Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
RPC DCOM Worm Hits the Net
Kevin Poulsen, SecurityFocus 2003-08-11

A malicious worm that exploits last month's RPC DCOM vulnerability struck the Internet Monday afternoon, targeting unpatched Windows 2000 and Windows XP machines.

Comments Mode:
RPC DCOM Worm Hits the Net 2003-08-11
Manu (4 replies)
RPC DCOM Worm Hits the Net 2003-08-12
Anonymous (3 replies)
RPC DCOM Worm Hits the Net 2003-08-12
Christopher Canova (2 replies)
RPC DCOM Worm Hits the Net 2003-08-13
Tim Watkins (1 replies)
RPC DCOM Worm Hits the Net 2003-08-13
Anonymous
RPC DCOM Worm Hits the Net 2003-08-13
BroadBand Man
RPC DCOM Worm Hits the Net 2003-08-12
Jean Debogue (1 replies)
You were warned and chose not to act. 2003-08-13
You_people_are_KILLING_me
RPC DCOM Worm Hits the Net 2003-08-13
bogaboga
RPC DCOM Worm Hits the Net 2003-08-12
Tasawar Jalali
RPC DCOM Worm Hits the Net 2003-08-13
Anonymous
RPC DCOM Worm Hits the Net 2003-08-13
gpnuke
RPC DCOM Worm Hits the Net 2003-08-11
Conrad Longmore
msblast.exe available 2003-08-11
Chris McNab
RPC DCOM Worm Hits the Net 2003-08-12
moonface (1 replies)
RPC DCOM Worm Hits the Net 2003-08-12
Anonymous
RPC DCOM Worm Hits the Net 2003-08-12
Anonymous (1 replies)
RPC DCOM Worm Hits the Net 2003-08-12
Scott Miller <smiller (at) secureadmin (dot) ca [email concealed]>
RPC DCOM Worm Hits the Net 2003-08-12
Nrik (1 replies)
RPC DCOM Worm Hits the Net 2003-08-12
Scott Miller <smiller (at) secureadmin (dot) ca [email concealed]> (1 replies)
RPC DCOM Worm Hits the Net 2003-08-12
Anonymous
RPC DCOM Worm Hits the Net 2003-08-12
KGB (1 replies)
RPC DCOM Worm Hits the Net 2003-08-12
Vegomatic
RPC DCOM Worm Hits the Net 2003-08-12
Anonymous
RPC DCOM Worm Hits the Net 2003-08-12
Anonymous
RPC DCOM Worm Hits the Net 2003-08-12
mike (at) thompsonmike.co (dot) uk [email concealed]
Took down our NT Network (500 Plus users) 2003-08-12
Anonymous (8 replies)
Took down our NT Network (500 Plus users) 2003-08-12
Anonymous (7 replies)
who is what? 2003-08-12
Anonymous
Took down our NT Network (500 Plus users) 2003-08-12
Anonymous (3 replies)
Took down our NT Network (500 Plus users) 2003-08-12
Anonymous (1 replies)
Reading sec forums 2003-08-13
Anonymous (1 replies)
Reading sec forums 2003-08-15
Jagdwulfe
Took down our NT Network (500 Plus users) 2003-08-12
Anonymous (2 replies)
Took down our NT Network (500 Plus users) 2003-08-13
A clueful IT guy in Canada
Took down our NT Network (500 Plus users) 2003-08-12
Anonymous (1 replies)
Windows Update is FREAKING AUTOMATIC! 2003-08-12
Anonymous (6 replies)
Windows Update is FREAKING AUTOMATIC! 2003-08-12
Big Guys (2 replies)
Windows Update is FREAKING AUTOMATIC! 2003-08-12
Anonymous (1 replies)
Windows Update is FREAKING AUTOMATIC! 2003-08-13
Anonymous (1 replies)
...on a frigging server? Are you NUTS!? 2003-08-12
Penguinisto (1 replies)
...on a frigging server? Are you NUTS!? 2003-08-13
Fortune_50_IT_Manager
Windows Update is FREAKING AUTOMATIC! 2003-08-12
AnotherAnonymous
Windows Update is FREAKING AUTOMATIC! 2003-08-13
HardKnox (1 replies)
Took down our NT Network (500 Plus users) 2003-08-12
Anonymous (1 replies)
Took down our NT Network (500 Plus users) 2003-08-12
Anonymous (1 replies)
to little to late 2003-08-12
Anonymous (2 replies)
to little to late 2003-08-12
Scott Miller <smiller (at) secureadmin (dot) ca [email concealed]>
Took down our NT Network (500 Plus users) 2003-08-12
Anonymous (2 replies)
Took down our NT Network (500 Plus users) 2003-08-13
Anonymous (1 replies)
Huh?! 2003-08-12
BLKMGK (1 replies)
Huh?! 2003-08-13
vapour
Took down our NT Network (500 Plus users) 2003-08-12
Anonymous (1 replies)
Took down our NT Network (500 Plus users) 2003-08-12
Anonymous (1 replies)
Why did you have port 135 open 2003-08-13
Anonymous (1 replies)
Why did you have port 135 open 2003-08-14
Anonymous
RPC DCOM Worm Hits the Net 2003-08-12
Federico Lucifredi (2 replies)
RPC DCOM Worm Hits the Net 2003-08-12
Cipherz (1 replies)
RPC DCOM Worm Hits the Net 2003-08-12
Anonymous
RPC DCOM Worm Hits the Net 2003-08-12
