04-May-2004, 03:10 PM
|
| | Your Friendly Admin Guy Karma +/- Power: 106 | | Local Time: 09:12 AM Local Date: 25-Jul-2008
Join Date: Jan 2004 Age: 29 Posts: 4,982 | |
Re: BEWARE! Sasser Virus Announcement Click here (mcafee site) for info on removal.
From the same site: Quote:
Method of Infection
This worm spreads by exploiting a recent Microsoft vulnerability, spreading from machine to machine with no user intervention required.
This worm scans random IP addresses for exploitable systems. When one is found, the worm exploits the vulnerable system, by overflowing a buffer in LSASS.EXE. It creates a remote shell on TCP port 9996. Next it creates an FTP script named cmd.ftp on the remote host and executes it. This FTP script instructs the target victim to download and execute the worm (with the filename #_up.exe as aforementioned) from the infected host. The infected host accepts this FTP traffic on TCP port 5554.
The worm spawns multiple threads, some of which scan the local class A subnet, others the class B subnet, and others completely random subnets. The destination port is TCP 445
| |
| |