[Full-Disclosure] RE: Possible new variant of Nachi

From: Schmehl, Paul L (pauls_at_utdallas.edu)
Date: 09/25/03

  • Next message: Brian Eckman: "[Full-Disclosure] Analysis of a Spam Trojan"
    To: <full-disclosure@lists.netsys.com>
    Date: Thu, 25 Sep 2003 13:40:29 -0500
    
    

    Working hypothesis is as follows:

    Hosts were turned off previously so they didn't show up in routine
    scanning. Then they were turned on and got infected with Nachi. Nachi
    patched for MS03-026. Then a scan showed them patched for MS03-026 but
    not for MS03-039. Then snort reported their infection. So, it appears
    to be a timing issue rather than something new.

    Paul Schmehl (pauls@utdallas.edu)
    Adjunct Information Security Officer
    The University of Texas at Dallas
    AVIEN Founding Member
    http://www.utdallas.edu/~pauls/

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Brian Eckman: "[Full-Disclosure] Analysis of a Spam Trojan"

    Relevant Pages

    • Re: Do not turn off email scanning
      ... >> antivirus software would normally detect the infection as soon as the ... The virus scanner will alert when the attachment is ... Email scanning does the necessary decoding to detect an ...
      (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
    • Re: Do not turn off email scanning
      ... because MSOE 6 places the "Reply to Sender" and "Reply to ... Email scanning does the necessary decoding to detect an infection ... first sixteen because my ISP has mail scanning in place, ...
      (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
    • Re: What is this infection" reported by Cyber Defender
      ... I used AVG for years w/o problems, recently switched to Avast on rec. ... stop it's scanning once OE opened up. ... Since you never mentioned what *is* the registry key on which CD is ... the claimed infection so "HKEY" is all it tells you regarding the ...
      (microsoft.public.windowsxp.help_and_support)
    • New RPC worm?
      ... binaries I have received so far are MD5 matches with the original Nachi. ... Another report states they saw the effects of blaster as of Thursday ... Here the bandwidth effect was very small, and infection rate ... code "NT1003" when registering to take the TICSA exam at www.2test.com. ...
      (NT-Bugtraq)
    • Re: What is this infection" reported by Cyber Defender
      ... I used AVG for years w/o problems, ... not "find" the options to stop it's scanning once OE opened up. ... Since you never mentioned what *is* the registry key on which CD is ... regarding the so-called infection. ...
      (microsoft.public.windowsxp.help_and_support)

  • Quantcast