Re: Sober resurface
- From: "karl levinson, mvp" <levinson_k@xxxxxxxxxxxxx>
- Date: Tue, 20 Dec 2005 08:10:23 -0500
"Curt Shaffer" <curt@xxxxxxxxxxxxx> wrote in message
news:dns1l90bm9@xxxxxxxxxxxxxxxxxxxxx
> All,
>
> I am working on a plan to try and help minimize the effect of the possible
> sober resurfacing on Jan. 5/6th. After reading the security focus article
> that this worm relies on NTP to know when to release, I am wondering on
> the
> feasibility of blocking NTP out to the internet that week except for the
> certain devices that need it. Does anyone have input on this?
It's in your best interest to configure your firewall to only allow in or
out those protocols you are specifically using, to and from only those
systems on your network that need those protocols.
However, I'm not sure that is going to stop Sober specifically. It seems
reasonable to assume Sober would keep spreading even if NTP was
unsuccessful.
.
- References:
- Sober resurface
- From: Curt Shaffer
- Sober resurface
- Prev by Date: Re: AD-Fu a bit rusty so a small sec question
- Next by Date: Re: Sober resurface
- Previous by thread: Sober resurface
- Next by thread: Re: Sober resurface
- Index(es):