[rescue] Fair Warning RPC Worm

Mike Meredith mike at blackhairy.demon.co.uk
Tue Aug 12 13:17:52 CDT 2003


On Tue, 12 Aug 2003 11:21:03 -0500
Mike Hebel <nimitz at nimitzbrood.com> wrote:
> Funny thing is.  If you just do proper firewall security this worm 
> isn't an issue.  

Yes it is. A firewall is no excuse for not securing the inside ... after
all there's laptops to consider which can be connected at unprotected
locations and then brought inside. There's plenty of tales of corporate
networks collapsing under Code Red or Slammer because of that sort of
thing.

Besides if you have an underpowered firewall (ho hum) having 100,000
attempted exploits an hour can have a negative impact even when it's all
being blocked.

> do you r best case and use the "Shields Up" port
> probe stuff at www.grc.com (Gibson Research) and you'll know
> immediately if there's a problem.

There's a lot of serious security people who don't much like Gibson.



More information about the rescue mailing list