IBM Computer, Laptops and Servers

Back Homepage Content Directory Resource Guide Blog

US-CERT Security Update : New Worm : W32/Korgo.F

US-CERT Security Update : New Worm : W32/Korgo.F

Added June 2

US-CERT has received reports of a new worm, referred to as "W32/Korgo.F" or "W32/Padobot". This worm attempts to take advantage of a buffer overflow vulnerability in the Windows Local Security Authority Service Server (LSASS). The vulnerability allows a remote attacker to execute arbitrary code with SYSTEM privileges. More information on this vulnerability is available in Vulnerability Note VU#753212 and Microsoft Security Bulletin MS04-011.
The worm propagates by scanning random IP addresses on port 445/tcp for vulnerable systems. Upon finding a vulnerable system, the worm will attempt to exploit this vulnerability. If successful, this worm will open a connection on port 113/tcp or port 3067/tcp and may attempt to connect to a list of pre-determined IRC servers.

US-CERT strongly encourages users to install and maintain anti-virus software as well as patch their systems to prevent exploitation of the listed vulnerabilities.

[ Comment, Edit or Article Submission ]

Share this:

Add To Yahoo MyWeb Add To Google Bookmarks Add To Furl Fav This With Technorati Add To Newsvine Add To Bloglines Add To Ask Add To Windows Live Add To Slashdot Stumble This Digg This Add To Del.icio.us Add To Reddit

More about:

Nov December 2008 Jan
Sun Mon Tue Wed Thu Fri Sat
  1 2 3 4 5 6
7 8 9 10 11 12 13
14 15 16 17 18 19 20
21 22 23 24 25 26 27
28 29 30 31      

IBM Computer, Laptops and Servers Blog on Technorati Related Blog of IBM Computer, Laptops and Servers on Sphere
Content Directory
Resource Guide


Kaspersky Lab Industry Leading Anti Virus Software

Website Links
IBM Computer, Laptops and Servers Copyright © 2008 www.ibmfans.com. All rights reserved. Site Map
Homepage | Blog | Advertise | Privacy Policy | Disclaimer | Contact Us | Links