Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Full-disclosure] Re: Quarantine your infected users spreading malware |
|---|---|
| Date: | Wed, 22 Feb 2006 09:27:02 +0100 |
On Monday 20 February 2006 22:40, Gadi Evron wrote:
Some who are user/broadband ISP's (not say, tier-1 and tier-2's who would be against it: "don't be the Internet's Firewall") are blocking ports such as 139 and 445 for a long time now, successfully preventing many of their users from becoming infected. This is also an excellent first step for responding to relevant outbreaks and halting their progress. Philosophy aside, it works. It stops infections. Period.
Umm.. sorry, but it doesn't. :-) While blocking ports 139 and 445 does help in reducing the number of infections, it doesn't stop them. We have here mostly user-friendly ISP's that offer antivirus and antispam protection along with blocking ports (turned on by default, and people don't know they can change that), but that just reduced the speed of spreading and gave some more protection to users, but people here still get infected, despite antivirus and port blocking. Antivirus software can't cope with brand new virus/worm/malware until it is detected and signature is distributed, so there's always a small chance you might get another e-mail that passed the checkpoints. And users are... umm... (searches google for polite variations of "idiot") ... gullible - they will just click on that "free sex" icon. The other part of the problem is that ISP's (in my country, at least) usually do not offer such services for their lease-line customers, or they charge them pretty penny for such services. Users on leased lines are up to their own defences, which in many cases mean they have little to no defences. -- Radoslav Dejanovi? Operacijski sustavi d.o.o. http://www.opsus.hr
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | PHP as a secure language? PHP worms? [was: Re: new linux malware], Gadi Evron |
|---|---|
| Next by Date: | [Full-disclosure] The Domain Name Service as an IDS, Gadi Evron |
| Previous by Thread: | Re: [Full-disclosure] Quarantine your infected users spreading malware, Simon Richter |
| Next by Thread: | [Full-disclosure] Re: Quarantine your infected users spreading malware, Bob Beck |
| Indexes: | [Date] [Thread] [Top] [All Lists] |