sasser virus (was Re: [unisog] student fees for cleaning.)

Reg Quinton reggers at
Thu May 13 06:09:43 GMT 2004

>  Do you have any stats on the number of computers on your campus that
> were/are unpatched and vulnerable to LSASS exploits?

Our experiences and practices at UWaterlooo are pretty much what Peter does
at SFU (we block the Microsoft protocols -- I wish we blocked more, we
monitor for scanning)... and we do have permission to scan for
vulnerablities. I scan and notify.

We've got over 10,000 machines, I've detected 342 who weren't patched, and
I've seen 25 Sasser compromises.

