Full Disclosure mailing list archives
Re: DCOM Worm released
From: Dennis Opacki <dopacki () adotout com>
Date: Mon, 11 Aug 2003 17:40:46 -0400 (EDT)
Can anyone confirm whether the tftp transfers appear to be solely from the hosts listed in the initial sans.org note (which now appear to have been taken down), or is the transfer done from the infecting host? TIA, -Dennis On Mon, 11 Aug 2003, Joey wrote:
They found a worm, but since it uses tftp servers that can be taken down and since tftp is slow, it shouldnt have much of an effect. "Scans sequentially for machines with open port 135, starting at a presumably random IP address" - very stupid way to spread! http://isc.sans.org/diary.html?date=2003-08-11 __________________________________ Do you Yahoo!? Yahoo! SiteBuilder - Free, easy-to-use web site design software http://sitebuilder.yahoo.com _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- DCOM Paul Marsh (Aug 11)
- <Possible follow-ups>
- DCOM Paul Marsh (Aug 11)
- DCOM Worm released Joey (Aug 11)
- Re: DCOM Worm released Dennis Opacki (Aug 11)
- Re: DCOM Worm released Dennis Opacki (Aug 11)
- Re: DCOM Worm released Jordan Wiens (Aug 11)
- RE: DCOM Worm released Marc Maiffret (Aug 11)
- Re: DCOM Worm released daniel uriah clemens (Aug 11)
- RE: DCOM Worm released gml (Aug 11)
- DCOM Worm released Joey (Aug 11)
- Re: DCOM Worm released Nils (Aug 11)
- Re: DCOM Worm released ragdelaed (Aug 11)
- Re: DCOM Joey (Aug 11)
- Re: DCOM Valdis . Kletnieks (Aug 13)