Sasser worm - why the internet is slow today !

Viruses, hackers and crackers
bb_matt
Registered User
Posts: 1652
Joined: 10 Nov 2003, 02:00
Location: Jhb

Sasser worm - why the internet is slow today !

Post by bb_matt »

http://news.bbc.co.uk/1/hi/technology/3682537.stm
Sasser net worm affects millions
Sasser spreads through networks by itself
The Sasser worm is continuing to cause disruption for large numbers of Windows PC users.

The first version of the malicious program was discovered on 1 May and since then has spread widely across the internet.

Some security experts estimate it has infected more than a million PCs and knocked out many computer systems.

Unlike more recent viruses, Sasser does not travel by e-mail instead it makes its way around the internet unaided.

Shut down

In at least seven cases, disruptions at large companies have been blamed on machines infected by Sasser.

The virus can infect PCs running Windows 2000 and XP that are not patched against the loophole it exploits.

According to anti-virus firms machines running Windows 95, 98 and Millennium Edition can help spread Sasser even though they cannot be infected by it.

The security firms urged users to install the latest security patches from Microsoft and advised home broadband users to install and run a firewall.

The virus is called a worm because it searches out machines to infect by itself without any help from users.

So far four variants of Sasser have been seen in the wild.

The latest version, Sasser.D, scans so aggressively for new computers to infect that it may cause networks to become congested with packets of data and slow down.

Poor programming by Sasser's creator makes infected machines shut down.

Microsoft and many security firms have released tools that help people find out if they are infected and to help them remove the virus from their system.

Users hit

Early reports suggest that home users will be hit hardest as many broadband users do not have a firewall fitted that would protect them from malicious programs like Sasser.

F-Secure said that many large companies had already installed the patch for the vulnerability Sasser exploits which may limit the ultimate spread of the worm.

Those that had not patched have been hit hard.

Taiwan's national post office said 1,600 of its machines were hit by the virus which forced more than 400 of its 1200 branch offices to revert to pen and paper.

The disruption left customers queuing in long lines at many of the company's offices, according to television reports.

Two Hong Kong government departments and some hospitals on the island were hit by the virus.

In Australia Railcorp trains were halted apparently because a virus disrupted the radio systems and stopped drivers talking to signalmen.

Also in Australia Westpac Bank staff were forced to use manual methods to record transactions as the virus made computers unusable. Two other banks reported infections.

Finnish bancassurer Sampo said it had temporarily closed all its 130 branch offices as a precaution against Sasser.

US airline Delta would not comment on reports that the virus caused disruption to its schedule.

Patch here

Microsoft played down reports that millions were being infected by Sasser.

It reported that almost four times as many PC owners were downloading patches for security problems now compared to autumn in 2003.

A patch for the vulnerability Sasser exploits was first released on 13 April and then updated on 28 April.

Holidays in the UK, parts of Europe and Japan may also help to limit the spread of the worm.

Some security experts said that using Sasser removal tools may not end the trouble because many of those caught out by it have also been infected by other viruses.

Creators of other malicious programs are trying to cash in on the success of Sasser.

The latest version of the Netsky virus, the 29th variant, travels with a file that claims to be a cure for Sasser sent out by anti-virus firms.

Inside this version the creators of Netsky claim that they were responsible for making Sasser too.
so get patching and checking !

Free removal tool :-

http://securityresponse.symantec.com/av ... .worm.html

Microsoft security bulletin with download links to patch :-

http://www.microsoft.com/technet/securi ... 4-011.mspx
bb_matt
Registered User
Posts: 1652
Joined: 10 Nov 2003, 02:00
Location: Jhb

Post by bb_matt »

For some reason, my first post of this was removed with no reason... :roll:
OnlyOneKenobi
Moderator Emeritus
Posts: 19641
Joined: 07 Mar 2003, 02:00
Location: A Galaxy Far, Far Away

Post by OnlyOneKenobi »

I just moved it to security where it belongs.
Image

Intel Core i7-950 | MSI X58 Pro-E, STK1366 | Geforce GTX470 1280 | 8GB DDR3 1333Mhz RAM | Samsung 226BW Monitor | Windows 7 Home Premium
bb_matt
Registered User
Posts: 1652
Joined: 10 Nov 2003, 02:00
Location: Jhb

Post by bb_matt »

Yeah, but it was a reply to Yoda's question in chillout relax.

