Tiki Central / General Tiki / Tiki Central access problems?
Post #89599 by Cultjam on 05/03/2004
C
Cultjam
Posted
posted
on
05/03/2004
It's this: W32/Sasser-A is a network worm that spreads by exploiting the Microsoft LSASS vulnerability. Microsoft has issued a patch to secure against this vulnerability which can be downloaded from Microsoft Security Bulletin MS04-011. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\avserve = avserve.exe W32/Sasser-A attempts to connect out on port TCP/9996 and TCP/445 and exploit the LSASS vulnerability. An FTP script is then downloaded and executed which connects back on port 5554 to download a copy of the worm via FTP. |