Sasser
ZXNet echo conference «zxnet.pc»
From Wladimir Bulchukey → To All 5 May 2004
Don't slaughter the cash cow that lays golden eggs, All...!
Folks, after msblast, this is the second infection of similar penetration ability.
THE vilest disgusting thing.
XP - HOLES and MAZDAI.
At work, everyone who is not under my command and with XP caught it.
Patches are required. Patches dated April 14, 3 pieces,
I need one of them, I didn’t specify which one (generally the one lsass
correct), it’s easier to stick everything on ;-) .
To remove the worm, disconnect from the Internet and use Kaspersky
with a fresh database (deletes correctly and cleans the registry - verified),
or manually remove it from %windir%avserve2.exe ,
from %windir%system32 - all detected ?_up.exe ,
remove avserve2.exe from autorun via msconfig,
clear the registry branch indicated below,
Restart your computer and make sure everything is done.
For Windows 2000 and Server 2003 everything is the same.
=== Cut ===
Worm.Win32.Sasser.b
Danger: high
Worm virus.
Distributed over global networks, using
propagation vulnerability in the Microsoft Windows LSASS service. Her
description is given in Microsoft Security Bulletin MS04-011:
http://www.microsoft.com/technet/security/bulletin/MS04-
011.mspx
The worm is written in C/C++ using a compiler
Visual C
Has a size of approx. 15 KB, packed in ZiPack.
Reproduction
When launched, the worm registers itself in the autorun key
system registry:[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersion
Run]
avserve2.exe = %WINDIR%avserve2.exe
The worm scans IP addresses looking for computers that are susceptible to
vulnerability MS04-011. Vulnerable computer on TCP port 9996
launches the command shell "cmd.exe" and accepts the command on
downloading and running a copy of the worm.
Uploading is performed via FTP protocol.
To do this, the worm starts an FTP server on TCP port 5554 and
upon request from a vulnerable computer, it uploads a copy there.
The downloaded copy is named "N_up.exe", where N is a random number.
Copyright since 2000
Kaspersky Lab
All rights reserved
Last update: 05/05/2004
=== Cut ===
With the best - Wlodek # wlblack(@)newmail.ru # http://wlodeks.narod.ru
[ZX] [500:95/462@ZXNet] [2:5016 Forever] [Golyanovo] [Old Russians]
From Wladimir Bulchukey → To All 8 May 2004
=== Cut ===
Protecting your home computer
Protection against PCT/SSL code vulnerabilities
Protection against LSASS code vulnerability
Additional information
Microsoft Security Bulletin MS04-011 (EN)
Microsoft Knowledge Base Article 187498
Terminology
Virus
Network worm (EN)
General information
Microsoft has received reports that there are
Internet software that searches and
exploitation of confirmed vulnerabilities reported in
security patch dated April 13th. The action of these malicious
software is aimed at the Private protocol
Communications Transport (PCT), the implementation of which is included in
Microsoft Secure Sockets Layer (SSL) library. In addition,
a code vulnerability has been confirmed in the LSASS service. Corporation
Microsoft considers the incidents reported to be probable and
serious, and earnestly asks all its clients to
rather install security patch MS04-011 (EN), also
like other important security fixes published
April 13.
Warning: Download and install critical updates
Windows security. Microsoft WindowsR users
New critical updates must be downloaded immediately
Security on the Windows Update website.
Protecting your home computerIf you have already installed security patch MS04-011
(EN), then your computer is already protected. It's always important to take action
necessary measures to ensure computer security.
Take three steps to protect your computer (EN)
Microsoft is doing everything we can to help.
users in maintaining a secure computing environment. This
The page will be updated as information becomes available
How to eliminate this vulnerability.
Protection against PCT/SSL code vulnerabilities
At the moment there is the following on this issue
information.
To avoid risk to users of personal
computers and workstations that are not web servers,
you should install the latest updates by downloading them from the website
Windows Update Download Center.
If you have installed and deployed the patch
security MS04-011 (EN), your system is protected from this
threats.
This vulnerability applies to all programs
using the SSL protocol. Although the SSL protocol is mainly
used by Internet Information Services,
interaction with which is carried out via the HTTP protocol via
port 443, it is likely that any service is vulnerable
implementing the SSL protocol on a platform susceptible to thisthreat. The list of such services includes, but is not limited to
as follows:
Microsoft Internet Information Services 4.0
Microsoft Internet Information Services 5.0
Microsoft Internet Information Services 5.1
Microsoft Exchange Server 5.5
Microsoft Exchange Server 2000
Microsoft Exchange Server 2003
Microsoft Analysis Services 2000 (included with
Microsoft SQL Server¤ 2000)
All third party software that uses
PCT protocol. The vulnerability does not apply to SQL Server 2000.
since it specifically blocks connections via the PCT protocol.
If you have Microsoft Windows XP or Windows OS installed
2000, and SSL support is enabled, your system is under
threat.
If you have Windows Server¤ 2003 deployed and enabled
PCT support in SSL, your system is also at risk.
If you are still evaluating and testing the fix
security MS04 011, you should immediately carry out
actions given on this page to reduce
risk.
Microsoft has tested various methods
protection of PCT/SSL protocol vulnerabilities. Although these measures are not
fix the problem, they can help prevent known
attacks. If the protection method is associated with a restriction
functionality, this will be noted below.Disabling PCT protocol support through the system registry
The method described here is described in detail in article 187498 (EN)
Microsoft Knowledge Base.
This sequence of actions allows you to disable
support for the PCT 1.0 protocol, preventing it from being used
vulnerabilities to attack the system.
Attention! Incorrect use of Registry Editor may
lead to serious problems and the need for reinstallation
operating system. Microsoft does not guarantee
solving problems resulting from incorrect operation of
registry editor. Responsibility for using the editor
The registry is borne by the user. Before making changes to the registry,
Always make a backup copy of it.
Information about editing the system registry can be found in
See 'Changing Keys and Values' in Help
Registry Editor (Regedit.exe) or in the 'Add and
deleting information from the registry' and 'Editing data
registry' help system program Regedt32.exe.
Click the 'Start' button
From Wladimir Bulchukey → To All 9 May 2004
"...And you will accept death from your worm!"
=== Cut ===
08.05 14:23 http://lenta.ru/internet/2004/05/08/sasser/
ALLEGED AUTHOR OF SASSER WORM DETAINED IN GERMANY
On Friday, an 18-year-old was detained in Lower Saxony, Germany.
summer schoolboy suspected of creating the Sasser Internet worm,
which caused another epidemic in early May.
The alleged author of the worm lived with his parents in the town of
Waffensen near Rothenburg.
According to the Associated Press, citing a representative.
local criminal investigation department, during a search of the suspect’s house there were
Evidence of his involvement in the creation of the virus has been discovered.
=== Cut ===