Leave a ghost thread.
OnlyOneKenobi
Moderator Emeritus
Posts: 19641
Joined: 07 Mar 2003, 02:00
Location: A Galaxy Far, Far Away

Post by OnlyOneKenobi »

bb_matt wrote:Yeah, but it was a reply to Yoda's question in chillout relax.

Leave a ghost thread.
The thread is still visible in the quick launch bar, and you could either reply to his topic or link to this one from that topic.
Image

Intel Core i7-950 | MSI X58 Pro-E, STK1366 | Geforce GTX470 1280 | 8GB DDR3 1333Mhz RAM | Samsung 226BW Monitor | Windows 7 Home Premium
bb_matt
Registered User
Posts: 1652
Joined: 10 Nov 2003, 02:00
Location: Jhb

Post by bb_matt »

Whatever, I didn't post it in chillout by accident, that was done on purpose because not everyone visits security and it's a pretty serious issue today.
OnlyOneKenobi
Moderator Emeritus
Posts: 19641
Joined: 07 Mar 2003, 02:00
Location: A Galaxy Far, Far Away

Post by OnlyOneKenobi »

I'm not going to argue about this with you, the post belongs in security and it is still visible to everyone on the quick launch bar for now - by the end of the day it would have been at the bottom of the chill out relax section and nobody would have seen it anyway unless it was bumped. At least now it's still at the top of the security section, and will stay at the top for a while.
Image

Intel Core i7-950 | MSI X58 Pro-E, STK1366 | Geforce GTX470 1280 | 8GB DDR3 1333Mhz RAM | Samsung 226BW Monitor | Windows 7 Home Premium
bb_matt
Registered User
Posts: 1652
Joined: 10 Nov 2003, 02:00
Location: Jhb

Post by bb_matt »

I already made a post here about the damn sasser worm !
Tel
Moderator Emeritus
Posts: 3046
Joined: 09 Oct 2003, 02:00
Location: Wellington, NZ
Contact:

Post by Tel »

Image
Image
Be Silly. Be Honest. Be Kind. | Ralph Waldo Emerson
Synkronos
Moderator Emeritus
Posts: 1914
Joined: 13 Mar 2003, 02:00
Location: Cape Town
Contact:

Post by Synkronos »

Mod wars!!

Oh, and *bump*
I thought what I'd do was, I'd pretend I was one of those deaf-mutes.
bb_matt
Registered User
Posts: 1652
Joined: 10 Nov 2003, 02:00
Location: Jhb

Post by bb_matt »

http://news.bbc.co.uk/1/hi/technology/3682803.stm
Worm brings down coastguard PCs

Coastguard stations around the UK have been severely disrupted after the Sasser worm brought down IT systems.

The worm has hit all 19 coastguard stations and the service's headquarters, leaving officers reliant on pens and paper.

But there is no danger to the public, a UK Maritime and Coastguard Agency spokeswoman said.

Its computer mapping facilities are not working but staff are still able to use paper maps, she added.
Kher-za
Registered User
Posts: 6500
Joined: 03 Feb 2004, 02:00
Location: Counting Miles On The Road To Perdition
Contact:

Post by Kher-za »

the computer i logged on through this morning shut down by itself, we're running win 2000 prof 8O
Tel
Moderator Emeritus
Posts: 3046
Joined: 09 Oct 2003, 02:00
Location: Wellington, NZ
Contact:

Post by Tel »

Infected :twisted: :wink:
Image
Be Silly. Be Honest. Be Kind. | Ralph Waldo Emerson
Kher-za
Registered User
Posts: 6500
Joined: 03 Feb 2004, 02:00
Location: Counting Miles On The Road To Perdition
Contact:

Post by Kher-za »

i feel violated!
Ri0t
Registered User
Posts: 290
Joined: 04 Apr 2003, 02:00
Location: PTA

