[Full-Disclosure] spoolcll.exe - new worm being distributed via mysql vulnerability?

From: Mike Bailey (worried_at_gmail.com)
Date: 01/27/05

  • Next message: Nicolas RUFF (lists): "Re: [Full-Disclosure] Terminal Server vulnerabilities"
    Date: Thu, 27 Jan 2005 00:18:21 -0500
    To: full-disclosure@lists.netsys.com
    
    

    Aloha,

    Earlier tonight, i was sitting here at home doing some normal
    browsing, and work and my firewall alerted me that a program called
    spoolcll.exe was attempting to open up a port which i cannot remember
    now.

    i tried killing it, but it just came back, over and over again each
    time spawning itselfs on a new port.

    Registry says the worm created a service called "evmon", it cannot be
    paused or stopped, but it can be disabled.

    The only information about this worm on google is a discussion at the
    following url: http://forums.whirlpool.net.au/forum-replies.cfm?t=291921&p=1
    they are beginning to determinthat it is being distributed via a hole
    in mysql.

    Do any of you know anything about this? Thanks in advance.

    -- 
    Love,
    Mike Bailey
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    

  • Next message: Nicolas RUFF (lists): "Re: [Full-Disclosure] Terminal Server vulnerabilities"

    Relevant Pages

    • RE: [Full-Disclosure] RE: MS SQL WORM IS DESTROYING INTERNET BLOCK PORT 1434!
      ... Subject: RE: MS SQL WORM IS DESTROYING INTERNET BLOCK PORT 1434! ... Seems to be the most common opinion of those who have no apparent experience with large networks. ... held no responsibility here, ...
      (Full-Disclosure)
    • RE: Remote Desktop vs VPN on Windows 2003
      ... > default SQL port to anything else, they would have never been touched by ... risk posed by slow insidious attacks when defenders are always facing off ... > characters) to prevent every SQL scanning worm in existence. ... > security through obscurity doesn't work, when clearly it does have its ...
      (Security-Basics)
    • Protecting Home Machines
      ... It also opens ports between port 666 to port 765 for its malicious ... Similar to the earlier MSBLAST worm variants, ... I recommend Sygate Personal Firewall ... internet connections. ...
      (Security-Basics)
    • Re: SQL Worm
      ... >will allow a connection to port 1433. ... I'm guessing that the worm has been modified and ... >password on the SA account. ... >access to port 1433 for most internet hosts except for certain subnets ...
      (microsoft.public.sqlserver.security)
    • Re: Zonealarm Netbios name on port 10xx messages ??
      ... > i use also tiny personal firewall on Win98. ... Probably the opaserv worm. ... just quoting the port it orginates from. ...
      (comp.security.firewalls)

  • Quantcast