Sasser worm strikes PC's worldwide


Reply
 
Thread Tools Display Modes
Old 04-05-2004   #1
Sab
Regular Member
 
Sab's Avatar
 
Join Date: 01-01-2000
Location: North Wales
Posts: 152
Thanks: 0
Thanked 1 Time in 1 Post

My System: DM 500 Gemini Release 3.0.0 Camd3.883
Sasser worm strikes PC's worldwide

The following extract is from Yahoo's news site 04.05.04
Attached Files
File Type: doc Sasser worm.doc (14.5 KB, 12 views)
Sab is offline   Reply With Quote
Old 04-05-2004   #2
Believe it when I see it Admin.
 
rolfw's Avatar
 
Join Date: 01-05-1999
Location: Southern England
Posts: 27729
Thanks: 34
Thanked 732 Times in 507 Posts
Blog Entries: 3

My System: Sky+, DB 7000s, Gemini 4.3 in flash, Var on USB stick. Transparent 80cm Dish, Moteck SG2100 DiseqC motor, lots of legacy gear. Meters: Satlook Digital NIT, Unaohm EP313, Swires Annie 204 Spectrum, Rover ST-4 Spectrum.

Have copied this to general Chat as well, members need to be aware of this and update with the latest security patch from Microsoft URL http://download.microsoft.com/downlo...32-x86-ENU.EXE. If they haven't already got one, then download one of the many free firewalls.

http://search.tucows.com/search?sear....tucows.com%2F
__________________
Rolf
If you enjoy our site, you can help support it by wearing our unique branded merchandise, you can do this by clicking on my baseball cap, making a direct donation with Paypal by clicking on the Donation button below, or using our site supporting advertisers, to do this, click on the central image below



Donate
rolfw is online now   Reply With Quote
Old 04-05-2004   #3
Super Minty Mod
 
PoloMint's Avatar
 
Join Date: 31-12-1999
Location: Fife, Scotland
Posts: 1587
Thanks: 5
Thanked 11 Times in 8 Posts

My System: 1200cc with 100,000,000,000 neurons and 100,000,000,000,000 connections

Yes, it’s important people actually go to that link and get the file, as it is not part of windows update (yet), well it wasn’t an hour or so ago anyway which was surprising.
__________________


'All you need is duck tape and WD40; if it moves and it shouldn't, use duck tape - if it should move and it doesn't, use WD40'
PoloMint is offline   Reply With Quote
Old 04-05-2004   #4
GotMyBusPass
Guest
 
Posts: n/a
Thumbs up

Thank's for the link rolfw.

GMBP
  Reply With Quote
Old 04-05-2004   #5
Believe it when I see it Admin.
 
rolfw's Avatar
 
Join Date: 01-05-1999
Location: Southern England
Posts: 27729
Thanks: 34
Thanked 732 Times in 507 Posts
Blog Entries: 3

My System: Sky+, DB 7000s, Gemini 4.3 in flash, Var on USB stick. Transparent 80cm Dish, Moteck SG2100 DiseqC motor, lots of legacy gear. Meters: Satlook Digital NIT, Unaohm EP313, Swires Annie 204 Spectrum, Rover ST-4 Spectrum.

No problem GMBP, as a matter of interest, I looked at my router log this afternoon and it had been bombarded with probes.

