Hey guys, Ok our company is owned by the msblaster worm, now we would like to keep the ddos attack under control. Our Idea is, that we can make that one of our proxies will identify himself as windowsupdate.com. Now my question is, is the Worm looking for windowsupdate.com per Lookup or has it a fix ip in the Source ? Does someone know anything ? Haves some the sorce :) PS: What are you doing against it ? regards Gruskovnjak Oliver ---------------------------------------------------------------------------- ------ Bundesamt für Informatik und Telekommunikation BIT Bereitstellung Netzdienste / BZBN Monbijoustrasse 74 3003 Bern ---------------------------------------------------------------------------- ------ Tel. +41 (0) 31 323 89 84 Fax +41 (0) 31 325 90 30 ---------------------------------------------------------------------------- ------ SMTP: oliver.gruskovnjakat_private WEB: www.bit.admin.ch ---------------------------------------------------------------------------- ------ --------------------------------------------------------------------------- ----------------------------------------------------------------------------
This archive was generated by hypermail 2b30 : Wed Aug 13 2003 - 07:53:16 PDT