• HEXUS
  • HEXUS.tv
  • channel
  • gaming
  • lifestyle
  • trust
  • community
  • ESReality
  • HEXUS.community discussion forums

    Welcome to the HEXUS.community discussion forums forums.

    You are currently viewing our boards as a guest which gives you limited access to view most discussions and other features. By joining our free community you will have access to post topics, respond to polls and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

    Go Back   HEXUS.community discussion forums > HEXUS.channels > General discussion

    General discussion Chatter, desires, jokes & rants; some threads are banter some are serious - please show respect for others Add RSS Feed

    Reply
     
    LinkBack Thread Tools
    Old 02-05-2004, 10:26 AM   #1 (permalink)
    Administrator
     
    Moby-Dick's Avatar
     
    Join Date: Jul 2003
    Location: There's no place like 127.0.0.1
    Posts: 8,277
    Thanks: 4
    Thanked 88 Times in 77 Posts
    Have you done all of your windows updates ?

    Or made sure your firewall is working ?

    if not, you might be in for a rough ride
    and here's why

    Sasser
    New Worm Spreads without User Interaction
    Severity: Medium
    (May elevate to high in the next few days)
    1 May, 2004

    About the Virus
    Beginning Friday evening a new worm called Sasser (technically known as W32/Sasser.worm) began spreading on the Internet. Like previous worms (such as Slammer, and to some extent, CodeRed and Nimda), Sasser relies on exploiting a recent flaw in Microsoft Windows to spread. If the worm finds a computer vulnerable to the specific Windows flaw, it infects that PC without any user interaction. Worms like Sasser that require no user interaction tend to spread wildly. The good news is that if you have kept up to date with the Microsoft patches , Sasser should pass you by.

    What It Does
    Unlike most worms, Sasser does not rely on email to spread. Instead, the worm attempts to connect to random victims on TCP port 445 and exploits a Microsoft Windows vulnerability we described in an April 13 alert (specifically MS04-011). Its name arises from the fact that it exploits a buffer overflow in LSASS (Local Security Authority Server Service) .

    If the exploit is successful, the worm downloads a copy of itself to your machine and adds the file "avserve.exe" to the default Windows directory. The worm also adjusts the registry to ensure that it can restart the next time you reboot. In fact, using a special Windows API, AbortSystemShutdown, Sasser makes it difficult to restart or shut down your PC.

    Finally, Sasser installs an FTP server on your computer, running on TCP port 5554 so that your machine can deliver the worm to others.

    Once installed on a victim machine, Sasser repeats the entire process by randomly scanning IP addresses on port 445, searching for exploitable machines. Out of the randomly scanned IPs, 50% are totally random, 25% have the same first octet as your IP address and the last 25% have the same first two octets as your IP address. This helps Sasser to spread efficiently both on the Internet and within your local network.



    Moby-Dick is online now   Reply With Quote
    Old 02-05-2004, 10:28 AM   #2 (permalink)
    Rank Bajin
     
    Join Date: Jul 2003
    Location: Hemel/St Albans
    Posts: 1,164
    Thanks: 0
    Thanked 4 Times in 4 Posts
    Nope, I haven't done any updates. I don't need too. That's BSD for you.
    headbrace is offline   Reply With Quote
    Old 02-05-2004, 10:28 AM   #3 (permalink)
    Administrator
     
    Moby-Dick's Avatar
     
    Join Date: Jul 2003
    Location: There's no place like 127.0.0.1
    Posts: 8,277
    Thanks: 4
    Thanked 88 Times in 77 Posts
    What You Should Know About the Sasser Worm
    Posted: May 1, 2004





    Microsoft teams and law enforcement authorities are investigating reports of a worm, identified as W32.Sasser.worm, that is currently circulating on the Internet. Microsoft has verified that the worm exploits the Local Security Authority Subsystem Service (LSASS) issue fixed in Microsoft Security Update MS04-011 on April 13, 2004.


    Products Affected by This Worm
    Windows 2000 Service Pack 2, Windows 2000 Service Pack 3, and Windows 2000 Service Pack 4
    Windows XP and Windows XP Service Pack 1
    Windows XP 64-bit Edition Service Pack 1

    Products Not Affected by This Worm
    Windows NT 4.0 Service Pack 6a
    Windows XP 64-Bit Edition Version 2003
    Windows Server 2003
    Windows Server 2003 64-Bit Edition



    How to Tell If Your Computer Is Infected
    If your computer is infected with W32.Sasser.worm, you may see a dialog box with text that refers to LSASS.exe. Some customers whose computers have been infected may not notice the presence of the worm at all, while others who are not infected may experience problems because the worm is attempting to attack their computer. Typical symptoms may include systems rebooting every few minutes without user input.


