On The Insider: Chris Brown Reacts to Rihanna Interview
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 11 of 11:
« Previous
A couple of points, and maybe I missed something
I think some of the problem is this BOT used IRC as a transport method (if I understand correctly). Since Windows uses "Windows Messenger" and the service runs by default, that could be the reason they were affected and other machines were not. Also I understand the Widnows firewall is ingress, not egress. So if a Bot is transmitted via IRC, though that client; the firewall would be useless since the machine is probably allowing the traffic back out.

Linux/UNIX machines are taylored to better security by default. Windows can be secure (flaws asside) as well with the proper settings.

The moral of the story; Don't run IRC on a production server (or any server except an IRC server). Lock down Daemons/Services to use non-adminstrative accounts. And for God sake; use a hard to crack password and don't login as an administrator unless necessary.
Posted by: Physco Dude   Posted on: 01/31/05 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

whaaa?  JoeMama_z | 01/28/05
YES you can.... but  htotten | 01/28/05
thanks but,  JoeMama_z | 01/28/05
MySQL does run under a normal user account on Windows  Hugh Jass | 01/28/05
I'm confused.  Immanuel Tranz-Mischen | 01/29/05
I'll explain  toadlife | 01/29/05
and...  linuxoverwindows | 01/29/05
why other platforms weren't affected  toadlife | 01/29/05
Moral: use secure passwords, especially on the root account (nt)  CobraA1 | 01/30/05
Running at root?  DonPMitchell@... | 01/31/05
A couple of points, and maybe I missed something  Physco Dude | 01/31/05

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
advertisement