View Single Post
  #2 (permalink)  
Old 04-May-2004, 03:10 PM
kall
kall's Avatar
kall is offline
 Your Friendly Admin Guy
 Karma +/- Power: 106
 Karma: kall has a spectacular aura aboutkall has a spectacular aura aboutkall has a spectacular aura about (231)
  Send a message via MSN to kall
 
 Local Time: 09:12 AM
 Local Date: 25-Jul-2008
 Join Date: Jan 2004
 Age: 29
 Posts: 4,982
 Blog Entries: 6
Default Re: BEWARE! Sasser Virus Announcement

Click here (mcafee site) for info on removal.

From the same site:
Quote:
Method of Infection

This worm spreads by exploiting a recent Microsoft vulnerability, spreading from machine to machine with no user intervention required.

This worm scans random IP addresses for exploitable systems. When one is found, the worm exploits the vulnerable system, by overflowing a buffer in LSASS.EXE. It creates a remote shell on TCP port 9996. Next it creates an FTP script named cmd.ftp on the remote host and executes it. This FTP script instructs the target victim to download and execute the worm (with the filename #_up.exe as aforementioned) from the infected host. The infected host accepts this FTP traffic on TCP port 5554.

The worm spawns multiple threads, some of which scan the local class A subnet, others the class B subnet, and others completely random subnets. The destination port is TCP 445
Reply With Quote