RE: New SASSER Worm varient ???

"Carey, Steve T GARRISON" <[email protected]>
Newsgroups gmane.comp.security.intrusions
Message-ID <2A39B3177D295F4583659FD74E26FE71E021ED@redstone817.ad.redstone.army.mil>
Actually may not be SASSER.  Turns out it is an IRCBOT that takes advanatage of a vulnerability in LSASS.  Don't think it is the same vulnerability as previous reported by Microsoft, these systems were patched for that vulnerability and had current anti-virus.  I have packet captures of the overflow, or at least most of it, don't have the packets for the traffic to port 4445 (my sensor I used to see this is pretty much maxed out and the data 'rolled' on me).   Haven't looked at the systems myself to see what I can find, will try and do that this week.
 
Steve Carey

________________________________

From: [email protected] on behalf of James C Slora Jr
Sent: Fri 8/27/2004 5:01 PM
To: 'Intrusions List (GCIA Practicals)'
Subject: RE: [Intrusions] New SASSER Worm varient ???



Steve Carey wrote: 

> Anyone seeing a new varient of SASSER using port 4445 as the 
> back door port?  I have had systems infected that were 
> patched (and verified). 

Do you have any captures to share, and do you know how the systems were 
infected? 

There is a new Sasser variant listed at Trend Micro, but it does not appear 
to match your description. 
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SASSER. 
G&VSect=T 

Theirs opens TCP 9996 as the initial shell backdoor and does not appear to 
do anything that would nail a patched system. 

_______________________________________________ 
Intrusions mailing list 
[email protected] 
http://www.dshield.org/mailman/listinfo/intrusions

_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.