Re: Linux Slapper Worm

From: Charles Stevenson (core@bokeoa.com)
Date: 09/19/02


Date: Thu, 19 Sep 2002 15:23:05 -0600
From: Charles Stevenson <core@bokeoa.com>
To: bugtraq@securityfocus.com

This method of security through obscurity will not prevent another
hacker from chaning the worm to use one of the modified versions of the
exploit which supports brute forcing. Nor does it trick Solar Eclipse's
scanner which actually overflows and checks to see if the server
response contains our data. All you did was waste your time. :)

peace,
core

-- 
    Charles Stevenson (core) <core@bokeoa.com>
    Lab Assistant, College of Eastern Utah San Juan Campus
    http://www.bokeoa.com/~core/core.asc



Relevant Pages

  • Re: security advice (possible hacker activity?)
    ... Launching CMD.EXE from IIS is a common hacker ... > are being scanned by worm that is not related to the lockups]. ... > sap resources and reboot computers, or it could be a general software ...
    (microsoft.public.inetserver.iis.security)
  • Re: security advice (possible hacker activity?)
    ... Launching CMD.EXE from IIS is a common hacker ... > are being scanned by worm that is not related to the lockups]. ... > sap resources and reboot computers, or it could be a general software ...
    (microsoft.public.win2000.security)
  • Re: security advice (possible hacker activity?)
    ... Launching CMD.EXE from IIS is a common hacker and ... are being scanned by worm that is not related to the lockups]. ... for Windows and IIS have probably not been applied, ... attempt occurred [e.g. whether the attempt coincided with the reboot, ...
    (microsoft.public.inetserver.iis.security)
  • Re: security advice (possible hacker activity?)
    ... Launching CMD.EXE from IIS is a common hacker and ... are being scanned by worm that is not related to the lockups]. ... for Windows and IIS have probably not been applied, ... attempt occurred [e.g. whether the attempt coincided with the reboot, ...
    (microsoft.public.win2000.security)
  • Hacked SQL Server
    ... We just found out that we got hacked by the sql server ... We have updated the machine and removed the worm. ... Looks like the hacker ... How do we recover the sa account password or make any ...
    (microsoft.public.sqlserver.security)

Quantcast