RE: New SASSER Worm varient ???

"Newell, Tim" <[email protected]>
Newsgroups gmane.comp.security.intrusions
Message-ID <00CE50EB651C264E900DDB241CF4AB09399D97@nshalexch01.corp.xwave.com>
Had the following report from someone at another organization this
morning, don't have any further details:

"[a/v vendor] did not know anything about it until we spoke to them
yesterday afternoon.  We have sent them the files and they have
confirmed it.  It attacks the lsass issus that microsoft identified a
few months back.(Port 445)  There are 2 different processes that load.
bling.exe or msxml32.exe.  These are then loaded from the
hkey_local/...../run as XML Service.  Its flooding our network"

- Tim

Tim Newell 
Security & Business Continuity
xwave, Halifax, NS 
Phone    (902) 495-2836  
Cellular  (902) 222-8815  
Fax         (902) 495-2095  
[email protected] 


-----Original Message-----
From: [email protected]
[mailto:[email protected]] On Behalf Of Carey, Steve T
GARRISON
Sent: Friday, August 27, 2004 12:40 PM
To: [email protected]
Subject: [Intrusions] New SASSER Worm varient ???


Anyone seeing a new varient of SASSER using port 4445 as the back door
port?  I have had systems infected that were patched (and verified).
 
STEVEN T. CAREY
LCIRT-R
(256) 876-5811
DSN 746-5811
Cell (256) 759-9767
[email protected]
 
_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions
_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.