Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: Virus Outbreak Attacking MS05-039 |
|---|---|
| Date: | Tue, 16 Aug 2005 06:17:34 +1200 |
I don't believe you can exploit MS05-039 on anything other than 445, Note that this thing doesn't spread via 445 it gains access through the exploit to start an FTP session and spreads via FTP. Of course it's always possible that the virus switches to a different vulnerability, it does have the ability to update but then we would be talking about a new variant. Mike -----Original Message----- From: Meni Milstein [mailto:meni@menimilstein.com] Sent: Tuesday, August 16, 2005 7:08 AM To: 'Ziots, Edward'; 'Mike' Cc: focus-virus@securityfocus.com Subject: RE: Virus Outbreak Attacking MS05-039 Wow... what I meant to bring up was the question whether there was some other way this thing is spreading OTHER than 445 TCP. Meni. -----Original Message----- From: Ziots, Edward [mailto:EZiots@Lifespan.org] Sent: Monday, August 15, 2005 7:58 PM To: 'Meni Milstein'; 'Mike' Cc: focus-virus@securityfocus.com Subject: RE: Virus Outbreak Attacking MS05-039 Well think of other avenues of attack, VPN, Dial-up unpatches systems being connected to your systems by vendors, just many many ways around the fun "firewall will protect us from everything" Z Edward Ziots Network Engineer Windows/Citrix Administrator Lifespan Organization MCSE,MCSA,MCP+I,M.E,CCA, Security +, Network + eziots@lifespan.org 401-639-3505 (Cell) 401-444-6926 (Office) 401-350-5284 (Pager) -----Original Message----- From: Meni Milstein [mailto:meni@menimilstein.com] Sent: Monday, August 15, 2005 2:00 PM To: 'Mike' Cc: focus-virus@securityfocus.com Subject: RE: Virus Outbreak Attacking MS05-039 As far as I know, if you are firewalled correctly and have your 445 tcp port shut to the outside - this thing should NOT be able to get in. Am I wrong? Meni Milstein. http://www.lcs-guides.com -----Original Message----- From: Mike [mailto:mjcarter@ihug.co.nz] Sent: Monday, August 15, 2005 3:41 PM To: focus-virus@securityfocus.com Subject: Virus Outbreak Attacking MS05-039 Hi List, Yesterday one of my customers was hit hard by what appears to be a variant of zotob. http://securityresponse.symantec.com/avcenter/venc/data/w32.zotob.b.html This one was very (noisy) crashing services.exe and forcing re-boots on unpatched WIN2K machines. The boxes we've had a chance to look at were not infected, but were unpatched. We hope to have samples today from the same network and have a closer look. It's time to get patching! Regards Mike Mike Information Security and Logistics www.infosec.co.nz
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: Virus Outbreak Attacking MS05-039, Paul Schmehl |
|---|---|
| Next by Date: | RE: zotob, Brady McClenon |
| Previous by Thread: | RE: Virus Outbreak Attacking MS05-039, Meni Milstein |
| Next by Thread: | Re: Virus Outbreak Attacking MS05-039, Chris Wensink |
| Indexes: | [Date] [Thread] [Top] [All Lists] |