[Dshield] Looks like Sobig-F is going to mess up TGIF

Johannes B. Ullrich jullrich at sans.org
Fri Aug 22 16:45:45 GMT 2003


On Fri, 2003-08-22 at 12:00, Joshua Thornburg wrote:
> This looks real bad...
> 
> http://www.f-secure.com/news/items/news_2003082200.shtml

Lets not forget: It is likely that F-Secure knows the IPs
for these systems, and has notified the relevant ISPs.

even if they are not shut down, they can go and pickup the
binary at least as fast as the virus.

I am going to bet that not much will happen. Maybe some
smaller IPSs / companies may see some pipe-clogging as the 
outbound virus requests pile up. But if they have that many 
infected machines, they probably ordered a bandwidth upgrade
anyway to accommodate the traffic they generate on a regular
basis.



-- 
SANS - Internet Storm Center
http://isc.sans.org
PGP Key: http://isc.sans.org/jullrich.txt
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: This is a digitally signed message part
Url : http://www.dshield.org/pipermail/list/attachments/20030822/68b02793/attachment.bin


More information about the list mailing list