[Snort-users] MS05-039 and Zotob worm

This is a discussion on [Snort-users] MS05-039 and Zotob worm within the Snort forums, part of the System Security and Security Related category; The Sourcefire Vulnerability Research Team (VRT) has received reports of a new worm variant, known as Zotob, that makes use ...


Go Back   Usenet Forums > System Security and Security Related > Snort

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 08-15-2005
Nigel Houghton
 
Posts: n/a
Default [Snort-users] MS05-039 and Zotob worm

The Sourcefire Vulnerability Research Team (VRT) has received reports of
a new worm variant, known as Zotob, that makes use of the Plug-and-Play
(PnP) vulnerability (MS05-039) to propogate. The worm uses exploit code
that targets the PnP issue via port 445 and upon sucessful exploitation,
it then uses ftp to transfer data from the infecting machine. The newly
infected machine then becomes an ftp server iteself and begins scanning
for other vulnerable hosts to infect.

The VRT released rules on August 12th, 2005 that detect all attempts to
exploit this vulnerability. These rules are identified as sids 3828
through 4125. The Zotob worm will alert on SID 3999. Inline users may
wish to set this rule to 'drop' for added protection.

In addition, a patch for this vulnerability is available at
http://www.microsoft.com/technet/sec.../MS05-039.mspx.

Download Rules:
These rules will be available to subscribers only until August 17th, 2005.
Subscribers can download the rules at http://www.snort.org/pub-bin/downloads.cgi.

If you would like to purchase a subscription, please visit
http://www.snort.org/rules/why_subscribe.html, contact Dale Reynolds at
(703) 462-2639 or send email to snort-sub@sourcefire.com.

+--------------------------------------------------------------------+
Nigel Houghton Research Engineer Sourcefire Inc.
Vulnerability Research Team



-------------------------------------------------------
SF.Net email is Sponsored by the Better Software Conference & EXPO
September 19-22, 2005 * San Francisco, CA * Development Lifecycle Practices
Agile & Plan-Driven Development * Managing Projects & Teams * Testing & QA
Security * Process Improvement & Measurement * http://www.sqe.com/bsce5sf
_______________________________________________
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/...fo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.p...st=snort-users
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 10:55 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0