[Dshield] DCOM morning after

Brenden Walker BKWalker at DRBSystems.com
Tue Aug 12 15:43:41 GMT 2003

> Am I the only one -stunned- by the number of companies and 
> professional 
> organisations being infected by thisworm?

Nope, I find it odd as well.. 

> Given its infection path is via port 135, and nobody should be 
> permitting this in to or out of their network (filtered at 
> the firewall) 
> this should only be impacting home users (who are less likely 
> to have a 
> firewall).

My home network (which is really the only net connection I administer)
firewall (Gentoo Linux)  filters everything I don't have an immediate need
for, what I don't get is that if I can manage to control my home network...
Why can't they?  Perhaps you should have to go through a 'driving test'
before being allowed a T1 or bigger pipe.

