Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old March 21st, 2004, 08:35 AM
gerardwil gerardwil is online now
Massive Poster
 
Join Date: Jan 2004
Posts: 4,508
Default w32.witty.worm

W32.Witty.Worm
Discovered on: March 20, 2004
Last Updated on: March 21, 2004 09:55:11 AM

W32.Witty.Worm utilizes a Vulnerability in ICQ Parsing by ISS Products. The worm sends itself out to multiple IP addresses on source port 4000/UDP and a random destination port. The worm is a memory-only based threat and does not create files on the system.

The worm has a payload of overwriting random sectors of a random hard disk.

NOTE: If your system is not running a vulnerable version of one of the products affected, then you will not be infected. Products affected by this vulnerability are listed below:

BlackICE™ Agent for Server 3.6 ebz, ecd, ece, ecf
BlackICE PC Protection 3.6 cbz, ccd, ccf
BlackICE Server Protection 3.6 cbz, ccd, ccf
RealSecure® Network 7.0, XPU 22.4 and 22.10
RealSecure Server Sensor 7.0 XPU 22.4 and 22.10
RealSecure Desktop 7.0 ebf, ebj, ebk, ebl
RealSecure Desktop 3.6 ebz, ecd, ece, ecf
RealSecure Guard 3.6 ebz, ecd, ece, ecf
RealSecure Sentry 3.6 ebz, ecd, ece, ecf

If you are running a product that has the vulnerability used by the worm, we recommend that you apply the relevant patch as soon as possible. Patches for this vulnerability are available at http://blackice.iss.net/update_center/index.php.

Symantec Security Response recommends that administrators block inbound and outbound traffic to their networks on source port 4000/UDP. Please note that the destination port for traffic generated by the worm is selected randomly.




__________________
25 forum posting etiquette tips
  #2  
Old March 21st, 2004, 09:41 AM
snowbound snowbound is offline
Retired Moderator
 
Join Date: Feb 2003
Location: The Big Smoke
Posts: 8,727
Default Re:w32.witty.worm

Since there is already reference to this here,

http://www.wilderssecurity.com/showthread.php?t=25182

this thread is closed.




snowbound
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 08:22 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums