Re: Detecting Blaster

From: Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP] (sbradcpa_at_pacbell.net)
Date: 08/14/03

  • Next message: Q?=offtopicQ=20?=: "Re: DCOM patch + Exchange"
    Date: Thu, 14 Aug 2003 14:05:19 -0700
    To: Bob Sadler <bobs@LEAWOOD.ORG>
    
    

    Microsoft has released a KB 823980 Scanning Tool (KB823980scan.exe) that
    can be used to scan networks to identify host computers that do not have
    the 823980 security patch (MS03-026) installed. For additional
    information about the 823980 security patch (MS03-026), click the
    following article number to view the article in the Microsoft Knowledge
    Base:
    823980 MS03-026: Buffer Overrun in RPC Interface May Allow Code
    Execution
    http://support.microsoft.com/default.aspx?scid=kb;en-us;823980

    For additional information about a new worm virus that tries to exploit
    the DCOM RPC vulnerability that is fixed by the 823980 security patch
    (MS03-026), click the following article number to view the article in
    the Microsoft Knowledge Base:
    826955 Virus Alert About the W32.Blaster.Worm Worm
    http://support.microsoft.com/default.aspx?scid=KB;EN-US;826955

    Download location:
    http://microsoft.com/downloads/details.aspx?FamilyId=C8F04C6C-B71B-4992-91F1-AAA785E709DA&displaylang=en

    Bob Sadler wrote:

    > I have been trying to figure out if there is a way that I can detect
    > signs of Blaster on a large number of machines on a network without
    > having to actually visit each one.
    >
    > I have a port scanner (Ethereal) and have it setup to look at any frame
    > with destination port 135. Is there a better way to do this, or is the
    > way I'm trying to do this all wrong in the first place?
    >
    > Bob Sadler
    > City of Leawood, KS, USA
    > WAN/Internet Specialist
    > 913-339-6700 x194
    >
    > Get a Life! Get TWO! Play Second Life!
    > http://secondlife.com/ss/?u=b4ebbfdd6af98a027fa7e89a86c55a68
    >
    > ---------------------------------------------------------------------------
    > Your network firewall and IDS products do not prevent Web application
    > attacks - the most common form of online exploitation- resulting in Web
    > defacement, data theft, sabotage and fraud.
    > KaVaDo is the only company that provides a complete suite of Web
    > application security products.
    > Download a FREE whitepaper on "Security Policy Automation for Web
    > Applications":http://www.securityfocus.com/Kavado-focus-ms
    > ---------------------------------------------------------------------------

    --
    "Don't lose sight of security. Security is a state of being,
    not a state of budget. He with the most firewalls still does
    not win. Put down that honeypot and keep up to date on your
    patches. Demand better security from vendors and hold them
    responsible. Use what you have, and make sure you know how
    to use it properly and effectively."
    ~Rain Forest Puppy
    http://www.wiretrip.net/rfp/txt/evolution.txt
    ---------------------------------------------------------------------------
    Your network firewall and IDS products do not prevent Web application 
    attacks - the most common form of online exploitation- resulting in Web 
    defacement, data theft, sabotage and fraud.
    KaVaDo is the only company that provides a complete suite of Web 
    application security products.
    Download a FREE whitepaper on "Security Policy Automation for Web
    Applications":http://www.securityfocus.com/Kavado-focus-ms
    ---------------------------------------------------------------------------
    

  • Next message: Q?=offtopicQ=20?=: "Re: DCOM patch + Exchange"

    Relevant Pages

    • RE: file sharing on network with vista and xp home computer
      ... Since the contact through microsoft email has been 24 hours+ for each reply, ... security settings for the root folder until I asked them to. ... network was working for that one week, that I had changed "Everyone's" access ... and I had to reinstall my copy of windows. ...
      (microsoft.public.windowsxp.network_web)
    • SecurityFocus Microsoft Newsletter #51
      ... Subject: SecurityFocus Microsoft Newsletter #51 ... If you're running a Windows network, then this is the intensive 3-day ... Specialist in Microsoft's Security Services Partner Program, ... Platforms: Solaris and Windows NT ...
      (Focus-Microsoft)
    • RE: ATTN : Microsoft - Security Event 529....Second Request for help....
      ... Security Event ID 529 is a failure audit for logon/logoff. ... computer from the network". ... Microsoft CSS Online Newsgroup Support ... newsgroups so that they can be resolved in an efficient and timely manner. ...
      (microsoft.public.windows.server.sbs)
    • OT (FW: Microsoft Progress Report: Security)
      ... Subject: Microsoft Progress Report: Security ... and on the technology industry to continue ... cause of network breaches. ...
      (comp.os.vms)
    • [Full-Disclosure] FW: Microsoft Progress Report: Security
      ... Subject: Microsoft Progress Report: Security ... computing devices converged to create a truly global computing network in ... threatening the potential of technology to ...
      (Full-Disclosure)