To protect networks against the Plug and Play attacks currently being exploited, security experts recommend IT professionals take steps that include:
- Patching systems quickly;
- Blocking TCP ports 139 and 445 at the firewall;
- Eliminating NULL sessions;
- Using access control lists (ACLs) to restrict traffic to worm-specific ports and destinations;
- Updating IDS/IPS signatures;
- Using a personal firewall such as the Internet Connection Firewall, which is included with Windows XP SP1;
- Enabling advanced TCP/IP filtering on systems that support the above feature; and
- Blocking affected ports using IPsec on the affected systems.
Requires Free Membership to View
SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!
Michael S. Mimoso, Editorial Director