Free Republic
Browse · Search
News/Activism
Topics · Post Article

To: nw_arizona_granny
Yesterday when I read about this Sasser worm, it wasn't thought to be a serious threat because it's code is poorly written. Now the articles I'm reading state that it's threat is increasing. This article is disturbing because it shows how serious a computer worm can be.

http://www.enterpriseitplanet.com/security/news/article.php/3348291

Sasser eyed over train outage
Chris Jenkins
MAY 03, 2004

NSW TRAINS authority RailCorp has sent in software engineers to find the source of the outage that left up to 300,000 commuters stranded yesterday, saying the new Sasser worm, which has already spawned two variants, is being evaluated as a possible cause.

A RailCorp spokesman confirmed that software engineers were investigating the problem, which prevented drivers from talking to signal boxes. A virus attack was one possibility being investigated, he said. RailCorp was unable to confirm when the investigation would be complete.
RailCorp chief executive Vince Graham raised the possibility of a virus attack at a press briefing yesterday. "There is no evidence that hacking is an issue here, the viral infection could have been introduced by one of our own people not taking sufficient care," Sydney's Daily Telegraph reported Mr Graham as saying.

The first incidence of the Sasser virus occurred in the US on Friday. Unlike other recent attacks, Sasser does not require email to propagate, instead "pinging" the internet for computers with the Windows operating system vulnerability it is designed to exploit.

Sasser leaves no obvious sign that it has infected a PC, meaning users may be unaware of its presence.

The Local Security Authority Subsystem Service (LSASS) vulnerability exists in versions of Windows XP, Windows 2000 and Windows Server 2003. Microsoft advised of the problem and issued a patch April 13.

Microsoft has also posted a notice on its website warning Windows users of the dangers and a tool to remove the worm. The patch provided by Microsoft meant it was likely that small businesses and home users, especially those on broadband connections, would be affected by the worm, technical director for internet security firm Symantec Tim Hartman said.

The first "a" version of Sasser to appear was designed to search for new IP addresses to attack via 128 different threads, Mr Hartman said. The more recent "c" variant used 1024 threads, he said. The traffic created by the worm could place "quite a burden on the internet," he said.

This report appears on australianIT.com.au.
1,758 posted on 05/02/2004 9:42:23 PM PDT by Honestly
[ Post Reply | Private Reply | To 1757 | View Replies ]


To: Honestly; All
I have to wonder if Delta Airlines Computer failed from your worm/virus?

This is an interesting site, worth digging around on, at the database of terrorist acts, the ships and phones are of interest, (others may be also), the numbers are clickable.

http://db.mipt.org/mipt_rand.cfm

http://db.mipt.org/rep_5tota_crit.cfm

http://mipt.org
1,778 posted on 05/02/2004 11:08:21 PM PDT by nw_arizona_granny (Google search: name of America's enemy within (also try with 1425 in front of search))
[ Post Reply | Private Reply | To 1758 | View Replies ]

To: Honestly
You know Honestly, I wonder if this is what truly affected the Delta flights system?
1,783 posted on 05/02/2004 11:18:56 PM PDT by JustPiper (Look for the dream that keeps coming back - It is your destiny)
[ Post Reply | Private Reply | To 1758 | View Replies ]

To: Honestly
Sasser Worm Analysis

Handler's Diary: Multiple Exploits targeting Microsoft MS-04-011 vulnerabilities threaten networks.

1,784 posted on 05/02/2004 11:22:23 PM PDT by LayoutGuru2 (Call me paranoid but finding '/*' inside this comment makes me suspicious)
[ Post Reply | Private Reply | To 1758 | View Replies ]

To: Honestly
CNN.com - Sasser worm rips through Internet - May 4, 2004
2,181 posted on 05/04/2004 12:43:14 PM PDT by LayoutGuru2 (Call me paranoid but finding '/*' inside this comment makes me suspicious)
[ Post Reply | Private Reply | To 1758 | View Replies ]

Free Republic
Browse · Search
News/Activism
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson