Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [Full-disclosure] NT4 worm |
|---|---|
| Date: | Wed, 30 Aug 2006 18:11:45 +0300 (EEST) |
Are the machines you have experience especially NT4.0 machines? It appears that one of the PoC's (public on Monday 28th Aug) lists the following information: "Systems Affected: * Microsoft Windows 2000 SP0-SP4 * Microsoft Windows XP SP0-SP1 * Microsoft Windows NT 4.0"
but reportedly it is tested against XPSP1 and W2KSP4 systems.
I believe that fully patched NT4SP6a/SRP shipped with Netapi32.dll is affected.
- Juha-Matti
Has anyone seen a writeup on this new NT4 worm that's spreading via port 139 MS06-040 yet? I'm seeing customers getting hit by it but I haven't seen any real mention of it anywhere yet. It appears to run two CMD.EXE hidden windows and sucks up all the cpu in the infected systems trying to spread. I've also seen one customer who found csrsc.exe on the machine after the worm hit them.
I did manage to find out once it exploits a machine it uses ftp.exe to connect back to the infecting host and transfer something but I've not had time to really dig into this thing. Hoping someone else has already. Looks like it's spreading pretty quick
http://isc.incidents.org/port_details.php?port=139&repax=1&tarax=2&srcax=2&p ercent=N&days=40
Geo.
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: [Full-disclosure] Re: Re: George Bush appoints a 9 year old to be the chairperson of the Information Security Deportment, Paul Schmehl |
|---|---|
| Next by Date: | Re: [Full-disclosure] Re: Re: George Bush appoints a 9 year old to be the chairperson of the Information Security Deportment, Paul Schmehl |
| Previous by Thread: | [Full-disclosure] [SECURITY] [DSA 1163-1] New gtetrinet packages fix arbitrary code execution, Martin Schulze |
| Next by Thread: | RE: [Full-disclosure] NT4 worm, Geo. |
| Indexes: | [Date] [Thread] [Top] [All Lists] |