Code:
Mon, 2004-05-03 11:19:42 - TCP Packet - Source:217.44.204.155,50124 Destination:192.168.0.253,41000 - [DOS]
Mon, 2004-05-03 11:19:43 - TCP Packet - Source:217.44.204.155,50128 Destination:192.168.0.253,41000 - [DOS]
Mon, 2004-05-03 11:19:43 - TCP Packet - Source:217.44.204.155,50129 Destination:192.168.0.253,41000 - [DOS]
Mon, 2004-05-03 11:19:43 - TCP Packet - Source:217.44.204.155,50137 Destination:192.168.0.253,41000 - [DOS]
Mon, 2004-05-03 11:19:45 - TCP Packet - Source:217.44.204.155,50150 Destination:192.168.0.253,41000 - [DOS]
Mon, 2004-05-03 11:19:45 - TCP Packet - Source:217.44.204.155,50151 Destination:192.168.0.253,41000 - [DOS]
Mon, 2004-05-03 11:19:45 - TCP Packet - Source:217.44.204.155,50153 Destination:192.168.0.253,41000 - [DOS]
Mon, 2004-05-03 11:19:45 - TCP Packet - Source:217.44.204.155,50154 Destination:192.168.0.253,41000 - [DOS]
Mon, 2004-05-03 11:19:50 - TCP Packet - Source:217.44.204.155,50162 Destination:192.168.0.253,41000 - [DOS]
Mon, 2004-05-03 11:19:50 - TCP Packet - Source:217.44.204.155,50164 Destination:192.168.0.253,41000 - [DOS]
Mon, 2004-05-03 11:19:51 - TCP Packet - Source:217.44.204.155,50165 Destination:192.168.0.253,41000 - [DOS]
Mon, 2004-05-03 11:19:54 - TCP Packet - Source:217.44.204.155,50168 Destination:192.168.0.253,41000 - [DOS]
Mon, 2004-05-03 11:19:54 - TCP Packet - Source:217.44.204.155,50169 Destination:192.168.0.253,41000 - [DOS]
Mon, 2004-05-03 11:19:54 - TCP Packet - Source:217.44.204.155,50154 Destination:192.168.0.253,41000 - [DOS]
Mon, 2004-05-03 11:26:04 - TCP Packet - Source:217.43.148.86,3067 Destination:192.168.0.253,135 - [DOS]
Mon, 2004-05-03 11:28:50 - TCP Packet - Source:217.44.204.155,50354 Destination:192.168.0.253,41000 - [DOS]
Mon, 2004-05-03 11:34:22 - TCP Packet - Source:217.44.204.155,50404 Destination:192.168.0.253,41000 - [DOS]
Mon, 2004-05-03 11:34:58 - TCP Packet - Source:217.43.112.251,4005 Destination:192.168.0.253,135 - [DOS]
Mon, 2004-05-03 12:18:08 - TCP Packet - Source:217.43.171.186,1537 Destination:192.168.0.253,445 - [DOS]
Mon, 2004-05-03 12:18:09 - TCP Packet - Source:217.43.171.186,1535 Destination:192.168.0.253,135 - [DOS]
Mon, 2004-05-03 13:05:10 - TCP Packet - Source:217.43.155.120,1196 Destination:192.168.0.253,1025 - [DOS]
Mon, 2004-05-03 13:05:10 - TCP Packet - Source:217.43.155.120,1197 Destination:192.168.0.253,445 - [DOS]
Mon, 2004-05-03 13:05:10 - TCP Packet - Source:217.43.155.120,1195 Destination:192.168.0.253,135 - [DOS]
Mon, 2004-05-03 13:16:19 - TCP Packet - Source:217.43.84.229,4292 Destination:192.168.0.253,2745 - [DOS]
Mon, 2004-05-03 13:39:36 - TCP Packet - Source:217.43.125.44,1827 Destination:192.168.0.253,135 - [DOS]