    Mitigation Steps for Affected Computers
    If your computer is infected with the W32.Sasser.worm, please do the following:

    Enable the Windows XP Internet Connection Firewall or a third-party firewall on the affected computer.
    Disconnect the computer from the Internet.
    Restart the computer. If you have problems rebooting, reboot in safe mode.
    Press CTRL+ALT+DEL.
    Click the Task Manager.
    Click the Processes tab.
    Press and hold the CTRL key and then click C:\WINDOWS\avserve.exe and c:\WINDOWS\system32\*_up.exe.
    Click the End Task button.
    Click Start.
    Click Search and then search for and delete the following files:
    C:\WINDOWS\avserve.exe
    C:\WINDOWS\system32\*_up.exe
    Click Start again, click Run, and then type: regedit32
    Click OK.
    In Registry Editor, locate and delete the following registry key:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "avserve.exe" = C:\WINDOWS\avserve.exe
    Connect the computer to the Internet.
    Go to the Windows Update site, and click the Scan for Updates button.
    Download and install the critical updates recommended after the scan.

    Preventive Steps for Home Users
    Customers can protect against this worm by installing Microsoft Security Update MS04-011 immediately.

    If you have a computer with Windows XP and have enabled the Windows XP Firewall, you are protected from attacks by this worm. Also, most third-party firewalls will block this attack.
    the above quote is form a news alert issued buy http://bink.nu ( a very credible source for windows news )

    The First quote is from the watchguard livesecurity update - this is not a drill folks



    Moby-Dick is online now   Reply With Quote
    Old 02-05-2004, 10:30 AM   #4 (permalink)
    Administrator
     
    Moby-Dick's Avatar
     
    Join Date: Jul 2003
    Location: There's no place like 127.0.0.1
    Posts: 8,277
    Thanks: 4
    Thanked 88 Times in 77 Posts
    Originally Posted by headbrace
    Nope, I haven't done any updates. I don't need too. That's BSD for you.
    which is why I said windows updates if you were applying MS patches to a BSD box I'd have serious concerns for your sanity



    Moby-Dick is online now   Reply With Quote
    Old 02-05-2004, 10:32 AM   #5 (permalink)
    Administrator
     
    Moby-Dick's Avatar
     
    Join Date: Jul 2003
    Location: There's no place like 127.0.0.1
    Posts: 8,277
    Thanks: 4
    Thanked 88 Times in 77 Posts
    If you have been affected by this worm , you'll find a removal tool here:

    http://www.microsoft.com/downloads/d...DisplayLang=en



    Moby-Dick is online now   Reply With Quote
    Old 02-05-2004, 10:45 AM   #6 (permalink)
    Spodes Henchman
     
    unrealrocks's Avatar
     
    Join Date: Aug 2003
    Location: Nottingham UK
    Posts: 2,390
    Thanks: 3
    Thanked 2 Times in 2 Posts
    I just leave updates for virus, windows etc. all on auto so it just does it. PC Cillin did tell me that there was this virus going round in the wild last night though.


    G4 PowerMac - Tiger 10.4 - 512MB RAM
    MacBook - 2Ghz - 1GB RAM - 120GB HDD

    Rotel RC970BX | DBX DriveRack |2x Rotel RB850
    B&W DM640i | Velodyne 1512
    unrealrocks is offline   Reply With Quote
    Old 02-05-2004, 10:50 AM   #7 (permalink)
    Drop it like it's hot
     
    Howard's Avatar
     
    Join Date: Jul 2003
    Location: Surrey, South East
    Posts: 11,631
    Thanks: 14
    Thanked 40 Times in 36 Posts
    Howard's system
    I'm always up to date

    My mate had this worm yesterday though... Lol

    Home cinema: Toshiba 42XV555DB Full HD LCD | Onkyo TX-SR705 | NAD C352 | Monitor Audio Bronze B2 | Monitor Audio Bronze C | Monitor Audio Bronze BFX | Yamaha NSC120 | BK Monolith sub | Toshiba HD-EP35 HD-DVD | Samsung BD-P1400 BluRay Player | Pioneer DV-575 | Squeezebox3 | Virgin Media V+ Box
    PC: Asus P5B | Core2duo 2.13GHz | 2GB DDR2 PC6400 | Inno3d iChill 7900GS | Auzentech X-Plosion 7.1 | 250GB | 500GB | NEC DVDRW | Dual AG Neovo 19"
    HTPC: | Core2Duo E6420 2.13GHz | 2GB DDR2 | 250GBx2 | Radeon X1300 | Terratec Aureon 7.1 | Windows MCE 2005
    Laptop: 1.5GHz Centrino | 512MB | 60GB | 15" Wide TFT | Wifi | DVDRW

