, SecurityFocus 2003-08-11
A malicious worm that exploits last month's RPC DCOM vulnerability struck the Internet Monday afternoon, targeting unpatched Windows 2000 and Windows XP machines.
Expand all |
Post comment
RPC DCOM Worm Hits the Net
2003-08-11
Manu (4 replies)
Manu (4 replies)
RPC DCOM Worm Hits the Net
2003-08-12
Anonymous (3 replies)
Anonymous (3 replies)
RPC DCOM Worm Hits the Net
2003-08-12
Christopher Canova (2 replies)
Christopher Canova (2 replies)
RPC DCOM Worm Hits the Net
2003-08-12
Anonymous (1 replies)
Anonymous (1 replies)
RPC DCOM Worm Hits the Net
2003-08-12
Scott Miller <smiller (at) secureadmin (dot) ca [email concealed]>
Scott Miller <smiller (at) secureadmin (dot) ca [email concealed]>
RPC DCOM Worm Hits the Net
2003-08-12
Nrik (1 replies)
Nrik (1 replies)
RPC DCOM Worm Hits the Net
2003-08-12
Scott Miller <smiller (at) secureadmin (dot) ca [email concealed]> (1 replies)
Scott Miller <smiller (at) secureadmin (dot) ca [email concealed]> (1 replies)
Took down our NT Network (500 Plus users)
2003-08-12
Anonymous (8 replies)
Anonymous (8 replies)
Took down our NT Network (500 Plus users)
2003-08-12
Anonymous (7 replies)
Anonymous (7 replies)
Took down our NT Network (500 Plus users)
2003-08-12
Anonymous (3 replies)
Anonymous (3 replies)
Took down our NT Network (500 Plus users)
2003-08-12
Anonymous (3 replies)
Anonymous (3 replies)
Took down our NT Network (500 Plus users)
2003-08-12
Anonymous (1 replies)
Anonymous (1 replies)
Windows Update is FREAKING AUTOMATIC!
2003-08-12
Anonymous (6 replies)
Anonymous (6 replies)
Windows Update is FREAKING AUTOMATIC!
2003-08-12
Big Guys (2 replies)
Big Guys (2 replies)
Windows Update is FREAKING AUTOMATIC!
2003-08-12
Anonymous (1 replies)
Anonymous (1 replies)
Took down our NT Network (500 Plus users)
2003-08-12
Anonymous (1 replies)
Anonymous (1 replies)
to little to late
2003-08-12
Anonymous (2 replies)
Anonymous (2 replies)
500 users went home early, yet we paid them. MS SUCKS!
2003-08-12
Anonymous (1 replies)
Anonymous (1 replies)
Took down our NT Network (500 Plus users)
2003-08-12
Anonymous (2 replies)
Anonymous (2 replies)
Took down our NT Network (500 Plus users)
2003-08-12
Anonymous (1 replies)
Anonymous (1 replies)
RPC DCOM Worm Hits the Net
2003-08-12
Federico Lucifredi (2 replies)
Federico Lucifredi (2 replies)
RPC DCOM Worm Hits the Net
2003-08-12
Jeff Serino (1 replies)
Jeff Serino (1 replies)
Anyone identified initial infection vector?
2003-08-12
Anonymous (1 replies)
Anonymous (1 replies)
Anyone identified initial infection vector?
2003-08-12
Anonymous (1 replies)
Anonymous (1 replies)
Anyone identified initial infection vector?
2003-08-12
Chris S (2 replies)
Chris S (2 replies)
Open letter to Bill Gates........
2003-08-12
Anonymous (1 replies)
Anonymous (1 replies)
Open letter to Bill Gates........
2003-08-12
Anonymous (1 replies)
Anonymous (1 replies)
Open letter to Bill Gates........
2003-08-12
Anonymous (3 replies)
Anonymous (3 replies)
RPC DCOM Worm Hits the Net
2003-08-12
AnonymousAdmin (1 replies)
AnonymousAdmin (1 replies)
RPC DCOM Worm Hits the Net
2003-08-12
Anonymous (2 replies)
Anonymous (2 replies)
RPC DCOM Worm Hits the Net
2003-08-12
Anonymous (1 replies)
Anonymous (1 replies)
RPC DCOM Worm Hits the Net
2003-08-13
Scott Moreau <smoreau (at) secureadmin (dot) ca [email concealed]>
Scott Moreau <smoreau (at) secureadmin (dot) ca [email concealed]>
RPC DCOM Worm Hits the Net - but without any executeable
2003-08-14
Anonymous (Lost user) that needs opinion (1 replies)
Anonymous (Lost user) that needs opinion (1 replies)

First indicators of infection hit a Florida installation on Thursday PM (8/11 - EST). Users being as they are, this was reported indirectly to the IS dept Monday AM. Research indicates that an external system attached to DSL was infected at the same time. An additional system attached to DSL appears to have suffered infection late PM on Friday.
The most dominant indicator of a compromised system (under W2K) is that the user's desktop does not appear during the boot process. The task manager indicates that explorer.exe is running, it simply does nothing.
Running explorer.exe will display the desktop but the system will not perform correctly. The following functions are confirmed affected:
-Copy/Move files - Disabled
-Network Connections - No adaptors displayed on list
-"Program Files" directory - won't list files (can still get to the individual directories).
- User Settings - Can not access advanced properties.
- File Window Displays - only shows left 1/3 of window (sometimes with a scroll bar?).
- Search/Find is disabled
- Update.microsoft.com does not seem to display (not confirmed on all systems)
This is only what I've observed dealing with these systems for the last several hours, and do not represent a complete list of disabled functions.
These exact symptoms have duplicated on computers attached to 2 separate DSL systems (Atlanta, Orlando)in addition to several attached to a corporate network.
Infection occurs across the network (no user action involved). An attempt to reinstall W2K while attached to the network (predictably) resulted in infection at first boot (or net component installation?).
Is this the same RPC issue? Or is there a nastier variant in the wild that is not yet discussed? Or is this a separate known problem?
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/articles/6689/21215#21215