Re: Would a firewall prevent Sasser worm?

From: Lars M. Hansen (badnews_at_hansenonline.net)
Date: 05/04/04


Date: Tue, 04 May 2004 17:09:38 GMT

On Tue, 4 May 2004 16:29:07 +0000 (UTC), Bill Unruh spoketh

>Lars M. Hansen <badnews@hansenonline.net> writes:
>
>]On Tue, 04 May 2004 08:33:32 GMT, Piotr Makley spoketh
>
>]>If I had a firewall would that prevent the Sasser worm infecting my
>]>PC?
>]>
>]>I mean, if another infected system cannot see my ports because they
>]>are stealthed then presumably Sasser could not infect me?
>
>]Yes, any firewall that blocks incoming port 445 will prevent infection
>]by the Sasser worm.
>
>Why is port 445 open on his system in the first place?

Port 445 is open by default on any W2K or WXP system unless you've
closed it somehow. Despite the fact that we all wish people would have
firewalls or at least a NAT router, we're not quite there yet...

Lars M. Hansen
www.hansenonline.net
Remove "bad" from my e-mail address to contact me.
"If you try to fail, and succeed, which have you done?"



Relevant Pages

  • Re: Hardening an ISA Server
    ... He sets up his reverse connection server to listen on port ... the spread of the infection is at least mitigated. ... and then cracks the local administrator password. ... access to internal resources as a normal configuration, through a firewall. ...
    (microsoft.public.isa)
  • Re: keeping ports open
    ... If a port is open, it means that 1) a software or service is running on your ... and 2) you're not using a firewall or your firewall isn't ... Use firewall software and hardware and antivirus software that is ... Follow the instructions for hardening Windows and IIS at ...
    (microsoft.public.security)
  • Re: How to Maintain an IIS Server?
    ... > server running on a Windows 2000 server. ... before a firewall and antivirus have been installed]. ... open ports; however, this will not identify which program is using the port. ...
    (microsoft.public.inetserver.iis.security)
  • Re: CEICW fails at firewall config
    ... ISA Server prevents connection to a remote desktop when you connect through ... Remote Web Workplace on a Windows Small Business Server 2003-based computer ... Acceleration Server as a firewall. ... connection uses TCP port 4125. ...
    (microsoft.public.windows.server.sbs)
  • Re: How get the computers communicate in XP?
    ... Specially port 445 which is giving problems last day with Zotob worm for example! ... I don't see that Windows Firewall is so configurable as I would like it to be. ... of an infection can save you a lot of trouble. ...
    (microsoft.public.windowsxp.network_web)