Use access-list to combat the "Shock Wave" virus

Source: Internet
Author: User
Access-list is used to combat the shock wave virus. Recently, the shock wave virus (WORM_MSBlast.A) began to spread on the Internet and some private networks in China. The access-list I previously created at the access layer serves! You can refer to the access-list120deny53anyanyaccess-list120deny55anyanyaccess-lis

Access-list is used to combat the shock wave virus. Recently, the shock wave virus (WORM_MSBlast.A) began to spread on the Internet and some private networks in China. The access-list I previously created at the access layer serves! For details, refer to access-list 120 deny 53 any access-list 120 deny 55 any access-lis.

Access-list Confrontation" Shock Wave" Virus

Recent" Shock Wave" Virus(WORM_MSBlast.A) began to spread on the domestic Internet and some private networks. The access-list I previously created at the access layer serves!

You can refer

Access-list 120 deny 53 any

Access-list 120 deny 55 any

Access-list 120 deny 77 any

Access-list 120 deny 103 any

Use the preceding items with caution!

Access-list 120 deny tcp any eq echo

Access-list 120 deny tcp any eq chargen

Access-list 120 deny tcp any eq 135

Access-list 120 deny tcp any eq 136

Access-list 120 deny tcp any eq 137

Access-list 120 deny tcp any eq 138

Access-list 120 deny tcp any eq 139

Access-list 120 deny tcp any eq 389

Access-list 120 deny tcp any eq 445

Access-list 120 deny tcp any eq 4444 // newly added

Access-list 120 deny udp any eq 69 // newly added

Access-list 120 deny udp any eq 135

Access-list 120 deny udp any eq 136

Access-list 120 deny udp any eq 137

Access-list 120 deny udp any eq 138

Access-list 120 deny udp any eq 139

Access-list 120 deny udp any eq snmp

Access-list 120 deny udp any eq 389

Access-list 120 deny udp any eq 445

Access-list 120 deny udp any eq 1434

Access-list 120 deny udp any eq 1433

Access-list 120 permit ip any

Appendix: solution!

**********************************

(1) For uninfected hosts:

We recommend that you install the patch specified in http://microsoft.com/technet/securi..p.

(2) For infected systems:

You may not be able to upgrade patches from Microsoft. We recommend that you use the following methods:

I. Disconnect the physical network connection of the machine.

II. Execute the registry editing command: regedit, check

"HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows

In CurrentVersion \ Run \ windows auto update ",

Whether the key value of msblast.exe exists. If yes, delete it.

Iii.run the task manager and shut down the msblast.exe process.

IV. either of the following two methods is used to complete the process:

A. Disable DCOM: Set HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Ole

The EnableDCOM key value in is N.

B. Set firewall or Microsoft's Internet

Connection Filter (ICF) blocks the following ports in the Incoming direction:

69/UDP 135/TCP 135/UDP 139/TCP

139/UDP 445/TCP 445/UDP 4444/TCP.

V. reconnect to the network and install the patch specified in http://microsoft.com/technet/securi..p.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.