• We’re currently investigating an issue related to the forum theme and styling that is impacting page layout and visual formatting. The problem has been identified, and we are actively working on a resolution. There is no impact to user data or functionality, this is strictly a front-end display issue. We’ll post an update once the fix has been deployed. Thanks for your patience while we get this sorted.

W32/Sasser.WORM alert

MadRat

Lifer
Notice has only been out for a few hours. Go get your updates. Specifically you need MS update Microsoft Security Update MS04-011 if you run Windows XP.

Details:

What You Should Know About the Sasser Worm

Sasser worm begins to spread
Last modified: May 1, 2004, 10:25 AM PDT
By Robert Lemos
Staff Writer, CNET News.com

The Sasser worm began spreading Friday night and seems to be moving at a pace far slower than previous worms such as MSBlast and Code Red, said Alfred Huger, senior director of security firm Symantec's response team.

"It is a slow burn," he said. "It is picking up speed, but right now we aren't seeing to much activity."

Symantec initially rated the Sasser worm as a two on its five-point scale of threats. A five is the highest danger rating on the scale. Rival antivirus firm Network Associates rated the threat a medium danger, and the Internet Storm Center, which monitors network threats, raised its general Internet danger level to yellow, essentially a medium rating as well.

"Due to the release of this worm, we moved to infocon yellow for the next 24 hrs," the Internet Storm Center site said. "The exact impact is not clear at this point."

Security experts did not know how far the worm had spread, but many companies reported some infections, said Vincent Gullotto, vice president of Network Associates' antivirus emergency response team.

"We have had 25 to 50 reports from companies that have had up to a few hundred machines infected," he said. "One company wanted to patch this weekend, but the worm infected their network first."

The creation of the worm didn't surprise the Internet's security community. Security experts widely predicted that a worm would soon start spreading using that particular flaw by exploiting a recent vulnerability in a component of Microsoft Windows known as the Local Security Authority Subsystem Service, or LSASS.

The Sasser worm spreads from infected computer to vulnerable computer with no user intervention required. The worm scans for vulnerable systems, creates a remote connection to the system, installs a file transfer protocol (FTP) server and then downloads itself to the new host.

The worm opens up the initial connection on a specific application data channel, or port, numbered 9996. After the worm infects the new host, the FTP server listens on port 5554 for new files.

The worm uses multiple processes to scan different ranges of Internet addresses. The scans attempt to detect the vulnerable LSASS component on port 445. Microsoft has analyzed the worm and believes it also spreads through port 139. Both are data channels used by the Windows file sharing protocol and, in many cases, are blocked by Internet service providers.

A team of Microsoft engineers worked through the night to analyze the worm, said Stephen Toulouse, security program manager for the software giant.

"We are still studying the worm, but we do know customers that install the update are protected from Sasser," Toulouse said.

The worm will cause the LSASS component of Windows to crash, according to analyses. Infected systems will then perform a 60-second countdown before restarting. Microsoft has created a Web page telling customers how to manually clean up the worm.

Antivirus firms also continue to analyze the worm.
 
This is a serious problem. My antivirus has picked up several propagation attempts in the past few hours!
 
Originally posted by: Psych
This is a serious problem. My antivirus has picked up several propagation attempts in the past few hours!
Grab that free ZoneAlarm firewall software, bro 🙂
 
Oooo, more free firewall softwares! 😎

/me tries one, I never liked ZoneAlarm's user interface anyway 😛
 
ISPs need to start filtering more ports :|

Looks like I have something new to scan for though. I've gotten some neat things off of FTP servers resulting from worms. 😀
 
Originally posted by: Megatomic
I love my router. 🙂
Sitting happy behind my wonderful Netgear router. After going through DLink and SMC with nothing but problems this Netgear has been amazing.
 
As cheap as routers are now I'm surprised more people haven't installed them. They are wonderful for blocking worms and sharing connections.

I am enjoying a sweet Linksys router myself. It looks just like my Linksys cable modem, the blue/charcoal color scheme is very attractive on my desk. :heart:
 
Already got it on the upstairs (wifes and sons) PC....Took it out fast without the update and just updated the fix....

I was onto the Lsass.exe and a AVserve2.exe very fast as they were stealing cycles from my FH projects....HT authority popped up when I was on the net and I said SH*T and routed it out and cleaned it out of the registry. All was fine but I defintely decided to add the patch anyways since it likely wouldn't be the last time it arrived.....


One quick key a tech guy gave me for the newbies who get the shutdown alert.......

Go to Start - Run - and type shutdown /a in the command line....this disables the shutdwon sequence for like 45-60 minutes and gives you plenty of time to get the update installed....
 
Originally posted by: buckmasterson
Originally posted by: ArmchairAthlete
ZoneAlarm... bleh.

Get Sygate or Kerio, they're both free and much better.

http://smb.sygate.com/products/spf_standard.htm

http://www.kerio.com/us/kpf_home.html

Huh, the Sygate link says it's 39$, and the Kerio link says it's freeware is limited. How exactly are these better that Zone Alarm? I'm not being smart, as I know nothing about firewalls. I'd just like to know what's better about them?

Sygate personal is free,it's the pro that's 39$.

As for kerio...
Limited free edition
For home users, Kerio Personal Firewall 4 is available in two flavors - the full edition and the limited free edition.

After installation, KPF works as the full edition for 30 days, after which it becomes the limited free edition.

Limited free edition does not provide the content filtering capabilities such as blocking pop-up windows, ads, VB scripts, cookies, etc. and other extra features. Please see the comparison table for more details.

free too,I would never pay 39$ for firewall software when you can buy a router for that price sometimes even cheaper. 😉
 
Originally posted by: n0cmonkey
Apparently the patch for this was out a couple of weeks ago. Why the hell isn't everyone protected? :|

these days virus makes play on ppls computer-dumbness, they see a security patch, read about the hole and make a virus exploiting that hole, they know that a majority of computer users will NOT have that update, it's just a sad fact, I had autoupdates installed on my sisters and brothers computers, where when there are updates available a small globe comes in yer taskbar when they're ready to install etc, found out they just ignored it, EVEN after I had told them about the importance of patching etc, the average PC user is just simply ignorant and dumb, every Pc I encounter to fix has NO updates installed whatsoever and is virus and adware ridden. the fix I applies wes setting the PC's to forced auto update, that way they dont even have to do anything, it just happens.
 
Originally posted by: n0cmonkey
Apparently the patch for this was out a couple of weeks ago. Why the hell isn't everyone protected? :|


Its obvious not many people are signed up for Microsofts Technet update. If they were, they would of had the patch as you said, installed weeks ago. I noticed that Blink sent out a huge mailer warning people and most likely, finally got peoples attention.

I cant find the link now of TEchnet home but if someone does find it to help others sign up for their security updates, it would probably help a lot of people.
 
Hmm, I guess I had the Win update, and probably AVG was OK too, as I just got a small file from them.

Thanks for the heads up, anyway. :beer:
 
I think my friends got hit by this (non firewalled dialup). For some reason though some emails were deleted and now lots of programs don't work. Figures for not using AntiVirus. 🙁
 
Doesn't Windows Update pop up automatically on the taskbar every time there's a patch ?


How easy does it have to be ?
 
Back
Top