Full Disclosure mailing list archives

Re: Red Bull Worm


From: "CHeeKY" <cheekypeople () sec33 com>
Date: Thu, 7 Aug 2003 18:09:10 +0100

I say CloseButNoCigar"


-------------------------------------------------------------------------
FIGHT BACK AGAINST SPAM!
Download Spam Inspector, the Award Winning Anti-Spam Filter
http://mail.giantcompany.com


----- Original Message ----- 
From: "Berend-Jan Wever" <SkyLined () edup tudelft nl>
To: <full-disclosure () lists netsys com>
Sent: Thursday, August 07, 2003 5:18 PM
Subject: Re: [Full-disclosure] Red Bull Worm


Why not call it SkyNet, after T3 ?

SkyLined
----- Original Message ----- 
From: "Joel R. Helgeson" <joel () helgeson com>
To: <full-disclosure () lists netsys com>
Sent: Thursday, August 07, 2003 17:53
Subject: [Full-disclosure] Red Bull Worm


Lets see, the last big worm to exploit windows was named Code Red after
the
Mountain Dew Code Red was brought to market.  Being that this worm is
much
more effective than Code Red ever was, I say worm should be named Red
Bull
as it is sure to exhibit much more energy than the Code Red worm.

---- Original Message ----- 
From: "Stephen" <alf1num3rik () yahoo com>
To: <full-disclosure () lists netsys com>
Sent: Thursday, August 07, 2003 5:25 AM
Subject: [Full-disclosure] DCOM Worm/scanner/autorooter !!!



Hello here,

a new worm is on the wild, it uses the exploit
released by k-otik (48 targets -
http://www.k-otik.com/exploits/07.30.dcom48.c.php)

look this shit :

/* RPC DCOM WORM v 2.2  -
 * This code is in relation to a specific DDOS IRCD
botnet project.
 * You may edit the code, and define which ftp to
login
 * and which .exeutable file to recieve and run.
 * I use spybot, very convienent
 * -
 * So basicly script kids and brazilian children, this
is useless to you
 *

So PATCH PATCH PATCH and block the ports 135 - 139
-445 - 593

Regards.

Stephen - Germany

__________________________________
Do you Yahoo!?
Yahoo! SiteBuilder - Free, easy-to-use web site design software
http://sitebuilder.yahoo.com
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html




_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: