Ads by TechWords

See your link here
Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Security
Virus and Vulnerability Roundup
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
 

New worm targets Sasser code flaw

'Dabber' is thought to be the first worm to spread by targeting a flaw in another worm

May 14, 2004 12:00 PM ET

IDG News Service - A new Internet worm is spreading by exploiting a flaw in the Sasser worm, according to an alert issued yesterday.
The new worm, tentatively named Dabber, takes advantage of a vulnerability in an FTP server component in the Sasser worm and may have infected thousands of computers already infected with Sasser. Dabber is believed to be the first worm that spreads by specifically targeting a flaw in another worm's code, according to an advisory published by LURHQ Corp., a Chicago managed security services company.
Using code written to exploit the FTP flaw, the recently released worm scans the Internet for Port 5554 to identify computers running Microsoft Corp.'s Windows operating system that are infected with Sasser, LURHQ said.
When it finds vulnerable hosts, it connects to the victim and uses a built-in FTP server to transfer the worm file, named package.exe, to the system. When it runs, the Dabber worm installs itself on Windows and then shuts down the Sasser worm and other worm processes, preventing them from running again. Dabber also opens TCP Port 9898 as a back door, which can be used by a remote attacker to download other code or communicate with the infected host, LURHQ said.
As of yesterday, Dabber didn't appear to be spreading quickly, but the number of infections was escalating, LURHQ said.
Sasser, which appeared on May 1 (see story), exploits a recently disclosed hole in a Windows component called the Local Security Authority Subsystem Service, or LSASS. Microsoft released a software patch, MS04-011, on April 13.
Dabber is similar to Sasser and earlier worms like Blaster because users don't need to receive an e-mail message or open a file to be infected. Instead, just having a Sasser-infected Windows machine connected to the Internet is enough to catch Dabber.
Last week, Microsoft acknowledged that more than 1.5 million copies of a Sasser cleanup tool were downloaded from its Web site within the first 48 hours after it was offered.
In its advisory, LURHQ posted instructions for shutting down and removing Dabber.


Reprinted with permission from

IDG.net
Story copyright 2009 International Data Group. All rights reserved.

Additional Resources

Xerox
By using solid ink technology only from Xerox, you could save up to 65% by printing color for the cost of black and white. Enter for a chance to WIN a PhaserTM 8860 network color printer!
Microsoft
Save time and mitigate security risk. Deploy it now.
Sybase
In this white paper, IDC analyzes the role of next-generation mobile enterprise platforms as organizations seek a more strategic deployment of mobile solutions.

Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.

White Papers & Webcasts

Addressing Compliance Initiatives with Tripwire and the Center for Internet Security
Learn the basics about security benchmarks, and specifically how the security benchmarks developed by the Center for Internet Security (CIS) can help you...  

Strategic ECM Webinar
Learn what new strategic business benefits can be realized through ECM!...

An All-in-One Approach to Web Security
Granting web access to employees poses challenges to IT administrators and introduces unique security risks. Even as companies have perfected their security techniques...  

Managing And Protecting Your Ever Increasing Mobile Assets
Learn best practices for desktop and application virtualization, computer security, and computer life-cycle management....

The Hidden Dangers of Spam
Beyond the well-understood productivity drain that spam inflicts on businesses, threats posed by illicit email circulating through a network are causing many security...  

5 Architecture Issues that Impact BES performance
This Live webinar will identify critical log file errors, performance counters, and configurations to pay close attention to when optimizing BES server performance....

Case Study: The Ritz London
Discover how the superior capabilities of Webroot E-mail Security SaaS allows user to focus on their principal tasks instead of wasting their time...  

Usability Is Everything
Learn what sets Workday's HR and Payroll solutions apart from the competition....

Case Study: Richmond Ambulance Authority (RAA)
In this case study, find out how Webroot Web Security SaaS delivers the proactive web security RAA needs....  

The Value of Real SaaS at Workday
Cost savings, speed to value, and innovation brought to the enterprise by Workday's software-as-a-service solutions for HR and Payroll....