Re: Can spammer worm get transfered via floppy disk?

From: Neil Pike (neilpike@compuserve.com)
Date: 02/13/03


Date: Thu, 13 Feb 2003 15:31:14 GMT
From: Neil Pike <neilpike@compuserve.com>


 Mike,
 
 Someone brought it into their internal company LAN then.
 
> I have a client who even though all incoming packets
> other than http and smtp are blocked, they got infected
> with the work. They had a msde based accounting
> application that wasn't patched.
>
> My question is how would they get infected in the first
> place if port 1434 UDP was blocked for incoming packets?
> Outgoing was not but I don't see how it could happen. Am
> I missing something?
>

 Neil Pike MVP/MCSE. Protech Computing Ltd
 Reply here - no email
 SQL FAQ (484 entries) see
 http://forumsb.compuserve.com/gvforums/UK/default.asp?SRV=MSDevApps
 (faqxxx.zip in lib 7)
 or www.ntfaq.com/Articles/Index.cfm?DepartmentID=800
 or www.sqlserverfaq.com
 or www.mssqlserver.com/faq



Relevant Pages

  • Re: Can spammer worm get transfered via floppy disk?
    ... > I have a client who even though all incoming packets ... > other than http and smtp are blocked, ... > place if port 1434 UDP was blocked for incoming packets? ...
    (microsoft.public.sqlserver.security)
  • Can spammer worm get transfered via floppy disk?
    ... other than http and smtp are blocked, ... They had a msde based accounting ... place if port 1434 UDP was blocked for incoming packets? ...
    (microsoft.public.sqlserver.security)
  • Re: Suggestions for custom application-layer protocol?
    ... I don't know of any HTTP, SMTP, NNTP, POP3, IMAP, etc. server that does ... NAWS and TTYPE etc to the client. ... A similar thing is happening with HTTP, it's not "good"but there are ...
    (comp.os.linux.embedded)
  • Re: Suggestions for custom application-layer protocol?
    ... I don't know of any HTTP, SMTP, NNTP, POP3, IMAP, etc. server that does ... NAWS and TTYPE etc to the client. ... A similar thing is happening with HTTP, it's not "good"but there are ...
    (comp.unix.programmer)
  • Re: [Full-Disclosure] Sidewinder G2
    ... > So if you have a HTTP application level proxy does that mean you are ... that's the server end of an SMTP conversation ... SMTP commands are generated by the SMTP client and sent to the SMTP ... RFC2616 says this about HTTP proxies in section 1.3: ...
    (Full-Disclosure)