Mon, 2004-05-03 13:39:36 - TCP Packet - Source:217.43.36.128,2459 Destination:192.168.0.253,445 - [DOS]
Mon, 2004-05-03 13:45:41 - TCP Packet - Source:217.42.233.248,3344 Destination:192.168.0.253,445 - [DOS]
Mon, 2004-05-03 14:18:00 - TCP Packet - Source:217.43.160.121,2361 Destination:192.168.0.253,445 - [DOS]
Mon, 2004-05-03 14:18:01 - TCP Packet - Source:81.153.144.74,3412 Destination:192.168.0.253,2745 - [DOS]
Mon, 2004-05-03 14:25:27 - TCP Packet - Source:217.43.71.118,3572 Destination:192.168.0.253,1025 - [DOS]
Mon, 2004-05-03 14:25:27 - TCP Packet - Source:217.43.71.118,3573 Destination:192.168.0.253,445 - [DOS]
Mon, 2004-05-03 14:48:03 - TCP Packet - Source:217.43.169.98,3663 Destination:192.168.0.253,135 - [DOS]
Mon, 2004-05-03 15:08:01 - TCP Packet - Source:217.57.230.154,3942 Destination:192.168.0.253,135 - [DOS]
Mon, 2004-05-03 15:08:02 - TCP Packet - Source:217.57.230.154,3957 Destination:192.168.0.253,445 - [DOS]
Mon, 2004-05-03 15:24:53 - TCP Packet - Source:80.46.163.142,3778 Destination:192.168.0.253,41000 - [DOS]
Mon, 2004-05-03 15:24:55 - TCP Packet - Source:80.46.163.142,3788 Destination:192.168.0.253,41000 - [DOS]
Mon, 2004-05-03 15:24:55 - TCP Packet - Source:80.46.163.142,3789 Destination:192.168.0.253,41000 - [DOS]
Mon, 2004-05-03 15:24:55 - TCP Packet - Source:80.46.163.142,3790 Destination:192.168.0.253,41000 - [DOS]
Mon, 2004-05-03 15:24:58 - TCP Packet - Source:80.46.163.142,3800 Destination:192.168.0.253,41000 - [DOS]
Mon, 2004-05-03 15:24:58 - TCP Packet - Source:80.46.163.142,3799 Destination:192.168.0.253,41000 - [DOS]
Mon, 2004-05-03 15:39:09 - TCP Packet - Source:217.43.99.253,3804 Destination:192.168.0.253,135 - [DOS]
Mon, 2004-05-03 15:39:09 - TCP Packet - Source:217.42.182.50,3270 Destination:192.168.0.253,135 - [DOS]
Mon, 2004-05-03 16:53:22 - TCP Packet - Source:217.43.173.118,3179 Destination:192.168.0.253,2745 - [DOS]
Mon, 2004-05-03 18:19:45 - TCP Packet - Source:217.43.19.206,2624 Destination:192.168.0.253,135 - [DOS]
Mon, 2004-05-03 18:40:32 - TCP Packet - Source:217.43.251.221,2600 Destination:192.168.0.253,2745 - [DOS]
Mon, 2004-05-03 18:40:32 - TCP Packet - Source:217.43.251.221,2601 Destination:192.168.0.253,135 - [DOS]
Mon, 2004-05-03 18:40:32 - TCP Packet - Source:217.43.251.221,2602 Destination:192.168.0.253,1025 - [DOS]
Mon, 2004-05-03 18:40:32 - TCP Packet - Source:217.43.251.221,2603 Destination:192.168.0.253,445 - [DOS]
Mon, 2004-05-03 18:40:32 - TCP Packet - Source:217.43.251.221,2604 Destination:192.168.0.253,3127 - [DOS]
Mon, 2004-05-03 18:49:15 - TCP Packet - Source:211.20.80.53,64184 Destination:192.168.0.253,80 - [DOS]
Mon, 2004-05-03 18:49:15 - TCP Packet - Source:217.43.243.4,2902 Destination:192.168.0.253,135 - [DOS]
