12/15/2008

Arbor Networks Belgian Internet threat theater

Yesterday we were number three in the world of the dangerous Internet networks and it seems that something fundamental will have to be done if we want ever to get out of this toplist. We are also in the toplist of active command and control servers (for botnets).

So you will have to patch your windows machines because the scanning for machines that aren't patched yet is going on in full swing. Yesterday a scanning/infection method grew with 1000%.

In the networks that according to Arbor Networks had a few problems, there was a new client, Proximus. THis made us sit down a moment. THis is for the mobile networks. Ok they use internet also, does that mean that there is malicious traffic on these networks. Say it ain't so.....

There was also some DDOS traffic yesterday, incoming to Belgium and outgoing from one of the botnets active on our networks. I hope the critical networks have some DDOS defenses set up or plan to set up next year.

The good news is that the central important infrastructure from Skynet is not mentioned this weekend. I hope they are monitoring it closely because there are a lot of new attacks under way - the IE exploit is for the moment only in Asia a problem but it won't take weeks before it will be actively used elsewhere - especially because the workaround are so difficult to install for 'users'. Especially if the links are injected in normal sites.

bo25

10:17 | Permalink | Comments (0) | Email this | |  del.icio.us | | Digg! Digg |  Facebook

Post a comment