Velocity Reviews

Velocity Reviews (http://www.velocityreviews.com/forums/index.php)
-   NZ Computing (http://www.velocityreviews.com/forums/f47-nz-computing.html)
-   -   Sasser scanner/removal tool (http://www.velocityreviews.com/forums/t570478-sasser-scanner-removal-tool.html)

Brett Roberts 05-03-2004 08:59 PM

Sasser scanner/removal tool
 
http://www.microsoft.com/security/incident/sasser.asp


Brett Roberts
Microsoft NZ



T.N.O. - Dave.net.nz 05-03-2004 09:30 PM

Re: Sasser scanner/removal tool
 
Brett Roberts wrote:
> http://www.microsoft.com/security/incident/sasser.asp


heh, thanks... grabbed for workmates brother.

--
Dave Hall
http://Dave.net.nz
We have Hangman, Pacman, and Space Invaders


Ray Greene 05-04-2004 02:11 AM

Re: Sasser scanner/removal tool
 
On Tue, 4 May 2004 08:59:05 +1200, "Brett Roberts"
<brettrob@abcmicrosoftxyz.com> wrote:

>http://www.microsoft.com/security/incident/sasser.asp


People should be aware that there is a serious bug with this patch. It can
cause a PC to be unable to load a driver on startup and to freeze while
trying to do so, by using all the CPU time. Some info is at
http://support.microsoft.com/default...b;EN-US;841382

It can happen with any driver apparently. It affected our file server and
locked it up while trying to load the driver for the RAID card. This was
early morning just before everyone turned up for work. Fortunately our
backups are on removable hard drives and not tapes, so the backup machine
became a file server for the day.

The patch can be uninstalled through Add/Remove Programs (Windows Hotfix
KB835732) but even in safe mode our machine was running so slowly it took
some hours to complete the uninstall.

There are no warnings about this on Microsoft Security Bulletin MS04-011.

We will being installing a Linux file server in the next week or so. We can
cope with viruses and vulnerabilities etc but having to rely on MS-supplied
"fixes" which can kill critical machines without warning is simply too
dangerous.

Ray Greene.

T.N.O. - Dave.net.nz 05-04-2004 02:21 AM

Re: Sasser scanner/removal tool
 
Ray Greene wrote:
> We will being installing a Linux file server in the next week or so. We can
> cope with viruses and vulnerabilities etc but having to rely on MS-supplied
> "fixes" which can kill critical machines without warning is simply too
> dangerous.


Any patches from anywhere can kill critical machines without warning...

if the machine is critical, why does it have access to the net?


--
Dave Hall
http://Dave.net.nz
We have Hangman, Pacman, and Space Invaders


Enkidu 05-04-2004 02:40 AM

Re: Sasser scanner/removal tool
 
On Tue, 4 May 2004 08:59:05 +1200, "Brett Roberts"
<brettrob@abcmicrosoftxyz.com> wrote:
>
>http://www.microsoft.com/security/incident/sasser.asp
>

Hi Brett,

Thanks for that. Just a bit of feedback - I ran the thing and it ended
silently - that is, it didn't say "not found" or "virus found". Now I
only ran it experimentally since I don't have the virus, but it would
have been nice if it had told me so!

Cheers,

Cliff

Brett Roberts 05-04-2004 03:05 AM

Re: Sasser scanner/removal tool
 
"Enkidu" <enkidu@xyzcliffpxyz.com> wrote in message
news:hh0e90hndfeqgg75vq8fg7es4cmpd3sj7h@4ax.com...
> On Tue, 4 May 2004 08:59:05 +1200, "Brett Roberts"
> <brettrob@abcmicrosoftxyz.com> wrote:
>>
>>http://www.microsoft.com/security/incident/sasser.asp
>>

> Hi Brett,
>
> Thanks for that. Just a bit of feedback - I ran the thing and it ended
> silently - that is, it didn't say "not found" or "virus found". Now I
> only ran it experimentally since I don't have the virus, but it would
> have been nice if it had told me so!
>
> Cheers,
>
> Cliff


Thanks Cliff, this is good feedback. I will forward to the people who built
the scanner tool



