RE: [Full-Disclosure] Interesting traffic

From: George Peek (GKPeek_at_AllstateTicketing.com)
Date: 09/09/03

  • Next message: SGI Security Coordinator: "Denial of Service Vulnerability in NFS XDR decoding Update"
    To: "'shawn6913'" <shawn6913@comcast.net>, full disclosure <full-disclosure@lists.netsys.com>
    Date: Tue, 9 Sep 2003 11:01:20 -0700
    
    

    Are you kidding? 98% of all Trojans, Worms, Viruses, and other malicious
    programs will likely harm your system and/or network by using such local
    system account (i.e. administrator access) or a some sort of network domain
    admin-privileged account.

    -----Original Message-----
    From: shawn6913 [mailto:shawn6913@comcast.net]
    Sent: Monday, September 08, 2003 4:55 PM
    To: full disclosure
    Subject: [Full-Disclosure] Interesting traffic

    I am interested in finding out if anyone knows about a worm or virus
    that attempts to login to windows boxes as local, administrator, or
    guest. Does such a thing exist? It only seems to ocurr at certain times
    during the day. Any clues?

    Shawn

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: SGI Security Coordinator: "Denial of Service Vulnerability in NFS XDR decoding Update"

    Relevant Pages

    • Re: Enterprise AV
      ... Subject: Enterprise AV ... Not one virus/worm has made it into my network. ... not battling stubborn worms and inefficient AV ... > - Precisely Define and Implement Network Security ...
      (Security-Basics)
    • Conficker (and friends) v.s. Penetration Testing
      ... The fact is that if people managed their networks properly that worms would not be able to spread, or at least not so quickly and on such a wide scale. ... we recently performed a penetration test for one of our customers. ... That is to say that we were able to hack into our customers network within 15 minutes of starting the project. ... Most people _try_ to protect their networks with anti-virus scanners and other technology. ...
      (Pen-Test)
    • Re: TCP/IP problems
      ... I have a bizzare problem that I cannot bound TCP/IP to my ... : with a virus. ... If a worm was trying to penetrate your network and that port was ... Worms are self-contained. ...
      (microsoft.public.win2000.networking)
    • Re: NetServerGetInfo using level 100 - Access Denied!!
      ... The Local System account does not have network access rights under Win2000, ...
      (microsoft.public.vc.atl)
    • RE: Suggestions
      ... We utilized exactly this detection system, with api detection features, ... been against the grain and felt that slow, stealthy worms are far more ... stealth and destruction tend to go together. ... One has to be able to monitor both network ...
      (Focus-IDS)