Increase in Scans of Port 445?

From: Compton, Rich (RComptonat_private)
Date: Mon Mar 10 2003 - 11:14:14 PST

  • Next message: james: "Re: Real-world attacks on sendmail CA-2003-07 seen"

    Hey guys,
    I've noticed on Incidents.org (http://isc.incidents.org/port_details.html?port=445) that there is an increase in traffic to port 445.  Is this because of this "Dropper" virus?  I noticed that the MacAfee link (http://vil.nai.com/vil/content/v_100124.htm) stated that the risk of this virus is very low but if we are seeing such an increase in traffic to this port then it does seem like boxes are getting infected.  Perhaps it is more of a threat than was first considered (especially to home users). Is there some other method of preventing this worm from infecting a box other than turning off (or blocking) sharing? 
    
    Thanks,
    Rich Compton
    
    ----------------------------------------------------------------------------
    
    <Pre>Lose another weekend managing your IDS?
    Take back your personal time.
    15-day free trial of StillSecure Border Guard.</Pre>
    <A href="http://www.securityfocus.com/stillsecure"> http://www.securityfocus.com/stillsecure </A>
    



    This archive was generated by hypermail 2b30 : Mon Mar 10 2003 - 12:20:29 PST