View Single Post
Old August 15th, 2003, 04:49 AM   Digg it!   #1 (permalink)
BitSpit
Member
 
BitSpit's Avatar
 
Join Date: Mar 2003
Location: Glasgow, KY
Posts: 175
Send a message via ICQ to BitSpit Send a message via Yahoo to BitSpit
Heads up! The MSBlast DDoS Attack Had Begun!

I'm barely able to connect to Microsoft at times. I just checked the firewall logs. There's a massive amount of connection attempts coming from 207.46.249.61 (wu-ori.microsoft.com). However, it's important to note that this IP is being spoofed by the MSBlast worm. It's attempting to connect to a random port between 1000 and 2000 every 2 seconds. The source port on the attempts is port 80, otherwise known as HTTP. The way this DDoS works is it attempts to connect to the port. However, because of the spoofed IP and port, the response to the connect attempt is sent to Windows Update on port 80. That means that all of you who don't have a firewall are contributing to this even if you aren't infected. If you're unprotected, please do everyone a favor and get a firewall.
__________________
Team Captain and Daily Stats Poster for the TechIMO Find-a-Drug Team. Download Find-a-Drug at http://www.find-a-drug.org/ and set the team number to 2037
BitSpit is offline   Reply With Quote
Search TechIMO for Answers: