Go Back   Velocity Reviews > Newsgroups > Computer Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply

Computer Security - What you need to know about the Sasser worm

 
Thread Tools Search this Thread
Old 05-24-2004, 09:10 PM   #1
Default What you need to know about the Sasser worm


The Sasser worm - what you need to know

http://www.microsoft.com/security/incident/sasser.asp What Microsoft says about Sasser...

The Sasser worms exploits a vulnerability in Microsoft operating systems Windows XP and Windows 2000, known as the LSASS vulnerability.

Micrrosoft acknowledges this vulnerability in the critical security bulletin
http://www.microsoft.com/technet/sec.../MS04-011.mspx MS04-011 .

Microsoft has a patch for the vulnerability, called security update 835732.



What else you need you know...

The real danger is not Sasser itself, but http://news.com.com/2100-7349_3-5204667.html?tag=nl variants of Sasser , which exploit the same LSASS vulnerability.

This worm does not propagate by email or by malicious scripts on Web sites.
You can get this worm without doing anything at all.
As long as your computer is running and connected to the Internet, it can get infected.

LSASS is on TCP port 445. Sasser can also propagate through port 139. If you have a firewall, and set it to block ports 139 and 445, you may be safe. But just to be sure, you should probably install the patch as well.

Even aside from this, it's a good idea to block port 445 anyway. This port can be used for a http://www.vnunet.com/News/1131065 denial of service attack .

Ports 139 and 445 are used by Microsoft's http://ntsecurity.nu/papers/port445/ file sharing . If you have a home or small office network, and want to use Microsoft's file sharing, then you need to allow traffic on these ports on your local network. But be sure to block it at the firewall to the Internet. Always block traffic on these ports from the Internet.

How can http://www.securityspace.com/smysecu....html?id=12219 know if you're infected? If your system has Sasser, it will have TCP port 5554 open, and also either port 9995 or 9996.

How can you get rid of it if you're infected? First, go to the Task Manager and kill any task named "ASERVE.EXE" "ASERVE2.EXE" or anything similar. Then go to the Windows directory and delete any file with a similar name.

Even if you're not infected by a worm, you can be affected by it. Worm traffic causes traffic jams on the Internet, which can slow down everyone's downloads. Also, worms are used to launch Distributed Denial of Service (DDoS) attacks on servers, which make those servers unavailable to everyone. The only way we can be completely free from the harmful effects of worms is if practically every single computer user out there takes precautions, and that's not likely to happen.

Security experts are becoming sceptical about whether just keeping your patches up to date is a real solution to the problem of worms and viruses. First of all, patching is http://news.zdnet.co.uk/internet/sec...9147340,00.htm so difficult that there will always be people who don't bother.
Also, sometimes patches http://www.theinquirer.net/?article=7610 actually make things worse .
Finally, at least one Microsoft expert says that releasing patches just http://www.nwfusion.com/columnists/2004/0308kearns.html lets bad guys know there's a vulnerability so they can exploit it.




http://techsupp.blcss.com/#sasser Home link

Southern New Hampshire residents: don't throw away that old broken computer.
Call us first: 603-244-1652. If we can't fix it cheap, we'll take it off your hands.

..


Bottom Line Computer
  Reply With Quote
Old 05-25-2004, 02:00 AM   #2
Stan Brown
 
Posts: n/a
Default Re: What you need to know about the Sasser worm
"Bottom Line Computer" <> wrote in
misc.consumers:
>The real danger is not Sasser itself, but


people who keep posting the same article.

--
Stan Brown, Oak Road Systems Cortland County, New York, USA
http://OakRoadSystems.com
You need any friends you can get. The only thing standing
between you and a watery grave is your wits, and that's not
my idea of adequate protection. -- /Beat the Devil/ (1954)


Stan Brown
  Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Sasser??? Tony A+ Certification 12 05-19-2004 04:07 AM
Re: Sasser??? Tony A+ Certification 0 05-17-2004 09:28 PM
worm hit county jail! Chesucat A+ Certification 0 10-13-2003 02:50 AM
Re: Question about worm removal... Ghost A+ Certification 7 09-16-2003 11:12 AM
Re: Question about worm removal... natural_4u A+ Certification 2 09-15-2003 10:36 AM




SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46