Mon, 2004-05-03 21:13:52 - TCP Packet - Source:217.43.86.181,3227 Destination:192.168.0.253,445 - [DOS]
Mon, 2004-05-03 21:29:11 - TCP Packet - Source:217.127.153.86,4024 Destination:192.168.0.253,139 - [DOS]
Mon, 2004-05-03 23:33:13 - TCP Packet - Source:217.43.195.105,3761 Destination:192.168.0.253,445 - [DOS]
Mon, 2004-05-03 23:33:14 - TCP Packet - Source:217.43.195.105,3759 Destination:192.168.0.253,135 - [DOS]
Tue, 2004-05-04 00:22:37 - TCP Packet - Source:217.43.59.123,4843 Destination:192.168.0.253,1025 - [DOS]
Tue, 2004-05-04 00:22:37 - TCP Packet - Source:217.43.59.123,4841 Destination:192.168.0.253,135 - [DOS]
Tue, 2004-05-04 00:22:37 - TCP Packet - Source:217.43.59.123,4849 Destination:192.168.0.253,445 - [DOS]
Tue, 2004-05-04 01:50:53 - TCP Packet - Source:217.43.203.246,2567 Destination:192.168.0.253,1025 - [DOS]
Tue, 2004-05-04 01:50:53 - TCP Packet - Source:217.43.203.246,2569 Destination:192.168.0.253,6129 - [DOS]
Tue, 2004-05-04 01:50:53 - TCP Packet - Source:217.43.203.246,2566 Destination:192.168.0.253,135 - [DOS]
Tue, 2004-05-04 01:50:53 - TCP Packet - Source:217.43.203.246,2568 Destination:192.168.0.253,445 - [DOS]
Tue, 2004-05-04 08:20:10 - TCP Packet - Source:217.43.197.137,3058 Destination:192.168.0.253,1025 - [DOS]
Tue, 2004-05-04 08:20:10 - TCP Packet - Source:217.43.197.137,3050 Destination:192.168.0.253,2745 - [DOS]
Tue, 2004-05-04 08:20:10 - TCP Packet - Source:217.43.197.137,3061 Destination:192.168.0.253,445 - [DOS]
Tue, 2004-05-04 08:20:10 - TCP Packet - Source:217.43.197.137,3064 Destination:192.168.0.253,6129 - [DOS]
Tue, 2004-05-04 08:20:10 - TCP Packet - Source:217.43.197.137,3066 Destination:192.168.0.253,80 - [DOS]
Tue, 2004-05-04 08:23:59 - TCP Packet - Source:217.43.171.7,4825 Destination:192.168.0.253,135 - [DOS]
Tue, 2004-05-04 08:23:59 - TCP Packet - Source:217.43.171.7,4826 Destination:192.168.0.253,1025 - [DOS]
Tue, 2004-05-04 08:23:59 - TCP Packet - Source:217.43.171.7,4830 Destination:192.168.0.253,445 - [DOS]
Tue, 2004-05-04 09:41:31 - TCP Packet - Source:217.43.176.252,4093 Destination:192.168.0.253,6129 - [DOS]
Tue, 2004-05-04 09:41:31 - TCP Packet - Source:217.43.176.252,4095 Destination:192.168.0.253,139 - [DOS]
Tue, 2004-05-04 09:41:31 - TCP Packet - Source:217.43.176.252,4091 Destination:192.168.0.253,445 - [DOS]
Tue, 2004-05-04 09:41:31 - TCP Packet - Source:217.43.176.252,4090 Destination:192.168.0.253,1025 - [DOS]
Tue, 2004-05-04 09:41:31 - TCP Packet - Source:217.43.176.252,4086 Destination:192.168.0.253,2745 - [DOS]
Tue, 2004-05-04 09:41:31 - TCP Packet - Source:217.43.176.252,4089 Destination:192.168.0.253,135 - [DOS]
Tue, 2004-05-04 09:41:31 - TCP Packet - Source:217.43.176.252,4092 Destination:192.168.0.253,3127 - [DOS]
