Sasser

ZXNet echo conference «zxnet.pc»

From Wladimir Bulchukey To All 5 May 2004

Don't slaughter the cash cow that lays golden eggs, All...! Folks, after msblast, this is the second infection of similar penetration ability. THE vilest disgusting thing. XP - HOLES and MAZDAI. At work, everyone who is not under my command and with XP caught it. Patches are required. Patches dated April 14, 3 pieces, I need one of them, I didn’t specify which one (generally the one lsass correct), it’s easier to stick everything on ;-) . To remove the worm, disconnect from the Internet and use Kaspersky with a fresh database (deletes correctly and cleans the registry - verified), or manually remove it from %windir%avserve2.exe , from %windir%system32 - all detected ?_up.exe , remove avserve2.exe from autorun via msconfig, clear the registry branch indicated below, Restart your computer and make sure everything is done. For Windows 2000 and Server 2003 everything is the same. === Cut === Worm.Win32.Sasser.b Danger: high Worm virus. Distributed over global networks, using propagation vulnerability in the Microsoft Windows LSASS service. Her description is given in Microsoft Security Bulletin MS04-011: http://www.microsoft.com/technet/security/bulletin/MS04- 011.mspx The worm is written in C/C++ using a compiler Visual C Has a size of approx. 15 KB, packed in ZiPack. Reproduction When launched, the worm registers itself in the autorun key system registry:[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersion Run] avserve2.exe = %WINDIR%avserve2.exe The worm scans IP addresses looking for computers that are susceptible to vulnerability MS04-011. Vulnerable computer on TCP port 9996 launches the command shell "cmd.exe" and accepts the command on downloading and running a copy of the worm. Uploading is performed via FTP protocol. To do this, the worm starts an FTP server on TCP port 5554 and upon request from a vulnerable computer, it uploads a copy there. The downloaded copy is named "N_up.exe", where N is a random number. Copyright since 2000 Kaspersky Lab All rights reserved Last update: 05/05/2004 === Cut === With the best - Wlodek # wlblack(@)newmail.ru # http://wlodeks.narod.ru [ZX] [500:95/462@ZXNet] [2:5016 Forever] [Golyanovo] [Old Russians]

From Wladimir Bulchukey To All 8 May 2004

=== Cut === Protecting your home computer Protection against PCT/SSL code vulnerabilities Protection against LSASS code vulnerability Additional information Microsoft Security Bulletin MS04-011 (EN) Microsoft Knowledge Base Article 187498 Terminology Virus Network worm (EN) General information Microsoft has received reports that there are Internet software that searches and exploitation of confirmed vulnerabilities reported in security patch dated April 13th. The action of these malicious software is aimed at the Private protocol Communications Transport (PCT), the implementation of which is included in Microsoft Secure Sockets Layer (SSL) library. In addition, a code vulnerability has been confirmed in the LSASS service. Corporation Microsoft considers the incidents reported to be probable and serious, and earnestly asks all its clients to rather install security patch MS04-011 (EN), also like other important security fixes published April 13. Warning: Download and install critical updates Windows security. Microsoft WindowsR users New critical updates must be downloaded immediately Security on the Windows Update website. Protecting your home computerIf you have already installed security patch MS04-011 (EN), then your computer is already protected. It's always important to take action necessary measures to ensure computer security. Take three steps to protect your computer (EN) Microsoft is doing everything we can to help. users in maintaining a secure computing environment. This The page will be updated as information becomes available How to eliminate this vulnerability. Protection against PCT/SSL code vulnerabilities At the moment there is the following on this issue information. To avoid risk to users of personal computers and workstations that are not web servers, you should install the latest updates by downloading them from the website Windows Update Download Center. If you have installed and deployed the patch security MS04-011 (EN), your system is protected from this threats. This vulnerability applies to all programs using the SSL protocol. Although the SSL protocol is mainly used by Internet Information Services, interaction with which is carried out via the HTTP protocol via port 443, it is likely that any service is vulnerable implementing the SSL protocol on a platform susceptible to thisthreat. The list of such services includes, but is not limited to as follows: Microsoft Internet Information Services 4.0 Microsoft Internet Information Services 5.0 Microsoft Internet Information Services 5.1 Microsoft Exchange Server 5.5 Microsoft Exchange Server 2000 Microsoft Exchange Server 2003 Microsoft Analysis Services 2000 (included with Microsoft SQL Server¤ 2000) All third party software that uses PCT protocol. The vulnerability does not apply to SQL Server 2000. since it specifically blocks connections via the PCT protocol. If you have Microsoft Windows XP or Windows OS installed 2000, and SSL support is enabled, your system is under threat. If you have Windows Server¤ 2003 deployed and enabled PCT support in SSL, your system is also at risk. If you are still evaluating and testing the fix security MS04 011, you should immediately carry out actions given on this page to reduce risk. Microsoft has tested various methods protection of PCT/SSL protocol vulnerabilities. Although these measures are not fix the problem, they can help prevent known attacks. If the protection method is associated with a restriction functionality, this will be noted below.Disabling PCT protocol support through the system registry The method described here is described in detail in article 187498 (EN) Microsoft Knowledge Base. This sequence of actions allows you to disable support for the PCT 1.0 protocol, preventing it from being used vulnerabilities to attack the system. Attention! Incorrect use of Registry Editor may lead to serious problems and the need for reinstallation operating system. Microsoft does not guarantee solving problems resulting from incorrect operation of registry editor. Responsibility for using the editor The registry is borne by the user. Before making changes to the registry, Always make a backup copy of it. Information about editing the system registry can be found in See 'Changing Keys and Values' in Help Registry Editor (Regedit.exe) or in the 'Add and deleting information from the registry' and 'Editing data registry' help system program Regedt32.exe. Click the 'Start' button

From Wladimir Bulchukey To All 9 May 2004

"...And you will accept death from your worm!" === Cut === 08.05 14:23 http://lenta.ru/internet/2004/05/08/sasser/ ALLEGED AUTHOR OF SASSER WORM DETAINED IN GERMANY On Friday, an 18-year-old was detained in Lower Saxony, Germany. summer schoolboy suspected of creating the Sasser Internet worm, which caused another epidemic in early May. The alleged author of the worm lived with his parents in the town of Waffensen near Rothenburg. According to the Associated Press, citing a representative. local criminal investigation department, during a search of the suspect’s house there were Evidence of his involvement in the creation of the virus has been discovered. === Cut ===