RE: New MSN Messenger Worm

From: Michael Fredericks (mfredericksat_private)
Date: Thu Feb 14 2002 - 08:04:41 PST

  • Next message: John Elliott: "Re: Port 80 SYN flood-like behavior"

    Hi All,
    Thanks for the warning on MSN Messenger. I have restricted access to the
    service from my network and suggest that it might be a good idea for
    others to do the same. I found that MSN Messenger uses TCP port 1863 but
    it also seems to fallback to an HTTP connection to various hosts on the
    "messenger.hotmail.com" domain. Therefore I found that I had to restrict
    the TCP port as well as any http connection attempts to this domain.
    
    Thanks,
    
    Michael Fredericks
    Manager - Networks and Telecommunications
    InfoSol, Inc.
    mfredericksat_private
    http://www.infosol.com/
    
    
    
    
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Thu Feb 14 2002 - 08:43:23 PST