 NorthernMage
join:2002-11-09 Mill Bay, BC
·TELUS
| [Kerio 2.x] LSASS Access Storm
I just installed Kerio 2.1.5 and was hit by a storm of requests to access lsass.exe/port 0 from sites all over the globe. Is this normal or is this part of the Sasser worm, I have patched my OS but am still getting pinged. I have denied access to all attempts to access port 0, is that the safe thing to do? Now that I have denied access the storm has stopped but am I blocked legitimate requests as well. |
  BlitzenZeus Burnt Out Cynic Premium,MVM join:2000-01-13 Beaverton, OR
·Verizon FIOS
·Verizon Online DSL
1 edit | No, if you really need lan rules, those lan rules would allow the necessary communications before the blocking rules. FYI, if your using the default rules, they are not secure, and I suggest you read over this thread, then at the bottom is a ruleset you can import which is more secure than the default configuration. »BZ Kerio 2x Default Replacement Update -- My hourly rates: $25 per hour. $35 per hour if you want to watch. $45 per hour if you want to help. $75 per hour if you tried to fix it, and failed. I'm sarcastic, and cynical by nature, deal with it. |