According to published docs on the worm it attacks "windowsupdate.com" which maps to ip's in 204.79.188.0/24 However checks to my cache logs show that nothing ever goes to plain old http://windowsupdate.com . Everything goes to download.windowsupdate.com , www.download.windowsupdate.com or something else. Even www.windowsupdate.com points elsewhere. In fact a glance though cache logs so nothing going anywhere near the 204.79.188.0/24 network. Even better the 204.79.188.0/24 is a /24 all by itself advertised as a /24. Does this mean: 1. It's safe to null route this network. 2. Microsoft will withdraw the advertisement for the network if the going gets tough. I notice that there is no route for the network on route-server.cw.net already. Thoughts? -- Simon Lyall. | Newsmaster | Work: simon.lyall(a)ihug.co.nz Senior Network/System Admin | Postmaster | Home: simon(a)darkmere.gen.nz Ihug Ltd, Auckland, NZ | Asst Doorman | Web: http://www.darkmere.gen.nz