Re: sasser worm

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Susan Bradley, CPA aka Ebitz SBS Rocks [MVP] (sbradcpa_at_pacbell.net)
Date: 05/04/04


Date: Mon, 03 May 2004 22:32:33 -0700

VPN from infected machine could infect it
Laptop brought back in could infect it

http://www.cpatechconf.com/photos/IMG_0646.JPG

Javier Gomez [SBS MVP] wrote:

> In theory (assuming all that you said) you would be protected. However, I
> would never leave a computer unpatched... very bad security practice.
> Furthermore, you can't rely on that no-VPN, no-floppy, no-roaming-laptops,
> no-emails, no-thumbdrives, no-nothing situation.
>
> There are vulnerabilities that can be exploited (that require user action)
> even in that scenario. I think several IE patches address issues on where
> people can host a malicious websites and lure you to them (thus getting
> infected). I don't think this particular one can be exploited that way...
> but I'm no security expert.
>
> Is always better one ounce of prevention that 10 pounds of the cure...
> right?
>



Relevant Pages

  • RE: Need Netsky_Q worm killer for macOS9
    ... This virus doesn't infect Mac's, unless you are running Virtual PC. ... What these messages indicate is that someone elses machine is infected, and the virus had found your email address, perhaps on that machine, perhaps from some web source--and is forging it. ... Unless your circle of friends and correspondents is rather small, you are unlikely to be able to spot the infected machine by looking at the pattern of addresses you can see. ... If you learn how to decode the headers you might be able to write to abuse@ the isp which is indicated by the headers, and they may take action to notify the owner of the infected machine. ...
    (microsoft.public.security.virus)
  • Re: [Full-Disclosure] Blaster: will it spread without tftp?
    ... > start to infect other systems... ... The tftp connection is made back to the machine that sent the original infection vector. ... So if somebody brings in a contaminated laptop, that laptop will start attacking, and ... any machines that get whacked will call that laptop for their tftp connection. ...
    (Full-Disclosure)
  • Re: Cant remove Partition table{MBR} virus NYB
    ... So should I format them on same machine/ How should I clean them? ... immediately write protect the 6 disk BEFORE sticking them into the infected machine, otherwise the 6 floppies will become infected and therefore infect any unprotected machine they're used on, they only have to be inserted in order to infect. ...
    (microsoft.public.windowsxp.general)