Re: Sasser ports

From: Andrew Mitchell (amitchell_at_removecasey.vic.gov.au)
Date: 05/03/04


Date: Mon, 03 May 2004 00:29:56 -0700


"John" <anonymous@discussions.microsoft.com> said

> Sasser scans on port 445. I've also read some sources that
> claim it scans on different ports:
> 139
> (http://www.microsoft.com/technet/Security/alerts/sasser.mspx
> under PREVENTION), 1025+ (can't find the link anymore), or
> 1068+ (http://vil.nai.com/vil/content/v_125007.htm under
> Symptoms)
>
> Only 445 has come up consistently though (excluding 5554
> and 9996 of course). Then there's a trojan that scans
> 137-139 and 445
> http://www.sarc.com/avcenter/venc/data/hacktool.lsasssba.html
> but I'm not sure if this is the same as the sasser worm. So
> what ports for sure besides 445 is sasser using?
>

Connects to destination port 445
Starts an FTP server listening on port 5554
Runs a remote shell on port 9996

AFAIK 139 is not used at all.

Andy.



Relevant Pages

  • Re: sasser removal tool not working
    ... The people think the Constitution protects their rights; But government sees it as an obstacle to be overcome. ... | My computer was infected with the sasser worm. ... I ran netstat -n command and saw that there was | a lot of activity on port 445, ... Is there a way to stop this, or a way to change | to a different port for internet access? ...
    (microsoft.public.security.virus)
  • sasser removal tool not working
    ... My computer was infected with the sasser worm. ... using the removal tool from 3 different sites to fix the ... a lot of activity on port 445, ... to a different port for internet access? ...
    (microsoft.public.security.virus)
  • sasser removal tool not working
    ... >My computer was infected with the sasser worm. ... >problem and I still have problems connecting to the ... >a lot of activity on port 445, ... >to a different port for internet access? ...
    (microsoft.public.security.virus)
  • Re: Would a firewall prevent Sasser worm?
    ... any firewall that blocks incoming port 445 will prevent infection ... >]by the Sasser worm. ...
    (comp.security.misc)
  • Re: Would a firewall prevent Sasser worm?
    ... any firewall that blocks incoming port 445 will prevent infection ... >]by the Sasser worm. ...
    (comp.security.firewalls)