A Worm's Worm 345
Carnildo writes "There's a new worm out, according to the Register, but one with a twist. This one, called 'Dabber', infects computers by exploiting a security hole in the Sasser worm."
An Ada exception is when a routine gets in trouble and says 'Beam me up, Scotty'.
Is not the first time it happens (Score:4, Informative)
Not the same thing (Score:3, Informative)
Re:Is not the first time it happens (Score:5, Informative)
Perhaps you are thinking of Welchia [viruslist.com] which exploited IIS but also removed Blaster.
This is doubly ironic! (Score:5, Informative)
Exploit available on packetstorm (Score:5, Informative)
IE users: don't click above links! (Score:1, Informative)
I know, I am an idiot, but I thought the flash demo might be funny also. The post was funny, but the web site was not.
Re:It's ok... SP1 is coming soon (Score:5, Informative)
SP1 will be a while
Add it to nmap! (Score:5, Informative)
Add this line:
sasser 5554/tcp # Sasser worm FTP server
This way when you do a port scan of a host, you can tell if they've been infected with sasser
Re:Ugh... (Score:5, Informative)
Re:Ugh... (Score:3, Informative)
Re:Spyware and others (Score:1, Informative)
It was decided that it wasn't worth it since once we knew a machine was infected with some adware, all bets are off to the stability of the machine.
Code which might work perfectly in QA would likely cause crashes in the wild due to multiple infections. So we went with the detect and warn rather than the using backdoors to fix.
Re:Spyware and others (Score:4, Informative)
Given this isn't exactly a code-level exploit, though it is annoying enough that I sent two people to the reformat docters today because of it. Antivirus installed on the system beforehand, too.
No sympathy to the victims (Score:3, Informative)
The fact is, this worm released relies on another worm that causes the computer to randomly shut down. Unlike the LSASS service, there is very little stability, therefore making it highly unlikely that a computer infected with the former worm will be hit by the latter.
Re:Ugh... (Score:3, Informative)
If it's in the public domain, then anyone can do anything they want with it - you are revoking all ownership so have no more right to impose restrictions such as copyright notices than the guy down the street does.
Re:Ugh... (Score:3, Informative)