Officer
The University of Texas at Dallas
http://www.utdallas.edu/~pauls/
AVIEN Founding Member 
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html

Reply via email to