Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

Virus Advisory: W32/Nachi.worm

Thread Tools
 
Search this Thread
 
Old 18 August 2003, 05:05 PM
  #1  
JackClark
Scooby Senior
Thread Starter
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Post

Another high volume threat exploiting the MS03-026 vulnerability.
Info here
This one is detected by the daily dats available here
Old 18 August 2003, 05:13 PM
  #2  
Figment
Scooby Regular
 
Figment's Avatar
 
Join Date: Jul 2001
Location: deep inside your imagination
Posts: 24,057
Likes: 0
Received 0 Likes on 0 Posts
Post

Correct URL here

Am I correct in assuming that anyone who has already patched against msblaster should be safe(ish)?
Old 18 August 2003, 05:45 PM
  #3  
JackClark
Scooby Senior
Thread Starter
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Post

Thanks for the link.

You're correct, everyone should be safe'ish.
Old 18 August 2003, 05:52 PM
  #4  
Figment
Scooby Regular
 
Figment's Avatar
 
Join Date: Jul 2001
Location: deep inside your imagination
Posts: 24,057
Likes: 0
Received 0 Likes on 0 Posts
Post

NP, and cheers

Old 18 August 2003, 06:06 PM
  #5  
beemerboy
Scooby Regular
 
beemerboy's Avatar
 
Join Date: Sep 2002
Location: Essexville
Posts: 4,391
Likes: 0
Received 0 Likes on 0 Posts
Post

thanks for the headsup, Jack

BB
Old 18 August 2003, 10:06 PM
  #6  
carl
Scooby Regular
 
carl's Avatar
 
Join Date: May 1999
Posts: 7,901
Likes: 0
Received 0 Likes on 0 Posts
Post

TBH I'm astounded that anyone was caught by MSBlast. There must be people connected to the net without any sort of hardware or software firewall, and no AV software
Old 18 August 2003, 11:02 PM
  #7  
stu200
Scooby Regular
iTrader: (1)
 
stu200's Avatar
 
Join Date: Apr 2001
Posts: 531
Likes: 0
Received 0 Likes on 0 Posts
Post

carl,

There's millions of them ... unfortunately
Old 18 August 2003, 11:58 PM
  #8  
beemerboy
Scooby Regular
 
beemerboy's Avatar
 
Join Date: Sep 2002
Location: Essexville
Posts: 4,391
Likes: 0
Received 0 Likes on 0 Posts
Post

no AV software
irrelevant at the time...
Old 19 August 2003, 12:08 AM
  #9  
JackClark
Scooby Senior
Thread Starter
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Post

Antivirus software is very relevant, we detected this threat on the 07/29/2003. Info
Old 19 August 2003, 02:35 PM
  #10  
JackClark
Scooby Senior
Thread Starter
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Post

Update: the virus also attempts to exploit an NTDLL.DLL vulnerability (MS03-007) via WebDav.

Time to get patching again.
Old 19 August 2003, 03:15 PM
  #11  
SJ_Skyline
Scooby Senior
 
SJ_Skyline's Avatar
 
Join Date: Apr 2002
Location: Limbo
Posts: 21,922
Likes: 0
Received 1 Like on 1 Post
Talking

"The writer of the Nachi worm may want to be seen as the Dirty Harry of the internet world, cleaning up malicious Blaster code wherever it is found,"

said Graham Cluley, senior technology consultant at Sophos



PMSL
Old 19 August 2003, 03:22 PM
  #12  
JackClark
Scooby Senior
Thread Starter
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Post

Graham is such a funny man
Old 20 August 2003, 12:07 AM
  #13  
fast bloke
Scooby Regular
 
fast bloke's Avatar
 
Join Date: Nov 2000
Posts: 26,619
Likes: 0
Received 0 Likes on 0 Posts
Question

Jack - Can you actually confirm that the Nachi payload attempts to clean up remnants of blaster code?

If so, does anyone else find this a bit freaky - sort of like biological warfare without the rotting flesh?
Old 20 August 2003, 09:18 AM
  #14  
Nicks VR4
Scooby Regular
 
Nicks VR4's Avatar
 
Join Date: May 2003
Posts: 1,165
Likes: 0
Received 0 Likes on 0 Posts
Post

FB

http://vil.nai.com/vil/content/v_100559.htm
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Big RS Dave
ScoobyNet General
5
14 April 2001 08:12 PM



Quick Reply: Virus Advisory: W32/Nachi.worm



All times are GMT +1. The time now is 02:12 PM.