RE: Detecting Blaster

oogelyboogly_at_hushmail.com
Date: 08/14/03

  • Next message: Carrera, Art: "RE: Account Lockout -- ARGH"
    Date: Thu, 14 Aug 2003 13:54:20 -0700
    To: bobs@LEAWOOD.ORG, focus-ms@securityfocus.com
    
    

    Most of the time the worm traffic will select address space for which
    there is no route within your network - that is especially true of the
    first version of msblaster. That means that almost always the traffic
    will head towards the route of last resort or your default route (towards
    the Internet).

    You shouldn't let TCP port 135 outbound through your firewall anyhow.
    Simply set an ACL to deny the packets and log the activity to a syslog
    server. This gives you a fairly good way to see what is going on.

    Once you have identified a suspect system (which is easy to see due to
    the traffic frequency and patterns of scanning) - check the registry
    with the NT4 resource kit tool "reg.exe" in the ussual places that the
    worms are setting their keys to restart.

    Syntax:

    reg query HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    /S \\<IP ADDR>

    You can also use the "reg.exe" tool to disable the DCOM reg key (which
    is not totally effective for all versions), or to delete the offending
    worm registry key - followed by a reboot (using the shutdown tool from
    the resource kit).

    example...

    reg update HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\EnableDCOM=N \\<IP
    ADDR>

    Hope this helps!

    0b

    -----Original Message-----
    From: Bob Sadler [mailto:bobs@LEAWOOD.ORG]
    Sent: Thursday, August 14, 2003 12:14 PM
    To: focus-ms@securityfocus.com
    Subject: Detecting Blaster

    I have been trying to figure out if there is a way that I can detect
    signs of Blaster on a large number of machines on a network without
    having to actually visit each one.

    I have a port scanner (Ethereal) and have it setup to look at any frame
    with destination port 135. Is there a better way to do this, or is the
    way I'm trying to do this all wrong in the first place?

    Bob Sadler
    City of Leawood, KS, USA
    WAN/Internet Specialist
    913-339-6700 x194

    Get a Life! Get TWO! Play Second Life!
    http://secondlife.com/ss/?u=b4ebbfdd6af98a027fa7e89a86c55a68

    ---------------------------------------------------------------------
    ------
    Your network firewall and IDS products do not prevent Web application

    attacks - the most common form of online exploitation- resulting in Web

    defacement, data theft, sabotage and fraud.
    KaVaDo is the only company that provides a complete suite of Web
    application security products.
    Download a FREE whitepaper on "Security Policy Automation for Web
    Applications":http://www.securityfocus.com/Kavado-focus-ms
    ---------------------------------------------------------------------
    ------

    Concerned about your privacy? Follow this link to get
    FREE encrypted email: https://www.hushmail.com/?l=2

    Free, ultra-private instant messaging with Hush Messenger
    https://www.hushmail.com/services.php?subloc=messenger&l=434

    Promote security and make money with the Hushmail Affiliate Program:
    https://www.hushmail.com/about.php?subloc=affiliate&l=427

    ---------------------------------------------------------------------------
    Your network firewall and IDS products do not prevent Web application
    attacks - the most common form of online exploitation- resulting in Web
    defacement, data theft, sabotage and fraud.
    KaVaDo is the only company that provides a complete suite of Web
    application security products.
    Download a FREE whitepaper on "Security Policy Automation for Web
    Applications":http://www.securityfocus.com/Kavado-focus-ms
    ---------------------------------------------------------------------------


  • Next message: Carrera, Art: "RE: Account Lockout -- ARGH"

    Relevant Pages

    • [REVS] Curious Yellow: The First Coordinated Worm Design
      ... The Warhol worm design began the theoretical discussion of so-called ... very quick infection of the network. ... Warhol superworm is to pre-scan the network for vulnerable targets. ... The method for nominating a worm to attack a target is easy. ...
      (Securiteam)
    • Re: Bridging network adapters in Linux
      ... ip addr add $address/$netbits dev br0 ... Either a default route ... two network devices assuming, ... This is done using the iptables mechanism. ...
      (comp.os.linux.networking)
    • RE: ISA 2004 help please
      ... network, and I have set that as the gateway on those machines. ... When I set a persistant route on ... the server to their addresses (how I configured the ISA 2000 serverand they ... This newsgroup only focuses on SBS technical issues. ...
      (microsoft.public.windows.server.sbs)
    • CERT Advisory CA-2001-23
      ... We believe the worm will begin propagating again on ... susceptible to the vulnerability described in CA-2001-13 Buffer ... time required to infect all vulnerable IIS servers with this worm ... and egress filtering should be implemented at the network edge. ...
      (Cert)
    • [IPv6] PROBLEM? Network unreachable despite correct route
      ... I have several boxes with native IPv6 connectivity at various places. ... Some of them show symptoms of a lost default route for small periods of ... self built AMD Athlon64, Ubuntu Edgy, Distribution kernel ... At the same time, a sibling (same hardware, same switch, same network ...
      (Linux-Kernel)