Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Waiting for the Worms
Tim Mullen, 2003-07-21

The hole's been announced, the patch has been released. Now there's nothing to do but wait for the worm to come and wreak its ugly havoc.

Comments Mode:
Waiting for the Worms 2003-07-21
Anonymous (1 replies)
Waiting for the Worms 2003-07-21
Anonymous (1 replies)
Waiting for the Worms 2003-07-22
Anonymous
Waiting for the Worms 2003-07-21
Anonymous (1 replies)
Waiting for the Worms 2003-07-21
blacklight
Waiting for the Worms 2003-07-21
Anonymous
Waiting for the Worms 2003-07-21
Jim Harrison (ISA_Dewd) (1 replies)
Waiting for the Worms 2003-07-24
Anonymous
Waiting for the Worms 2003-07-21
By bet is eEye will still get to name it (1 replies)
Waiting for the Worms 2003-07-21
Anonymous (1 replies)
Waiting for the Worms 2003-07-22
Anonymous (1 replies)
Waiting for the Worms 2003-07-22
Anonymous
Waiting for the Naming 2003-07-21
Rick Deckard (1 replies)
Waiting for the Naming 2003-07-21
Anonymous (2 replies)
Waiting for the Naming 2003-07-21
Rick Deckard (1 replies)
Waiting for the Naming 2003-07-22
Anonymous
Waiting for the Concert 2003-07-22
Anonymous (1 replies)
Waiting for the Concert 2003-07-22
Fatty Boom Cracker (2 replies)
Waiting for the Concert 2003-07-22
Brett Delaney
Waiting for the Concert 2003-07-23
Anonymous
Waiting for the Worms 2003-07-21
Anonymous (3 replies)
It Sounds like you don't have to have port 135 open to the wild to be devastated by this possible worm.

You could have an e-mail that installs it on one machine inside your network.
That machine would then have access to port 135 on of any number of computers on the protected network, say 1 or 2 or thousands of computers.

The virus could then simply infect all computers and then set themselves to format all the computers after a certain time has past.

The infected machine could infect others through port 135, The machines that are protected by anti-virus could simply be formatted without using programs that would alert the ant-virus program.

Make sure local users only have 'user' rights and not 'admin' or 'power user' rights since this will limit the formatting ability of the logged on user or worm program.



[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/174/20967#20967
Waiting for the Worms 2003-07-22
Stack (1 replies)
Waiting for the Worms 2003-07-23
Anonymous
Waiting for the Worms 2003-07-23
Sam Schinke
Bravo 2003-07-21
Anonymous (2 replies)
Bravo? 2003-07-22
Sun Li DlavRot
Bravo 2003-07-23
Anonymous (2 replies)
Bravo 2003-07-25
Brett Delaney
Bravo 2003-07-26
Anonymous
Waiting for the Worms 2003-07-22
Anonymous
Waiting for the Worms 2003-07-22
Dan Jenkins
Waiting for More Info? 2003-07-22
Penguinisto
Waiting for the Worms 2003-07-22
Zap The Dingbat
Waiting for the Worms 2003-07-22
ICMPType8
Waiting for the Worms 2003-07-22
blacklight
Waiting for the Worms 2003-07-23
Anonymous
Waiting for the Worms 2003-07-24
Anonymous
The Making is in The Progress... 2003-07-25
Anonymous (1 replies)
winhack 2003-07-30
Anonymous
Waiting for the Worms 2003-07-28
ziago







 

Privacy Statement
Copyright 2009, SecurityFocus