- New anti-blaster worm attempts to fix RPC/DCOM vuln - W32/Nachi.worm
- Posted by Lord Shaolin on August 19th, 2003
Info from: http://www.security-forums.com/forum...pic.php?t=7631
Synopsis:
UPDATED: New variants of the MS Blast worm have been detected in the wild.
A new worm has also been discovered that exploits the MSRPC DCOM
vulnerability that is not related to the MS Blast variants. This new worm
has been labeled "Nachi", and also labeled incorrectly as a LovSan.D. The
Nachi worm has improved scanning logic, feature improvements, and auto-
patching functionality. It also propagates by an additional exploit vector,
exploiting the WebDAV vulnerability in Microsoft's IIS 5 Web Server.
Impact:
UPDATED: The Nachi worm will infect vulnerable Windows XP machines using
the same exploit used by the MS Blast worm family. The main difference
between Nachi and MS Blast, is that Nachi will remove and disable MS Blast
infections that it encounters, and download and install the correct MSRPC
DCOM patch from Microsoft. This action will permanently close the MSRPC
DCOM vulnerability. The Nachi worm will not patch the WebDAV vulnerability
on Windows 2000 Servers.
Description:
UPDATED: Nachi Worm
The Nachi worm is technically superior to its predecessors. Its scanning
logic is more robust, it has the ability to propagate more quickly and it
will clean computers infected with MS Blast. It contains an additional
exploit
vector which exploits Microsoft IIS 5.0 via WebDAV. The Nachi worm seems to
have
been designed for benevolent purposes only. There is no viral or DDoS
payload. Expanded technical details are included below:
From ISS - http://xforce.iss.net/xforce/alerts/id/150
Full info from Symantec:
http://www.sarc.com/avcenter/venc/da...chia.worm.html
Removal tool:
http://securityresponse.symantec.com...oval.tool.html
Original Blaster info:
http://www.security-forums.com/forum...pic.php?t=7474
Cheers
--
-+ Shaolin +-
Discard what is useless, absorb what is not and
add what is uniquely your own.
.: http://www.security-forums.com :.
- Posted by donut on August 19th, 2003
"Lord Shaolin" <abuse@127.0.0.1> wrote in
news:vk3p2fsf5c01f9@corp.supernews.com:
What is to prevent that from changing, once the creator(s) have discovered
how effective it is?
As with any worm, scour, disallow, disinfect, and protect (first and
foremost.)
- Posted by R Green -WoWsat.com on August 19th, 2003
Wouldn't be surprised if Microsoft had released this worm in an effort to
protect their own arse (ie. the windowsupdate site)..
R Green
Technical Support
--------------------------
WoWsat.com
--------------------------
"Lord Shaolin" <abuse@127.0.0.1> wrote in message
news:vk3p2fsf5c01f9@corp.supernews.com...
- Posted by J. Reilink on August 20th, 2003
R Green -WoWsat.com wrote:
Yeah, right... If you've read the article(s) you'd know that the worm does a
little more than patching the RPC DCOM hole. Among other things, it exploits
a vulnerability in NTDLL.DLL (MS03-007) and overwrites some files (such as
DLLHOST.EXE and SVCHOST.EXE).
--
Met vriendelijke groet / Best regards,
Jan Reilink
Dutch Security Information Network,
http://www.dsinet.org
- Posted by Hü©klëßë®®ÿ on August 20th, 2003
Gee, wouldn't it be a great move for someone to write a DESTRUCTIVE virus
and name it "FixBlast" or "FixBlaster" so that people would PURPOSELY
download it!!!
"J. Reilink" <digiover@dsinet.org> wrote in message
news:vk6om55sv57b0e@corp.supernews.com...
- Posted by John Tate on August 20th, 2003
On Tue, 19 Aug 2003 16:01:53 +0000, R Green -WoWsat.com wrote:
isnt viral or ddosing, maybe he just wanted to flood the internet with
crap. making it the third worm this year to do it, and all 3 being
Microsoft Products.
And they say they know security.
- Posted by John Tate on August 20th, 2003
On Wed, 20 Aug 2003 14:00:10 +0200, J. Reilink wrote:
be the same guy who did blaster.