Interesting related URL:
http://isc.sans.org/diary.html?date=2003-08-11
The folks at SANS seem to have caught a worm ... they are still working on analysis.
The way I read it is, turn of tftp outbound and you should be ok, even if you are vulnerable (this of course does NOT mean you are ok from somone attacking you)...Relevant to this worm only.
/nebulus




Reply With Quote