MDAC worm exploit via MS04-003
From: Carboni, Mark (Mark.Carboni_at_FMR.COM)
Date: 02/02/04
- Previous message: Darryl J Roberts: "MS Exchange 5.5 NDRs (from MyDoom)"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Mon, 2 Feb 2004 12:16:56 -0500 To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
Hi all:
We've experienced numerous hits to port 1434 by exploit to MS SQL
Servers on desktops and WIN2K/WIN2.3K Server class machines. So far, we have
not found origin of this worm and MS's only solution is patch the infected
boxes. My personal opinion is flatten and rebuild for no one (including MS)
can show us a 'cleaner' or tool that will identify what was done to the
machine via this exploit, i.e. registry, DLLs, absolute disk writes to
sectors, etc...
My bet is this was deposited by previous MyDoom or variants. Any
ideas?
-Mark
-----
NTBugtraq Editor's Note:
Most viruses these days use spoofed email addresses. As such, using an Anti-Virus product which automatically notifies the perceived sender of a message it believes is infected may well cause more harm than good. Someone who did not actually send you a virus may receive the notification and scramble their support staff to find an infection which never existed in the first place. Suggest such notifications be disabled by whomever is responsible for your AV, or at least that the idea is considered.
-----
- Previous message: Darryl J Roberts: "MS Exchange 5.5 NDRs (from MyDoom)"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]