"Even identifying vulnerable machines will be quite a challenge."

To be vulnerable a machine has to have been specifically set up by an administrator, and vulnerable machines can be found by a portscan.

Patching or disabling look less work than gluing up the port and installing a new NIC.