Tue, 2004-05-04 09:41:34 - TCP Packet - Source:217.43.176.252,4093 Destination:192.168.0.253,6129 - [DOS]
Tue, 2004-05-04 09:41:37 - TCP Packet - Source:217.43.176.252,4089 Destination:192.168.0.253,135 - [DOS]
Tue, 2004-05-04 09:41:37 - TCP Packet - Source:217.43.176.252,4092 Destination:192.168.0.253,3127 - [DOS]
Tue, 2004-05-04 09:50:26 - TCP Packet - Source:217.43.139.239,3388 Destination:192.168.0.253,445 - [DOS]
Tue, 2004-05-04 09:50:26 - TCP Packet - Source:217.43.139.239,3390 Destination:192.168.0.253,445 - [DOS]
Tue, 2004-05-04 09:50:26 - TCP Packet - Source:217.43.139.239,3391 Destination:192.168.0.253,445 - [DOS]
Tue, 2004-05-04 09:50:26 - TCP Packet - Source:217.43.139.239,3392 Destination:192.168.0.253,3127 - [DOS]
Tue, 2004-05-04 09:50:26 - TCP Packet - Source:217.43.139.239,3393 Destination:192.168.0.253,6129 - [DOS]
Tue, 2004-05-04 09:50:26 - TCP Packet - Source:217.43.139.239,3397 Destination:192.168.0.253,139 - [DOS]
Tue, 2004-05-04 09:50:27 - TCP Packet - Source:217.43.139.239,3382 Destination:192.168.0.253,135 - [DOS]
Tue, 2004-05-04 09:50:27 - TCP Packet - Source:217.43.139.239,3381 Destination:192.168.0.253,2745 - [DOS]
Tue, 2004-05-04 09:50:27 - TCP Packet - Source:217.43.139.239,3386 Destination:192.168.0.253,1025 - [DOS]
Tue, 2004-05-04 09:50:27 - TCP Packet - Source:217.43.139.239,3384 Destination:192.168.0.253,1025 - [DOS]
Tue, 2004-05-04 09:50:27 - TCP Packet - Source:217.43.139.239,3383 Destination:192.168.0.253,135 - [DOS]
Tue, 2004-05-04 09:50:29 - TCP Packet - Source:217.43.139.239,3392 Destination:192.168.0.253,3127 - [DOS]
Tue, 2004-05-04 09:50:29 - TCP Packet - Source:217.43.139.239,3393 Destination:192.168.0.253,6129 - [DOS]
Tue, 2004-05-04 09:50:29 - TCP Packet - Source:217.43.139.239,3397 Destination:192.168.0.253,139 - [DOS]
Tue, 2004-05-04 09:50:30 - TCP Packet - Source:217.43.139.239,3391 Destination:192.168.0.253,445 - [DOS]
Tue, 2004-05-04 09:50:30 - TCP Packet - Source:217.43.139.239,3390 Destination:192.168.0.253,445 - [DOS]
Tue, 2004-05-04 09:50:30 - TCP Packet - Source:217.43.139.239,3388 Destination:192.168.0.253,445 - [DOS]
Tue, 2004-05-04 09:50:33 - TCP Packet - Source:217.43.139.239,3384 Destination:192.168.0.253,1025 - [DOS]
Tue, 2004-05-04 09:50:33 - TCP Packet - Source:217.43.139.239,3386 Destination:192.168.0.253,1025 - [DOS]
Tue, 2004-05-04 10:09:54 - TCP Packet - Source:217.43.56.123,4154 Destination:192.168.0.253,135 - [DOS]
Tue, 2004-05-04 10:09:54 - TCP Packet - Source:217.43.56.123,4155 Destination:192.168.0.253,1025 - [DOS]
Tue, 2004-05-04 10:59:32 - TCP Packet - Source:4.26.165.131,1141 Destination:192.168.0.253,445 - [DOS]
Tue, 2004-05-04 11:05:44 - TCP Packet - Source:217.43.214.164,4776 Destination:192.168.0.253,1025 - [DOS]
