FAO IT bods... major virus alert...
MS-08-067
similar to sasser potentially.
MS have confirmed off the record that 2 major corporates in the states have already been subject to attack.
our place is working on deployment as i type.
gonna be a looong night!
similar to sasser potentially.
MS have confirmed off the record that 2 major corporates in the states have already been subject to attack.
our place is working on deployment as i type.
gonna be a looong night!
initial trojan exploit..
ymantec Definitions version released 101024p today
http://www.symantec.com/business/security_response/definitions/rapidrelease/index.jsp
Sophos Protection available since 23rd October
Site explaining Trojan/ worm http://blog.threatexpert.com/2008/10/gimmiva-exploits-zero-day-vulnerability.html
worm won't be far behind......
ymantec Definitions version released 101024p today
http://www.symantec.com/business/security_response/definitions/rapidrelease/index.jsp
Sophos Protection available since 23rd October
Site explaining Trojan/ worm http://blog.threatexpert.com/2008/10/gimmiva-exploits-zero-day-vulnerability.html
worm won't be far behind......
Trending Topics
aka Turbosailorboy
iTrader: (5)
Joined: Apr 2005
Posts: 6,527
Likes: 21
From: Under the water.... .......in a nuclear submarine
It starts from probing other IPs from the same network by sending them a sequence of bytes "abcde" or "12345". The worm then attempts to exploit other machines by sending them a malformed RPC request and relying on a vulnerable Server service. As known, Server service uses a named pipe SRVSVC as its RPC interface, which is registered with UUID equal to 4b324fc8-1670-01d3-1278-5a47bf6ee188. In order to attack it, the worm firstly attempts to bind SRVSVC by constructing the following RPC request:
I agree Lee


20K+ Super Poster.
Joined: May 2003
Posts: 20,599
Likes: 0
From: Ramsgate, Kent Drives: E39 530D Touring
thanks for the heads up mark. have passed this information onto the powers that be for them to totally ignore 
its fun this way when you turn up at the last minute, do a bit of overtime and save the day you look a proper hero

its fun this way when you turn up at the last minute, do a bit of overtime and save the day you look a proper hero
I doubt my Internal Support Team have any idea about this, let alone know how to rectify it
They send around an e-mail saying they have approved the latest windows updates for download each time they are out, they don't know I've got service pack 3 on the machine
They send around an e-mail saying they have approved the latest windows updates for download each time they are out, they don't know I've got service pack 3 on the machine
threat status was downgraded over the weekend. we've still patched everything though just in case. took us about 3 hours to do 1800 workstations + 500 laptops
unfortunately for the server team, they're so out of date that they're having to install a service pack as a perrequisite on most of their servers. took them all weekend to do 350
unfortunately for the server team, they're so out of date that they're having to install a service pack as a perrequisite on most of their servers. took them all weekend to do 350
Thread
Thread Starter
Forum
Replies
Last Post