Brett Roberts 05-04-2004 03:09 AM

Re: Sasser scanner/removal tool
 
"Ray Greene" <ray.greene@icsc.co.nz> wrote in message
news:IZClc.89$XI4.1566@news.xtra.co.nz...
> On Tue, 4 May 2004 08:59:05 +1200, "Brett Roberts"
> <brettrob@abcmicrosoftxyz.com> wrote:
>
>>http://www.microsoft.com/security/incident/sasser.asp

>
> People should be aware that there is a serious bug with this patch. It can
> cause a PC to be unable to load a driver on startup and to freeze while
> trying to do so, by using all the CPU time. Some info is at
> http://support.microsoft.com/default...b;EN-US;841382
>
> It can happen with any driver apparently. It affected our file server and
> locked it up while trying to load the driver for the RAID card. This was
> early morning just before everyone turned up for work. Fortunately our
> backups are on removable hard drives and not tapes, so the backup machine
> became a file server for the day.
>
> The patch can be uninstalled through Add/Remove Programs (Windows Hotfix
> KB835732) but even in safe mode our machine was running so slowly it took
> some hours to complete the uninstall.
>
> There are no warnings about this on Microsoft Security Bulletin MS04-011.
>
> We will being installing a Linux file server in the next week or so. We
> can
> cope with viruses and vulnerabilities etc but having to rely on
> MS-supplied
> "fixes" which can kill critical machines without warning is simply too
> dangerous.
>
> Ray Greene.


Hi Ray, I'm sorry to hear about the hassles you ran into applying MS04-011.
Please let me know via nz.comp or by calling me on (09) 3575800 if you need
any technical support in remedying the problems.



Patrick Dunford 05-04-2004 03:56 AM

Re: Sasser scanner/removal tool
 
Ray Greene
> On Tue, 4 May 2004 08:59:05 +1200, "Brett Roberts"
> <brettrob@abcmicrosoftxyz.com> wrote:
>
> >http://www.microsoft.com/security/incident/sasser.asp

>
> People should be aware that there is a serious bug with this patch. It can
> cause a PC to be unable to load a driver on startup and to freeze while
> trying to do so, by using all the CPU time. Some info is at
> http://support.microsoft.com/default...b;EN-US;841382
>
> It can happen with any driver apparently. It affected our file server and
> locked it up while trying to load the driver for the RAID card. This was
> early morning just before everyone turned up for work. Fortunately our
> backups are on removable hard drives and not tapes, so the backup machine
> became a file server for the day.
>
> The patch can be uninstalled through Add/Remove Programs (Windows Hotfix
> KB835732) but even in safe mode our machine was running so slowly it took
> some hours to complete the uninstall.
>
> There are no warnings about this on Microsoft Security Bulletin MS04-011.


I did read some warnings about these patches on the MS site so the info
is there, I understand Windows 2000 has had some problems with it

Patrick Dunford 05-04-2004 03:56 AM

Re: Sasser scanner/removal tool
 
T.N.O. - Dave.net.nz
> Ray Greene wrote:
> > We will being installing a Linux file server in the next week or so. We can
> > cope with viruses and vulnerabilities etc but having to rely on MS-supplied
> > "fixes" which can kill critical machines without warning is simply too
> > dangerous.

>
> Any patches from anywhere can kill critical machines without warning...
>
> if the machine is critical, why does it have access to the net?


it's a file server, it has access to their internal network, and anything
that is on a network is potentially vulnerable to any of these things

Patrick Dunford 05-04-2004 03:57 AM

Re: Sasser scanner/removal tool
 
Enkidu
> On Tue, 4 May 2004 08:59:05 +1200, "Brett Roberts"
> <brettrob@abcmicrosoftxyz.com> wrote:
> >
> >http://www.microsoft.com/security/incident/sasser.asp
> >

> Hi Brett,
>
> Thanks for that. Just a bit of feedback - I ran the thing and it ended
> silently - that is, it didn't say "not found" or "virus found". Now I
> only ran it experimentally since I don't have the virus, but it would
> have been nice if it had told me so!


There are also scanners available from the antivirus companies and
probably one for your favourite AV package.


All times are GMT. The time now is 08:11 AM.

Powered by vBulletin®. Copyright ©2000 - 2013, vBulletin Solutions, Inc.
SEO by vBSEO ©2010, Crawlability, Inc.


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57