Access-list is used to combat the shock wave virus. Recently, the shock wave virus (WORM_MSBlast.A) began to spread on the Internet and some private networks in China. The access-list I previously created at the access layer serves! You can refer to the access-list120deny53anyanyaccess-list120deny55anyanyaccess-lis
Access-list is used to combat the shock wave virus. Recently, the shock wave virus (WORM_MSBlast.A) began to spread on the Internet and some private networks in China. The access-list I previously created at the access layer serves! For details, refer to access-list 120 deny 53 any access-list 120 deny 55 any access-lis.
Access-list
Confrontation"
Shock Wave"
Virus
Recent"
Shock Wave"
Virus(WORM_MSBlast.A) began to spread on the domestic Internet and some private networks. The access-list I previously created at the access layer serves!
You can refer
Access-list 120 deny 53 any
Access-list 120 deny 55 any
Access-list 120 deny 77 any
Access-list 120 deny 103 any
Use the preceding items with caution!
Access-list 120 deny tcp any eq echo
Access-list 120 deny tcp any eq chargen
Access-list 120 deny tcp any eq 135
Access-list 120 deny tcp any eq 136
Access-list 120 deny tcp any eq 137
Access-list 120 deny tcp any eq 138
Access-list 120 deny tcp any eq 139
Access-list 120 deny tcp any eq 389
Access-list 120 deny tcp any eq 445
Access-list 120 deny tcp any eq 4444 // newly added
Access-list 120 deny udp any eq 69 // newly added
Access-list 120 deny udp any eq 135
Access-list 120 deny udp any eq 136
Access-list 120 deny udp any eq 137
Access-list 120 deny udp any eq 138
Access-list 120 deny udp any eq 139
Access-list 120 deny udp any eq snmp
Access-list 120 deny udp any eq 389
Access-list 120 deny udp any eq 445
Access-list 120 deny udp any eq 1434
Access-list 120 deny udp any eq 1433
Access-list 120 permit ip any
Appendix: solution!
**********************************
(1) For uninfected hosts:
We recommend that you install the patch specified in http://microsoft.com/technet/securi..p.
(2) For infected systems:
You may not be able to upgrade patches from Microsoft. We recommend that you use the following methods:
I. Disconnect the physical network connection of the machine.
II. Execute the registry editing command: regedit, check
"HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows
In CurrentVersion \ Run \ windows auto update ",
Whether the key value of msblast.exe exists. If yes, delete it.
Iii.run the task manager and shut down the msblast.exe process.
IV. either of the following two methods is used to complete the process:
A. Disable DCOM: Set HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Ole
The EnableDCOM key value in is N.
B. Set firewall or Microsoft's Internet
Connection Filter (ICF) blocks the following ports in the Incoming direction:
69/UDP 135/TCP 135/UDP 139/TCP
139/UDP 445/TCP 445/UDP 4444/TCP.
V. reconnect to the network and install the patch specified in http://microsoft.com/technet/securi..p.