[Dshield] Blaster date forward.

Johannes B. Ullrich jullrich at sans.org
Sat Aug 16 03:04:09 GMT 2003


This message was converted from multipart/signed to ascii armored
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Content-Type: text/plain
Content-Transfer-Encoding: quoted-printable

On Fri, 2003-08-15 at 22:28, BarkerJr wrote:
> > > So, this means that they'll all stop scanning because windowsupdate.com
> > > resolves to 127.0.0.1?  Very cool!
> >
> > No. They stop scanning if it does not resolve at all. At least in my
> > end of the net, windowsupdate.com is not resolving at all.
> 
> Ah, it's just Cox cable, I guess.

I just ran a quick check here, and if I resolve windowsupdate.com
to 127.0.0.1, it does not to any DDOS. But it does continue to scan port
135 and 4444.

-- 
SANS - Internet Storm Center
http://isc.sans.org
PGP Key: http://isc.sans.org/jullrich.txt

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)

iD8DBQA/PZ8pR1p7hYJvB/wRAqWGAJ92Dbnm87WpT96u9OEzYF2hsMU5bQCfcLFt
cNTfkrdUsix8hGbZVhZ7bjE-----END PGP SIGNATURE-----

--
SHA1



More information about the list mailing list