Wichita_KS_NETOPS (2 replies)
RPC DCOM Worm Hits the Net 2003-08-12
obyteme
RPC DCOM Worm Hits the Net 2003-08-12
Anonymous
RPC DCOM Worm Hits the Net 2003-08-12
Chris S (1 replies)
Single IP? 2003-08-12
BLKMGK
RPC DCOM Worm cleanup details 2003-08-12
Barry Irwin <bvi (at) moria (dot) org [email concealed]>
RPC DCOM Worm Hits the Net 2003-08-12
Anonymous
RPC DCOM Worm Hits the Net 2003-08-12
Sunfire070
RPC DCOM Worm Hits the Net 2003-08-12
Anonymous
I patched 2003-08-12
Anonymous
RPC DCOM Worm Hits the Net 2003-08-12
kl3675
RPC DCOM Worm Hits the Net 2003-08-12
Anonymous
RPC DCOM Worm Hits the Net 2003-08-12
HardKnox
RPC DCOM Worm Hits the Net 2003-08-12
apsu_of_freshwater
RPC DCOM Worm Hits the Net 2003-08-12
Jeff Serino (1 replies)
RPC DCOM Worm Hits the Net 2003-08-12
Federico Lucifredi (1 replies)
RPC DCOM Worm Hits the Net 2003-08-13
HardKnox
RPC DCOM Worm Hits the Net 2003-08-12
Anonymous
Anyone identified initial infection vector? 2003-08-12
Anonymous (1 replies)
Anyone identified initial infection vector? 2003-08-12
Anonymous (1 replies)
Anyone identified initial infection vector? 2003-08-12
Chris S (2 replies)
That should be obvious to all these "IT" guys. 2003-08-13
You_people_are_KILLING_me (1 replies)
portable users 2003-08-14
Scott Miller <smiller (at) secureadmin (dot) ca [email concealed]>
RPC DCOM Worm Hits the Net 2003-08-12
Anonymous
RPC DCOM Worm Hits the Net 2003-08-12
Anonymous
Mixed Results (Utah) 2003-08-12
Penguinisto
Open letter to Bill Gates........ 2003-08-12
Anonymous (1 replies)
Open letter to Bill Gates........ 2003-08-12
Anonymous (1 replies)
Open letter to Bill Gates........ 2003-08-12
Anonymous (3 replies)
Open letter to Bill Gates........ 2003-08-12
Anonymous
Open letter to Bill Gates........ 2003-08-12
Anonymous (2 replies)
Open letter to Bill Gates........ 2003-08-13
Fortune_50_IT_Manager
Managing Your Security Profile 2003-08-13
Anonymous
Open letter to Bill Gates........ 2003-08-13
Anonymous
RPC DCOM Worm Hits the Net 2003-08-12
AnonymousAdmin (1 replies)
RPC DCOM Worm Hits the Net 2003-08-12
Anonymous (2 replies)
RPC DCOM Worm Hits the Net 2003-08-12
Anonymous (1 replies)
RPC DCOM Worm Hits the Net 2003-08-13
A clueful IT guy in Canada (2 replies)
RPC DCOM Worm Hits the Net 2003-08-13
Fortune_50_IT_Manager
RPC DCOM Worm Hits the Net 2003-08-13
apsu_of_freshwater
RPC DCOM Worm Hits the Net 2003-08-13
AnonymousAdmin (1 replies)
What if the ratios were reversed? 2003-08-14
Fortune_50_IT_Manager
RPC DCOM Worm Hits the Net 2003-08-12
Anonymous
RPC DCOM Worm 2003-08-12
B
RPC DCOM Worm Hits the Net 2003-08-13
Anonymous (1 replies)
RPC DCOM Worm Hits the Net 2003-08-13
AnonymousAdmin
RPC DCOM Worm Hits the Net 2003-08-13
Scott Moreau <smoreau (at) secureadmin (dot) ca [email concealed]>
A what? 2003-08-13
Anonymous
National Security 2003-08-13
Duke Nukem
RPC DCOM Worm Hits the Net 2003-08-13
Anonymous
RPC DCOM Worm Hits the Net 2003-08-13
Anonymous
SVCHOST.EXE "crash" 2003-08-13
Anonymous
RPC DCOM Worm Hits the Net 2003-08-13
Anonymous
New Dell XP laptop was not installed with patch! 2003-08-13
Anti-Dell customer (1 replies)
New Dell XP laptop was not installed with patch! 2003-08-15
Some people, really!
RPC DCOM Worm Hits the Net 2003-08-13
Anonymous
RPC DCOM Worm Hits the Net 2003-08-13
Anonymous
RPC DCOM Worm Hits the Net 2003-08-14
ButtCovered
RPC DCOM Worm Hits the Net 2003-08-14
Anonymous
RPC DCOM Worm - treat it as a vaccin 2003-08-14
ultravioletu
RPC DCOM Worm Hits the Net - but without any executeable 2003-08-14
Anonymous (Lost user) that needs opinion (1 replies)
BIG Providers Decided to Turn Off Ports 2003-08-14
Scott Moulton
Through a firewall?? 2003-08-14
KyleTek
Anti-virus prevention is not segregated to patches 2003-08-15
Canada (1 replies)
I apologize if I missed this in one of the previous postings, but whatever happened to anti-virus or simple ACL's on your core network to prevent propagation of the worm throughout your network? Or am I the only that realizes that virus prevention is not simply segregated to patch updates from vendors?