Post by Ri0t »

these ppl are full of *****
they make it sound 100 000 000 times worse than it really is
Kher-za
Registered User
Posts: 6500
Joined: 03 Feb 2004, 02:00
Location: Counting Miles On The Road To Perdition
Contact:

Post by Kher-za »

sorry for mentioning it, BloWiNg StuFf out of proportion just does it for me.

and i was being sarcastic, why wud it bother me? if it were my home pc i'd be blowing it out of proportion!
Zellin
Registered User
Posts: 149
Joined: 09 Apr 2003, 02:00

Post by Zellin »

DAM!!! my poor cousin... he never knew what hit him. His Home PC was dying i told wait a few days before you format a removal tool will come... tsk...tsk :twisted:
"Fake smiles surround me all day,
No more can I tolerate,
These excuses
or all this" - Chimaira
Thrall
Moderator Emeritus
Posts: 3687
Joined: 30 Apr 2003, 02:00
Location: Texas, USA

Post by Thrall »

Sounds like he learned the hard way, like we all do :?
Be polite, professional and have a plan to kill everyone you meet.

My Iraq pics
jee
Registered User
Posts: 19336
Joined: 03 Jun 2003, 02:00
Location: a hole so deep...

Post by jee »

Oh my, trigger happy again I see..... hmmmm such importance....
"Integrity" and "integer" both contain a Latin root meaning "whole; complete." The root sense, then, is that people may be said to be acting with integrity when their beliefs, words, and actions have a sense of unity or wholeness.
OnlyOneKenobi
Moderator Emeritus
Posts: 19641
Joined: 07 Mar 2003, 02:00
Location: A Galaxy Far, Far Away

Post by OnlyOneKenobi »

Jee wrote:Oh my, trigger happy again I see..... hmmmm such importance....
Sorry I don't follow, care to explain what you're talking about?
Image

Intel Core i7-950 | MSI X58 Pro-E, STK1366 | Geforce GTX470 1280 | 8GB DDR3 1333Mhz RAM | Samsung 226BW Monitor | Windows 7 Home Premium
jee
Registered User
Posts: 19336
Joined: 03 Jun 2003, 02:00
Location: a hole so deep...

Post by jee »

That is exactly what i'm talking about.....
"Integrity" and "integer" both contain a Latin root meaning "whole; complete." The root sense, then, is that people may be said to be acting with integrity when their beliefs, words, and actions have a sense of unity or wholeness.
OnlyOneKenobi
Moderator Emeritus
Posts: 19641
Joined: 07 Mar 2003, 02:00
Location: A Galaxy Far, Far Away

Post by OnlyOneKenobi »

Jee wrote:That is exactly what i'm talking about.....
Just like you to side with anyone who disagrees with me. The fact of the matter is the topic belongs here, if you don't like it, too bad. I'm not wasting my time with you anymore.
Image

Intel Core i7-950 | MSI X58 Pro-E, STK1366 | Geforce GTX470 1280 | 8GB DDR3 1333Mhz RAM | Samsung 226BW Monitor | Windows 7 Home Premium
Thrall
Moderator Emeritus
Posts: 3687
Joined: 30 Apr 2003, 02:00
Location: Texas, USA

Post by Thrall »

Ok, everyone calm down and take a breath, please - I don't think it's something worth getting all het-up about.
Be polite, professional and have a plan to kill everyone you meet.

My Iraq pics
jee
Registered User
Posts: 19336
Joined: 03 Jun 2003, 02:00
Location: a hole so deep...

Post by jee »

Ok Thrall, but only because of respect for you.....
"Integrity" and "integer" both contain a Latin root meaning "whole; complete." The root sense, then, is that people may be said to be acting with integrity when their beliefs, words, and actions have a sense of unity or wholeness.
Thrall
Moderator Emeritus
Posts: 3687
Joined: 30 Apr 2003, 02:00
Location: Texas, USA

Post by Thrall »

Thanks, Jee *huggle*
Be polite, professional and have a plan to kill everyone you meet.

My Iraq pics
Post Reply