Sticky Please: New Worm! (March 20 2004)

NogginBoink

Diamond Member
Feb 17, 2002
5,322
0
0
This one is nasty. Exploits a buffer overrun in Black Ice (ironic, no? Black Ice is supposed to protect your computer!) and overwrites random sectors on your disks.

Ouch indeed.

Details here

Patch info here.

Surprisingly, this one doesn't appear to be Microsoft's fault.

(Cross posted to Operating Systems and slashdot pending moderator approval.)
 

DaWhim

Lifer
Feb 3, 2003
12,985
1
81
my school network.....yikes! it has been down the whole frigging morning!

There appears to be a new, as yet unknown worm or bot that sends large amounts
of UDP traffic with source port 4000, apparently attempting to exploit a
recently disclosed vulnerability with RealSecure and BlackICE:


http://www.eeye.com/html/Research/Advisories/AD20040226.html

The UB network began getting hammered by this traffic at approximately
midnight. As of right now (approx 4am) we have

blocked "UDP source port 4000" traffic from leaving or entering UB.
Unfortunately, we appear to have hundreds of machines on campus
that are affected by this worm/bot, therefore there is still a
lot of congestion on our internal networks. For example, our
gigabit (1000Mbps) link leading towards Internet1 and Internet2
is currently very close to 100% utilization. We are continuing to investigate
ways that we can alleviate the stress on the UB network.
 

InlineFive

Diamond Member
Sep 20, 2003
9,599
2
0
I presume this also affects computers directly connected without software firewalls?

-Por
 

rh71

No Lifer
Aug 28, 2001
52,844
1,049
126
It took the coders this long to get smart ? Attacking Antivirus first was the right thing to do ... why didn't they think of this until now ?

Score one for hardware firewalls.
 

EagleKeeper

Discussion Club Moderator<br>Elite Member
Staff member
Oct 30, 2000
42,589
5
0
Notice that it went for Black Ice and not Zone Alarm
 

Sideswipe001

Golden Member
May 23, 2003
1,116
0
0
Originally posted by: spidey07
Originally posted by: EagleKeeper
Notice that it went for Black Ice and not Zone Alarm

gee, maybe because the vulnerability was in Black Ice?

I never thought of Black Ice as being a particularly effective firewall anyway.
 

azazyel

Diamond Member
Oct 6, 2000
5,872
1
81
Does anyone know what the emails look like? I received one that said.

"If the message will not displayed automatically,
follow the link to read the delivered message.

Received message is available at:"

then there was a link to my inbox.


I am not going to open it I was just wondering if this was it.
 

simms

Diamond Member
Sep 21, 2001
8,211
0
0
Originally posted by: Sideswipe001
Originally posted by: spidey07
Originally posted by: EagleKeeper
Notice that it went for Black Ice and not Zone Alarm

gee, maybe because the vulnerability was in Black Ice?

I never thought of Black Ice as being a particularly effective firewall anyway.

IMHO it sucks... did you read that thread on GRC.com?
 

Triumph

Lifer
Oct 9, 1999
15,031
14
81
Kerio has been blocking a lot of hits to mstask.exe in the last few days. Not sure if this is the same thing or not.
 

Ozoned

Diamond Member
Mar 22, 2004
5,578
0
0
This sounds cool. Do I get this from microsofts

website like I did the blaster worm??

:D
 

Rogue

Banned
Jan 28, 2000
5,774
0
0
I found this yesterday and it looks very similar to this NEW worm that everyone's talking about, only these posts are dated clear back to 2002. Seems to me the problem has existed for a very, very long time and no one has done anything about it. Pretty scary really. At least Microsoft takes a few months, not years (usually ;)) to fix their issues.
 

fw3308

Member
Dec 12, 2003
168
0
0
It may not need to be stickied but it is a nasty virus. The scary thing is that is is memory resident and NAV or McAfee will not pick it up. Even worse is that it randomly re-writes 128 sectors on your hard drive. If you are hit by it there is no fix. Just reimage the machine and either update your Black Ice or get a different product.
 

DWW

Platinum Member
Apr 4, 2003
2,030
0
0
Why is this even stickied? Worms happen all the time.

Besides Black Ice has always sucked. Its had proof of concept code available around for some time (couple years) for something else ;)