As soon as the information was released on the worm via CERT and other reliable security resources such as; symantec and of course security focus - you KNEW full well that the propagation is done via 69/udp ... how about something like the following on your cores:

access-list 100 deny udp any any eq 69 log

access-list 100 permit ip any any

So check your syslog servers for any outbreak, it's really simple:

grep -i '169 denied' | grep -v | awk '{print }' | cut -d( -f1 | sort -u | uniq -c | mail -s "whatever"

Cron it and voila, notifications within 5 minutes.

Yes I realize that scanning could potentially cause a DoS, but if you were fairly knowledgeable about this little work of art - it only had a 40% chance of scanning the network in which your machine resided on.

Windows will contiune to function as it does not have a heavy reliance on tftp ... *NIX surprisingly enough, UNIX figured out (10 years ago I believe) that a completely unsecure protocol such as tftp is not a wise process to leave running after system install ... *sigh*

Something as simple as the above will segregate the propagation and will help keep the spread segregated to each floor/building (depending on how smart some of you were when you designed your network). That way you can deploy the necessary teams to clean and patch the virus ...

Complete prevention is of course a whole other issue - many factors are included: internal processes for patch deployments, anti-virus use for VPN and local users, and of course budget!

Just my .02

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/6689/21481#21481







 

Privacy Statement
Copyright 2008, SecurityFocus