    Howard is online now   Reply With Quote
    Old 02-05-2004, 11:37 AM   #8 (permalink)
    Senior Member
     
    Kezzer's Avatar
     
    Join Date: Sep 2003
    Posts: 4,864
    Thanks: 12
    Thanked 5 Times in 5 Posts
    /me strokes linux firewall
    Kezzer is offline   Reply With Quote
    Old 02-05-2004, 11:49 AM   #9 (permalink)
    Rank Bajin
     
    Join Date: Jul 2003
    Location: Hemel/St Albans
    Posts: 1,164
    Thanks: 0
    Thanked 4 Times in 4 Posts
    /remembers to read thread thoroughly before posting

    I'll get me goat.
    headbrace is offline   Reply With Quote
    Old 02-05-2004, 02:03 PM   #10 (permalink)
    Member
     
    Join Date: Jul 2003
    Posts: 139
    Thanks: 0
    Thanked 0 Times in 0 Posts
    /me strokes linux
    Joel is offline   Reply With Quote
    Old 02-05-2004, 02:08 PM   #11 (permalink)
    Goat Boy
     
    Join Date: Jul 2003
    Location: Alexandra Park, London
    Posts: 2,422
    Thanks: 0
    Thanked 0 Times in 0 Posts
    Originally Posted by headbrace
    /remembers to read thread thoroughly before posting

    I'll get me goat.
    here you go matey...



    **** knows how the old boy managed to get to Australia in that time


    "All our beliefs are being challenged now, and rightfully so, they're stupid." - Bill Hicks
    DaBeeeenster is offline   Reply With Quote
    Old 02-05-2004, 02:14 PM   #12 (permalink)
    Crazy HEXUS.net
     
    Stoo's Avatar
     
    Join Date: Jul 2003
    Location: The Void.. Floating
    Posts: 10,417
    Thanks: 27
    Thanked 60 Times in 48 Posts
    Stoo's system
    *snigger*

    Always make sure you've got enough RAM for your system?

    Originally Posted by silent ben
    Nanotechnology is going to be huge.
    Stoo is offline   Reply With Quote
    Old 02-05-2004, 02:24 PM   #13 (permalink)
    Goat Boy
     
    Join Date: Jul 2003
    Location: Alexandra Park, London
    Posts: 2,422
    Thanks: 0
    Thanked 0 Times in 0 Posts
    Originally Posted by Stoo
    *snigger*

    Always make sure you've got enough RAM for your system?
    this is the funniest post in the world ever.


    "All our beliefs are being challenged now, and rightfully so, they're stupid." - Bill Hicks
    DaBeeeenster is offline   Reply With Quote
    Old 02-05-2004, 02:26 PM   #14 (permalink)
    Crazy HEXUS.net
     
    Stoo's Avatar
     
    Join Date: Jul 2003
    Location: The Void.. Floating
    Posts: 10,417
    Thanks: 27
    Thanked 60 Times in 48 Posts
    Stoo's system
    Sorry.. *skulks off*

    Originally Posted by silent ben
    Nanotechnology is going to be huge.
    Stoo is offline   Reply With Quote
    Old 02-05-2004, 02:33 PM   #15 (permalink)
    More l33t than dangel
     
    directhex's Avatar
     
    Join Date: Jul 2003
    Location: /dev/urandom
    Posts: 13,337
    Thanks: 27
    Thanked 252 Times in 199 Posts
    directhex's system
    C:\Documents and Settings\directhex>apt-get upgrade
    'apt-get' is not recognized as an internal or external command,
    operable program or batch file.

    no worky, moby

    directhex is offline   Reply With Quote
    Old 02-05-2004, 03:27 PM   #16 (permalink)
    "I can be such an apple slut"
     
    steve threlfall's Avatar
     
    Join Date: Jul 2003
    Location: Sacred Heart
    Posts: 5,973
    Thanks: 98
    Thanked 57 Times in 37 Posts
    steve threlfall's system
    Originally Posted by Stoo
    *snigger*

    Always make sure you've got enough RAM for your system?

    steve threlfall is offline   Reply With Quote
    Reply

    Breadcrumb
    Go Back   HEXUS.community discussion forums > HEXUS.channels > General discussion


    Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
     
    Thread Tools

    Posting Rules
    You may not post new threads
    You may not post replies
    You may not post attachments
    You may not edit your posts

    BB code is On
    Smilies are On
    [IMG] code is On
    HTML code is Off
    Trackbacks are On
    Pingbacks are On
    Refbacks are On
    Forum Jump

    Similar Threads
    Thread Thread Starter Forum Replies Last Post
    Windows Updates? Jimmy Little Operating systems & applications 2 19-04-2004 12:41 PM
    Windows (Critical) Updates jonathan_phang Operating systems & applica