Tue, 2004-05-04 11:05:44 - TCP Packet - Source:217.43.214.164,4777 Destination:192.168.0.253,445 - [DOS]
Tue, 2004-05-04 11:37:52 - TCP Packet - Source:217.132.9.12,2966 Destination:192.168.0.253,6129 - [DOS]
Tue, 2004-05-04 11:37:52 - TCP Packet - Source:217.132.9.12,2967 Destination:192.168.0.253,139 - [DOS]
Tue, 2004-05-04 11:37:55 - TCP Packet - Source:217.132.9.12,2964 Destination:192.168.0.253,445 - [DOS]
Tue, 2004-05-04 11:37:55 - TCP Packet - Source:217.132.9.12,2965 Destination:192.168.0.253,3127 - [DOS]
Tue, 2004-05-04 11:37:55 - TCP Packet - Source:217.132.9.12,2966 Destination:192.168.0.253,6129 - [DOS]
Tue, 2004-05-04 11:37:55 - TCP Packet - Source:217.132.9.12,2967 Destination:192.168.0.253,139 - [DOS]
Tue, 2004-05-04 11:37:58 - TCP Packet - Source:217.132.9.12,2961 Destination:192.168.0.253,2745 - [DOS]
Tue, 2004-05-04 11:37:59 - TCP Packet - Source:217.43.84.184,1713 Destination:192.168.0.253,135 - [DOS]
Tue, 2004-05-04 11:38:01 - TCP Packet - Source:217.132.9.12,2965 Destination:192.168.0.253,3127 - [DOS]
Tue, 2004-05-04 11:38:01 - TCP Packet - Source:217.132.9.12,2964 Destination:192.168.0.253,445 - [DOS]
Tue, 2004-05-04 12:27:00 - Administrator login successful - IP:192.168.0.2
Tue, 2004-05-04 12:34:54 - Administrator login successful - IP:192.168.0.2
Tue, 2004-05-04 13:34:40 - TCP Packet - Source:217.44.28.70,3636 Destination:192.168.0.253,135 - [DOS]
Tue, 2004-05-04 15:42:25 - TCP Packet - Source:217.43.78.185,1763 Destination:192.168.0.253,6129 - [DOS]
Tue, 2004-05-04 15:42:26 - TCP Packet - Source:217.43.78.185,1759 Destination:192.168.0.253,3127 - [DOS]
Tue, 2004-05-04 15:42:26 - TCP Packet - Source:217.43.78.185,1758 Destination:192.168.0.253,445 - [DOS]
Tue, 2004-05-04 15:42:26 - TCP Packet - Source:217.43.78.185,1757 Destination:192.168.0.253,1025 - [DOS]
Tue, 2004-05-04 15:42:26 - TCP Packet - Source:217.43.78.185,1750 Destination:192.168.0.253,2745 - [DOS]
Tue, 2004-05-04 15:42:26 - TCP Packet - Source:217.43.78.185,1753 Destination:192.168.0.253,135 - [DOS]
Tue, 2004-05-04 16:00:04 - TCP Packet - Source:217.43.170.9,3077 Destination:192.168.0.253,139 - [DOS]
Tue, 2004-05-04 16:00:05 - TCP Packet - Source:217.43.170.9,3071 Destination:192.168.0.253,135 - [DOS]
Tue, 2004-05-04 16:00:05 - TCP Packet - Source:217.43.170.9,3069 Destination:192.168.0.253,2745 - [DOS]
Tue, 2004-05-04 16:00:05 - TCP Packet - Source:217.43.170.9,3075 Destination:192.168.0.253,3127 - [DOS]
Tue, 2004-05-04 16:00:05 - TCP Packet - Source:217.43.170.9,3073 Destination:192.168.0.253,445 - [DOS]
Tue, 2004-05-04 16:01:49 - TCP Packet - Source:217.43.170.227,3945 Destination:192.168.0.253,1025 - [DOS]
Tue, 2004-05-04 16:01:49 - TCP Packet - Source:217.43.170.227,3944 Destination:192.168.0.253,135 - [DOS]
