Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: wintbp.exe |
|---|---|
| Date: | Tue, 16 Aug 2005 23:36:01 -0400 |
Despite what Russ Cooper posted on NTBugtraq two years ago in the wake of Blaster, that is NOT true (and wasn't true then). While Blaster, Sasser, and the recent MS05-039 exploits rely on a buffer overflow for a remote infection mechanism, they all use the vulnerability to download an infectuous executable to the target system, and av absolutely can prevent the infection if sigs are in place. These are different from pure memory worms like Code Red and SQL Slammer. Also, McAfee for a while has had defenses in place for pure memory worms, and I believe several other vendors have it in place now. Regards, Gaby -----Original Message----- From: Joswiak, Johnny G. [mailto:jgjoswia@UTMB.EDU] Sent: Tuesday, August 16, 2005 11:16 PM To: womalley@cmu.edu; Schlegel, Justin; focus-virus@securityfocus.com Subject: RE: wintbp.exe CA is calling it Win32.Peabot.A with a "Medium" alert, McAfee is calling it "W32/IRCbot.worm!MS05-039", Symantec has the Zotob.e, etcetera. Patch the systems, this is an MS05-039 exploit. The various antivirus companies can only provide cleanup after the worm hits unless they have buffer overflow protection like VSE8.0i provides (ok a plug but I like it). Hope this helps. Johnny -----Original Message----- From: William O'Malley [mailto:wo@andrew.cmu.edu] Sent: Tue 8/16/2005 8:51 PM To: Schlegel, Justin; focus-virus@securityfocus.com Cc: Subject: Re: wintbp.exe __________________ This e-mail is sent by a law firm and contains information that may be privileged and confidential. If you are not the intended recipient, please delete the e-mail and notify us immediately.
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: wintbp.exe, Martin Chester - cmarti |
|---|---|
| Next by Date: | Re: wintbp.exe, jayjwa |
| Previous by Thread: | RE: wintbp.exe, Martin Chester - cmarti |
| Next by Thread: | RE: wintbp.exe, Joswiak, Johnny G. |
| Indexes: | [Date] [Thread] [Top] [All Lists] |