sasserall about the sasser viruslssa.exe exploits out on the open for everyone- May 19, 2004 http:www.astalavista.comsection=dir&cmd=file&id=1647 the source code http:www.astalavista.comsection=dir&cmd=file&id=1639 more source codehttp:www.astalavista.comsection=dir&cmd=file&id=1651 binary windows tool and then be surprised that in http:virusalerts.skynetblogs.com one lssa.exe using worm after another comes byhttp://sasser.skynetblogs.be/post/364980 who is surprised- May 18, 2004 Marle B. - the man who provided the tip-off to Microsoft that led to the arrest of Sven Jaschan, 18 - has become a suspect in the German police's computer sabotage inquiry. Munich-based weekly Focus reports that a criminal investigation would blight Marle B's chances of a share in the $250,000 reward money from Microsoft's Anti-Virus Reward Program that caused him to come forward in the first place.http:www.theregister.com20040518sasser_informant_turns_suspecthttp://sasser.skynetblogs.be/post/363528 infected sasser computers attacked- May 16, 2004 The sasser backdoor exploit. Computers infected with sasser are now being re-attacked to incorporate them in botnets controlled by spammers, criminal gangs, hackers, viruswriters and porno-people. This is an example of the used code that is manually executed. The automated tool is the virus dabber, which seems quite active on the net.http:dshield.orgport_report.phpport=5554 http:www.lurhq.comdabber.html http:www.pandasoftware.comvirus_infoencyclopediaoverview.aspxIdVirus=47477&sind=0LURHQ's Joe.http://sasser.skynetblogs.be/post/360999 some other fallen heroes- May 14, 2004 American Express joined a number of U.S. universities in reporting infections from the Sasser worm http:seclists.orglistsisn2004May0017.html One solution we are now considering is setting up secure meeting rooms in our buildings in which we put up seperate small security appliances so that when all hell breaks lose, we can move some cleaned computers over and let those people be responsable for the continuity. Also all portable computers could only be logged on to the network in these rooms...http://sasser.skynetblogs.be/post/358146 network scanning for sasser- May 11, 2004 http:www.foundstone.comresourcesproddescdsscan.htmA network admin utility for remotely detecting LSASS vulnerability released in the MS04-011 bulletin http:www.foundstone.comresourcestermsofuse.htmfile=dsscan.ziphttp://sasser.skynetblogs.be/post/352434 and the next is version f- May 11, 2004 http:www.trendmicro.comvinfovirusencyclodefault5.aspVName=WORM_SASSER.F makes file NAPATCH.EXE TCP port 445 The resulting overflow allows the malware to listen to a certain port, which instructs it to spawn a command shellhttp://sasser.skynetblogs.be/post/351963 New microsoft removal tool for sasser also E.- May 10, 2004 http:www.microsoft.comdownloadsdetails.aspxFamilyID=76c6de7e-1b6b-4fc3-90d4-9fa42d14cc17&DisplayLang=en for french place fr instead of lang=en (es for spanish) and so onhttp://sasser.skynetblogs.be/post/350974 exploits same as sasser- May 10, 2004 http:packetstormsecurity.nl0405-exploitsRemote exploit for the Lsasrv.dll RPC buffer overflow. Tested against various Russian and English versions of Windows XP Professional, Windows 2000 Professional, and Windows 2000 Advanced Server. Ported to compile properly on Linux.http:packetstormsecurity.nl0405-exploitswin_msrpc_lsass_ms04-11_Ex.c Remote exploit for the Lsasrv.dll RPC buffer overflow. To make this exploit work remotely you have to use the sbaaNetapi.dll which modifies the...http://sasser.skynetblogs.be/post/350969 sasser's ftp server overrun- May 10, 2004 We received a submission of an exploit for Sasser's FTP server. It appears to be a buffer overflow targeting port 5554 by default. If successful it will spawn a shell listening on port 53. Anyone seeing any traffic or activity related to this please let us know. Fom the internet storm center http:isc.sans.orgmy comment Sasser installs a ftp server on infected machines. It is not only a security flaw an sich, but has a security flaw. This way it can be recuperated by other trojans. Just...http://sasser.skynetblogs.be/post/350892 Sasser E.- May 10, 2004 As we said, the code is in the open or being reverse engineered and the arrest of the creator has as much effect as arresting God for the creation of man. So here is the first of the changed and better thought-through sasser variants. http:www.trendmicro.comvinfovirusencyclodefault5.aspVName=WORM_SASSER.E&VSect=T infection : The resulting overflow executes a code that creates a command shell and opens port 1022 on the remote machine then waits for the malware to issue commands that...http://sasser.skynetblogs.be/post/350331 |