New CIFS (port 445) worm?

From: David Gillett (gillettdavid@fhda.edu)
Date: 12/17/02

  • Next message: Oliver.C.Rochford CFH: "Re[2]: Rooted, .haos on system"
    From: "David Gillett" <gillettdavid@fhda.edu>
    To: <incidents@securityfocus.com>
    Date: Tue, 17 Dec 2002 08:30:13 -0800
    
    

      Overnight, I logged 13 connection attempts from random
    Internet addresses to my machine. 10 of them were to
    port 445, which is up significantly from a week ago.
      I'm also seeing lots of probes of this port at other
    network points.

      Yesterday I also had to disconnect two ports on our
    network because the machines on those ports were probing
    random Internet addresses on this port -- fast enough
    that one of our core routers was choking.

      My assumption, at this point, is that those two machines
    (and a bunch more out on the Internet) have been infected
    with something. The choice of port 445 suggests Win 2000/XP
    file shares as the infection vector.

      Anybody got more information?

    David Gillett

    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management
    and tracking system please see: http://aris.securityfocus.com



    Relevant Pages

    • Re: [SLE] SuSEfirewall2 and games
      ... Is there a simple way to set up the firewall to allow windows machines to ... > eth0 connected to the internet ... anything above 1024 is a high port. ... as my games I would leave it that way. ...
      (SuSE)
    • Re: [SLE] SuSEfirewall2 and games
      ... Now I have to figure out how to let my internal machines see the web site on the ... connection on the internal card to port 80. ... >> eth0 connected to the internet ...
      (SuSE)
    • [SLE] SuSEfirewall2 and games
      ... eth0 connected to the internet ... Internal machines can access the web, external machines can access ssh and the ... The game I want to play is using port 2325, and some others show up for source ... running pretty quickly, but I had to initiate the connection with my friend, the ...
      (SuSE)
    • Re: Linux als Router
      ... # Enter all trusted network interfaces here. ... # which should be available to the internet and set FW_ROUTE to yes. ... space separated list of ports, ... # Packets to silently reject without log message. ...
      (de.comp.os.unix.linux.misc)
    • Re: SharePoint 3.0: problems with external access
      ... "Go to 'Alternate Access Mappings' and in the 'Internet Zone' for your ... Port 443 won't work because it is already used by the Default Web Site. ... What you need to do is create a wildcard certificate and use it in ISA. ... The steps to publish WSS 3.0 applications behind ISA 2004 are the same ...
      (microsoft.public.windows.server.sbs)