Tue, 2004-05-04 16:01:49 - TCP Packet - Source:217.43.170.227,3943 Destination:192.168.0.253,2745 - [DOS]
Tue, 2004-05-04 16:26:07 - TCP Packet - Source:217.43.198.227,2667 Destination:192.168.0.253,6129 - [DOS]
Tue, 2004-05-04 16:26:08 - TCP Packet - Source:217.43.198.227,2676 Destination:192.168.0.253,139 - [DOS]
Tue, 2004-05-04 16:26:08 - TCP Packet - Source:217.43.28.108,3346 Destination:192.168.0.253,445 - [DOS]
Tue, 2004-05-04 16:26:10 - TCP Packet - Source:217.43.198.227,2660 Destination:192.168.0.253,445 - [DOS]
Tue, 2004-05-04 16:26:10 - TCP Packet - Source:217.43.198.227,2666 Destination:192.168.0.253,3127 - [DOS]
Tue, 2004-05-04 16:26:10 - TCP Packet - Source:217.43.198.227,2657 Destination:192.168.0.253,135 - [DOS]
Tue, 2004-05-04 16:26:10 - TCP Packet - Source:217.43.198.227,2678 Destination:192.168.0.253,80 - [DOS]
Tue, 2004-05-04 16:29:35 - TCP Packet - Source:217.42.249.143,3237 Destination:192.168.0.253,135 - [DOS]
Tue, 2004-05-04 16:59:38 - TCP Packet - Source:217.43.78.185,4693 Destination:192.168.0.253,6129 - [DOS]
Tue, 2004-05-04 16:59:38 - TCP Packet - Source:217.43.78.185,4699 Destination:192.168.0.253,139 - [DOS]
Tue, 2004-05-04 16:59:38 - TCP Packet - Source:217.43.78.185,4701 Destination:192.168.0.253,80 - [DOS]
Tue, 2004-05-04 16:59:38 - TCP Packet - Source:217.43.78.185,4688 Destination:192.168.0.253,3127 - [DOS]
Tue, 2004-05-04 16:59:38 - TCP Packet - Source:217.43.78.185,4686 Destination:192.168.0.253,445 - [DOS]
Tue, 2004-05-04 16:59:38 - TCP Packet - Source:217.43.78.185,4684 Destination:192.168.0.253,1025 - [DOS]
Tue, 2004-05-04 16:59:38 - TCP Packet - Source:217.43.78.185,4676 Destination:192.168.0.253,2745 - [DOS]
Tue, 2004-05-04 16:59:38 - TCP Packet - Source:217.43.78.185,4681 Destination:192.168.0.253,135 - [DOS]
Tue, 2004-05-04 16:59:41 - TCP Packet - Source:217.43.78.185,4699 Destination:192.168.0.253,139 - [DOS]
Tue, 2004-05-04 16:59:41 - TCP Packet - Source:217.43.78.185,4693 Destination:192.168.0.253,6129 - [DOS]
Tue, 2004-05-04 16:59:41 - TCP Packet - Source:217.43.78.185,4701 Destination:192.168.0.253,80 - [DOS]
Tue, 2004-05-04 16:59:44 - TCP Packet - Source:217.43.78.185,4676 Destination:192.168.0.253,2745 - [DOS]
Tue, 2004-05-04 16:59:44 - TCP Packet - Source:217.43.78.185,4681 Destination:192.168.0.253,135 - [DOS]
Tue, 2004-05-04 19:55:22 - Administrator login successful - IP:192.168.0.2 
__________________
Rolf
If you enjoy our site, you can help support it by wearing our unique branded merchandise, you can do this by clicking on my baseball cap, making a direct donation with Paypal by clicking on the Donation button below, or using our site supporting advertisers, to do this, click on the central image below



