AlphaOne Technology Support Forums
Welcome, Guest. Please login or register.
December 02, 2008, 06:06:22 AM

Login with username, password and session length
Search:     Advanced search
1733 Posts in 827 Topics by 4755 Members
Latest Member: typetroyk
* Home Help Search Login Register
AlphaOne Technology Support Forums  |  IMPORTANT ANNOUNCEMENTS  |  Security Announcements  |  Windows-based Security Issues  |  Topic: ALERT - The Zotob.A worm exploiting the MS05-039 flaw 0 Members and 1 Guest are viewing this topic. « previous next »
Pages: [1] Go Down Print
Author Topic: ALERT - The Zotob.A worm exploiting the MS05-039 flaw  (Read 816 times)
TJ
Tech Team
Hero Member
********
Offline Offline

Posts: 136



View Profile
ALERT - The Zotob.A worm exploiting the MS05-039 flaw
« on: August 14, 2005, 09:05:09 AM »

Description

Alias : W32/Zotob.A
Type : Worm
Taille : 22,528 bytes

Technical details

Zotob.A is a worm that exploits the recent Plug-and-Play vulnerability (MS05-039) using TCP port 445. The worm targets only Windows 2000 machines.

This worm attempts to download the "haha.exe" file to %SYSTEM%\"botzor.exe" and then execute it. When Zotob.A runs, it does the following :

- Adds the value : "WINDOWS SYSTEM" = "botzor.exe" to the registry so that the worm runs when Windows starts.
- Opens a shell on port 8888
- Installs an FTP server on port 33333
- Connects to a predefined IRC channel
- Connects to the generated IP address on TCP port 445 to determine if a remote computer is vulnerable
- When a vulnerable system is found, the worm sends a copy of itself to this machine via the FTP server

Recommendations

We recommend that you apply the appropriate patches, filter access to TCP ports 139/445, and block ports 8888 and 33333 at the firewall level.
Logged
Pages: [1] Go Up Print 
AlphaOne Technology Support Forums  |  IMPORTANT ANNOUNCEMENTS  |  Security Announcements  |  Windows-based Security Issues  |  Topic: ALERT - The Zotob.A worm exploiting the MS05-039 flaw « previous next »
Jump to:  

Powered by MySQL Powered by PHP AlphaOne Technology Support Forums | Powered by SMF 1.0.7.
© 2001-2005, Lewis Media. All Rights Reserved.
Valid XHTML 1.0! Valid CSS!