Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Lessons From the Slammer
Richard Forno, 2003-02-05

January's Slammer infection held valuable lessons for all security stakeholders.

Comments Mode:
Lessons From the Slammer 2003-02-06
Villy.Madsen@Shaw.ca (1 replies)
Lessons From the Slammer 2003-02-10
Matt Ostiguy
You just needed one host exposed/brought in to infect huge lans - see (allegedly) MSFT, HP, etc. If an infected laptop was put into hibernation (this particular nasty didn't write anything to disk - it goes away if machine is power cycled), and brought into a corp and placed behind the firewall, it could then run rampant, regardless of ports being open, so long as the default outbound firewall rules are permissive.

Worrying about what ports are open is a problem - if that is your only defense, what happens when things break down?

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/140/18072#18072
Lesson Number Four 2003-02-08
Nicholas Weaver (1 replies)
Lesson Number Four 2003-02-11
Villy.Madsen@shaw.ca
Lessons From the Slammer 2003-02-10
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus