Re: Will the Sasser worm become the next Blaster?

From: Damian Menscher (menscher_at_uiuc.edu)
Date: 05/03/04

  • Next message: Janek Vind: "[waraxe-2004-SA#026 - Multiple vulnerabilities in Coppermine Photo Gallery for PhpNuke]"
    Date: Sun, 2 May 2004 17:54:03 -0500 (CDT)
    To: bugtraq@securityfocus.com
    
    

    Gadi Evron <ge linuxbox org> wrote:
    > if you simply port scan for Sasser you get many false positives, as
    > that port (5554) is also used by Oracle. If you get "200 OK" as a
    > reply though in the first packet, it's Sasser.

    Another false positive is IRIX boxes which listen to port 5554/tcp for
    esp-httpd (their "Embedded Support Partner"). From the default
    /etc/inetd.conf:
    sgi-esphttp stream tcp wait root /usr/etc/esphttpd esphttpd -u300

    To cut down on false positives, I tried scanning for BOTH 5554/tcp AND
    9996/tcp. Unfortunately we found that very few (about 2%) of the
    infected machines had both ports open. Another 1% had only port
    9996/tcp open. The remaining 97% had only 5554 open.

    Damian Menscher

    -- 
    -=#| Physics Grad Student & SysAdmin @ U Illinois Urbana-Champaign |#=-
    -=#| 488 LLP, 1110 W. Green St, Urbana, IL 61801 Ofc:(217)333-0038 |#=-
    -=#| <menscher@uiuc.edu> www.uiuc.edu/~menscher/ Fax:(217)333-9819 |#=-
    -=#| The above opinions are not necessarily those of my employers: |#=-
    -=#| UIUC CITES Security Group || Beckman Imaging Technology Group |#=-
    

  • Next message: Janek Vind: "[waraxe-2004-SA#026 - Multiple vulnerabilities in Coppermine Photo Gallery for PhpNuke]"

    Relevant Pages

    • Re: Port Scanning: AV program causes false-positive on port 110?
      ... Performing port scanning on TCP port 110 really shouldn't be seen by ... not false positives. ... port-scanning software that port-110 is open. ...
      (alt.comp.anti-virus)
    • Re: Port Scanning: AV program causes false-positive on port 110?
      ... scanning program on the host against a remote IP ... scanning (particularly in this case by hooking into or onto port 110) ... not false positives. ... port-scanning software that port-110 is open. ...
      (alt.comp.anti-virus)
    • Re: snort and port 53 <-> 53 false positives
      ... > I've installed snort 1.8.1 and receive a lot of false positives ... > because of the traffic between my caching nameserver and the root ... > but this way somebody can flood my port 53 with packets from port 53, ...
      (comp.security.firewalls)
    • snort and port 53 <-> 53 false positives
      ... I've installed snort 1.8.1 and receive a lot of false positives ... because of the traffic between my caching nameserver and the root ... but this way somebody can flood my port 53 with packets from port 53, ...
      (comp.security.firewalls)
    • Re: Wer oder was ist mit meinem Rechner connected
      ... Der lokale Port ist jedesmal 445, ... MaW, das ist ein Teil von NetBIOS. ... Und außerdem der Port, auf den Sasser ...
      (microsoft.public.de.security.heimanwender)