MS04-011: Bobax (Sasser-like Internet worm)
http://www.f-secure.com/v-descs/bobax.shtml
Bobax is a new, Sasser-like worm that uses the MS04-011 (LSASS.EXE) vulnerability to propagate. The worm scans random IP addresses for vulnerable computers. When Bobax infects a host, the exploit uses HTTP to download the worm from a webserver which listens on a random port on the attacker host. The data is downloaded into a dropper file called 'svc.exe'. The dropper drops the actual worm body, which is a DLL, to the temporary directory with a random name. The worm is launched by injecting it to Explorer with a technique called DLL Injection. Because the worm runs as a thread in Explorer it's not visible as a separate process.
http://www.f-secure.com/v-descs/bobax.shtml
Bobax is a new, Sasser-like worm that uses the MS04-011 (LSASS.EXE) vulnerability to propagate. The worm scans random IP addresses for vulnerable computers. When Bobax infects a host, the exploit uses HTTP to download the worm from a webserver which listens on a random port on the attacker host. The data is downloaded into a dropper file called 'svc.exe'. The dropper drops the actual worm body, which is a DLL, to the temporary directory with a random name. The worm is launched by injecting it to Explorer with a technique called DLL Injection. Because the worm runs as a thread in Explorer it's not visible as a separate process.

Help
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.



Back to top








