Forum Settings
       
Reply To Thread

new virus out thereFollow

#1 May 01 2004 at 10:22 PM Rating: Default
Quote:

NEW WORM SPREADS WITHOUT USER INTERACTION
Severity: Medium (May elevate to high in the next few days)
1 May, 2004
---------------------------------------------------------------
For an easier-to-read HTML version of this article, go to:
https://www.watchguard.com/archive/showhtml.asp?pack=11040
---------------------------------------------------------------
ABOUT THE VIRUS:

Beginning Friday evening a new worm called Sasser (technically known
as W32/Sasser.worm) began spreading on the Internet. Like previous
worms (such as Slammer, and to some extent, CodeRed and Nimda),
Sasser relies on exploiting a recent flaw in Microsoft Windows to
spread. If the worm finds a computer vulnerable to the specific
Windows flaw, it infects that PC without any user interaction. Worms
like Sasser that require no user interaction tend to spread wildly.
The good news is that if you have kept up to date with the Microsoft
patches we've recommended in past alerts, and if your Firebox has a
typical configuration, Sasser should pass you by.

WHAT IT DOES:

Unlike most worms, Sasser does not rely on email to spread. Instead,
the worm attempts to connect to random victims on TCP port 445 and
exploits a Microsoft Windows vulnerability we described in an April
13 alert (specifically MS04-011). Its name arises from the fact that
it exploits a buffer overflow in LSASS (Local Security Authority
Server Service) .
If the exploit is successful, the worm downloads a copy of itself to
your machine and adds the file "avserve.exe" to the default Windows
directory. The worm also adjusts the registry to ensure that it can
restart the next time you reboot. In fact, using a special Windows
API, AbortSystemShutdown, Sasser makes it difficult to restart or
shut down your PC.
Finally, Sasser installs an FTP server on your computer, running on
TCP port 5554 so that your machine can deliver the worm to others.
Once installed on a victim machine, Sasser repeats the entire
process by randomly scanning IP addresses on port 445, searching for
exploitable machines. Out of the randomly scanned IPs, 50% are
totally random, 25% have the same first octet as your IP address and
the last 25% have the same first two octets as your IP address. This
helps Sasser to spread efficiently both on the Internet and within
your local network.

WHAT YOU CAN DO:

Make sure you've installed all of the Microsoft patches that we
recommended in our April 13 alert! With these patches installed,
Sasser cannot find a direct path into your network. As you'll see
below, your Firebox is probably already set up to defend against
this worm. However, take extra precautions to protect your network
from your mobile users or visiting customers. If this worm can sneak
its way onto an unpatched Microsoft network, it will be difficult to
contain.

SUGGESTIONS FOR FIREBOX II / III / X, VCLASS, AND SOHO USERS:

All of WatchGuard's firewalls block incoming TCP port 445 by
default. As long as you have not added a service allowing TCP port
445 in, you are protected from Sasser infection via the Internet.
In case your network becomes infected, filtering TCP ports 5554 and
9996 (the ports that the worm uses to spread itself) helps to
prevent your computers from becoming infectious hosts -- that is,
spreading the worm to others. If you don't already egress filter,
follow the instructions specific to your WatchGuard firewall to add
custom services for TCP port 5554 and 9996 and block both incoming
and outgoing access for these ports. The links below lead to
instructions on how to do so.

this also means that most of you behind NAT routers should be rather safe as the default for most routers is to denie anything under 1024 access. i would take the extra step to update your antivirus software, patch your OS (windowsupdate.microsoft.com copy and paste that in your navigation bar of IE), and run a system scan on the above file name to verify that you have not already been infected.

cross fingers and good luck at not getting this one.


putting this on a few of the forums here to help others from getting ganked.
#2 May 02 2004 at 12:39 AM Rating: Decent
Spaming like an idiot is not going to help anybody cause if you are dumb enough to get a virus reading about it won't help. It's like putting up a DONT DRINK GASOLINE sign if they weren't going to drink it they would have already known not to. This is just a stupid waste of time.
#3 May 02 2004 at 12:54 AM Rating: Good
So you're saying I should quit making my website for people that have gotten the nasty virus that makes it so windows wont start up?
#4 May 02 2004 at 12:57 AM Rating: Good
Actually, there are probably a few computer illiterate people here. Posts like this help keep the number of virus carrying computers to a minimum. Thus minimizing the chances of other un patched computers from getting viruses. I am all for the odd post about viruses.

Although this is even better info....

https://everquest.allakhazam.com/forum.html?forum=25&mid=1083477863178907715&num=0









Edited, Sun May 2 02:06:34 2004 by Reinman
#5 May 02 2004 at 12:58 AM Rating: Excellent
Spankatorium Administratix
*****
1oooo posts
Hey Reinman since we can't move posts yet, why not copy paste that puppy over on the tech forum, may save Kao some typing :)
____________________________

#6 May 02 2004 at 1:00 AM Rating: Good
Tech forum?
#7 May 02 2004 at 1:02 AM Rating: Excellent
Spankatorium Administratix
*****
1oooo posts
*whaps da brotha* hehe j/k

Alla's Forum listings (SWG color)
____________________________

#8 May 02 2004 at 1:08 AM Rating: Good
Better?
#9 May 02 2004 at 10:46 AM Rating: Default
His Excellency Spidermilk wrote:
Spaming like an idiot is not going to help anybody cause if you are dumb enough to get a virus reading about it won't help. It's like putting up a DONT DRINK GASOLINE sign if they weren't going to drink it they would have already known not to. This is just a stupid waste of time.


well as you must not of read, here ya go, ill post it again for you:

Quote:
putting this on a few of the forums here to help others from getting ganked.


i know for a fact that a lot of posters here DO NOT READ OTHER FORUMS so this is to hit those forums i visit to reduce the risk of them getting infected, or to help them clean up their system if they are infected.



Edited, Sun May 2 11:46:45 2004 by Singdall
#10 May 02 2004 at 11:55 AM Rating: Decent
Lunatic
******
30,086 posts
A virus that takes advantage of massive security flaw in a Windows product?

Thta's new. I think they should start a new company "Microsoft Home Security" first step is to smash huge holes in the walls near any locked doors and paint florescent orange arrows on the ground outside pointing to the holes, in case they need to come and help you, they'll be able to find the house ok.
____________________________
Disclaimer:

To make a long story short, I don't take any responsibility for anything I post here. It's not news, it's not truth, it's not serious. It's parody. It's satire. It's bitter. It's angsty. Your mother's a *****. You like to jack off dogs. That's right, you heard me. You like to grab that dog by the bone and rub it like a ski pole. Your dad? Gay. Your priest? Straight. **** off and let me post. It's not true, it's all in good fun. Now go away.

#11 May 02 2004 at 12:16 PM Rating: Good
**
564 posts
Skeeter the Venerable wrote:
So you're saying I should quit making my website for people that have gotten the nasty virus that makes it so windows wont start up?


No, actually I think spidermilk was just taking the opportunity to announce his complete lack of tact and intelligence to the OoT community.

Looks like it's open season on another idiot.

Thanks for the informative post singdall, the virus was news to me and I appreciate being warned about it.
Reply To Thread

Colors Smileys Quote OriginalQuote Checked Help

 

Recent Visitors: 338 All times are in CST
Anonymous Guests (338)