Donate
rolfw is online now   Reply With Quote
Old 05-05-2004   #6
GotMyBusPass
Guest
 
Posts: n/a
Thumbs down

Bl**dy H**l rolfw, just checked my firewall logs! The hits per minute are frightening and from the USA and Australia of all places. G*d knows what it must be like to have a commercial site, the firewalls must be going bonkers!
GMBP
PS must change my sig now that this years raffle is over
Cheers GMBP
  Reply With Quote
Old 05-05-2004   #7
Believe it when I see it Admin.
 
rolfw's Avatar
 
Join Date: 01-05-1999
Location: Southern England
Posts: 27729
Thanks: 34
Thanked 732 Times in 507 Posts
Blog Entries: 3

My System: Sky+, DB 7000s, Gemini 4.3 in flash, Var on USB stick. Transparent 80cm Dish, Moteck SG2100 DiseqC motor, lots of legacy gear. Meters: Satlook Digital NIT, Unaohm EP313, Swires Annie 204 Spectrum, Rover ST-4 Spectrum.

All of the hits there are heading for my IP Camera, it's the only thing in the DMZ, so the router sends everything towards it.
__________________
Rolf
If you enjoy our site, you can help support it by wearing our unique branded merchandise, you can do this by clicking on my baseball cap, making a direct donation with Paypal by clicking on the Donation button below, or using our site supporting advertisers, to do this, click on the central image below



Donate
rolfw is online now   Reply With Quote
Old 05-05-2004   #8
Long Term Contributor
 
s*t*a*r*m*a*n's Avatar
 
Join Date: 01-05-1999
Location: scotland
Posts: 504
Thanks: 0
Thanked 0 Times in 0 Posts



Software Affected

Windows XP, Windows XP Service Pack 1 (SP1)
Windows 2000 SP2, Windows 2000 SP3, Windows 2000 SP4


Software Not Affected

Windows XP 64-Bit Edition Version 2003
Windows Server™ 2003
Windows XP 64-Bit Edition SP1
Windows Millennium Edition
Windows 98 Second Edition
Windows 98
Windows NT® 4.0 SP6a



more info here
http://www.microsoft.com/security/incident/sasser.asp

Last edited by s*t*a*r*m*a*n; 05-05-2004 at 04:16 AM
s*t*a*r*m*a*n is offline   Reply With Quote
Old 05-05-2004   #9
Regular Member
 
ngj26's Avatar
 
Join Date: 12-03-2004
Location: Doncaster
Posts: 26
Thanks: 0
Thanked 0 Times in 0 Posts
Thumbs up Windows 98

if you have windows 98 you do not get affected by the Sasser worm i have checked up its only windows xp and windows 2000 so if you have windows 98 dont panic
ngj26 is offline   Reply With Quote
Old 05-05-2004   #10
Mod and septic resident
 
Channel Hopper's Avatar
 
Join Date: 01-01-2000
Location: London SW
Posts: 7399
Thanks: 1
Thanked 43 Times in 41 Posts

Originally Posted by ngj26
if you have windows 98 you do not get affected by the Sasser worm i have checked up its only windows xp and windows 2000 so if you have windows 98 dont panic
Not entirely true, the Win98 PC can operate as a host and programme routines that run through it may slow down the processing speed.
Best to get it checked out anyway using one of the isolation and removal tools.
__________________
There is a very fine line between "hobby" and "mental illness"
Channel Hopper is offline   Reply With Quote
Old 05-05-2004   #11
Regular Member
 
ngj26's Avatar
 
Join Date: 12-03-2004
Location: Doncaster
Posts: 26
Thanks: 0
Thanked 0 Times in 0 Posts
Windows 98

No i have looked into it and contacted them also it is on the site if you read about it so yes it is true
ngj26 is offline   Reply With Quote
Old 05-05-2004   #12
Mod and septic resident
 
Channel Hopper's Avatar
 
Join Date: 01-01-2000
Location: London SW
Posts: 7399
Thanks: 1
Thanked 43 Times in 41 Posts

From www.symantec.com

W32.Sasser.Worm can run on (but not infect) Windows 95/98/Me computers. Although these operating systems cannot be infected, they can still be used to infect vulnerable systems that they are able to connect to. In this case, the worm will waste a lot of resources so that programs cannot run properly, including our removal tool. (On Windows 95/98/Me computers, the tool should be run in Safe mode.)

There are also the new variants , Sasser B, C, and D just being released.
__________________
There is a very fine line between "hobby" and "mental illness"
Channel Hopper is offline   Reply With Quote
Reply

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
More Sasser worm suspects net1 Computer Discussion 0 14-05-2004 06:58 PM
Sasser, Sasser and more Sasser net1 Computer Discussion 3 09-05-2004 06:39 PM
Sasser worm strikes PC's worldwide Sab Computer Discussion 2 06-05-2004 12:32 PM
Trojan serves porn off home PCs, net1 Computer Discussion 1 14-07-2003 11:44 PM
Worm could be clearing path for DDoS attack net1 Computer Discussion 0 10-03-2003 09:18 PM






All times are GMT +1. The time now is 06:58 PM.


All views and information expressed in users' communications and profiles represent the opinions of the users concerned and do not represent the views of Satellites.co.uk. All images and news content are believed to be in the public domain, except where otherwise stated. Forum software by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.


Content Relevant URLs by vBSEO 3.2.0