zinno -> how bagle works on a LAN? (18.Jul.2004 2:12:00 AM)
|
Sorry for the noob question, but there is some stuff i don't really understand about the worms of today
scenario: 1 server 2003 with isa and internet connection & 1 infected client
If u have setup ISA-server, and one of your clients is infected with bagle and send out mail with his own bagel buildin SMTP server, will it use port 8866 (listed as port to block) to send these mails ?
If your ISA-server is set "allow all" policy for outbound traffic, will these mails still be send through port 8866 on the isa-server aswell?
So if i place a sniffer on port 8866 of the server i should be able to detect infected clients?
|
|
|
|