Security Incidents mailing list archives
Re: cuebot-d infection method
From: Jeff Bryner <jbryner1 () yahoo com>
Date: Wed, 24 Aug 2005 16:17:27 -0700 (PDT)
"W32/Cuebot-D attempts to spread using a variety of techniques including the exploitation of the PnP vulnerability (MS05-039)." ... from my reading of it, there multiple attack vectors involved
Yes, thanks for reading me the link I provided ;-) I *did* read all tabs on the links and did google for other references. I guess I should have stated that...oh well no worries. I was looking for more detail from those who had actually delt with this specific beast about what the other 'variety of techniques' were besides the ms05-039 vulnerability. Thanks to those who responded with their stories. FYI in case you run into this here is my story. It seems the machines in my case had been attached to an unprotected network and were unpatched against ms05-039. When they attached to the production network, whammo. Old scenario, new worm. Thanks again, case closed. Jeff.
Current thread:
- Re: cuebot-d infection method, (continued)
- Re: cuebot-d infection method Matt Stockdale (Aug 24)
- Re: cuebot-d infection method Irwan Ismail (Aug 25)
- RE: cuebot-d infection method Jason Burton (Aug 25)
- Re: cuebot-d infection method Jayson Anderson (Aug 25)
- Re: cuebot-d infection method Harlan Carvey (Aug 26)
- Re: cuebot-d infection method Jeff Bryner (Aug 29)
- Re: cuebot-d infection method Harlan Carvey (Aug 29)
- Re: cuebot-d infection method Jayson Anderson (Aug 29)
- Re: cuebot-d infection method Jose Nazario (Aug 29)
- Re: cuebot-d infection method Irwan Ismail (Aug 25)
- Re: cuebot-d infection method Matt Stockdale (Aug 24)
- Re: cuebot-d infection method Jeff Bryner (Aug 25)
- Re: cuebot-d infection method Simon Borduas (Aug 29)