[Full-Disclosure] New variant of Nachi ?

Helmut Springer delta at faveve.uni-stuttgart.de
Wed Oct 29 07:58:53 GMT 2003


Hi,


On 29 Oct 2003 at 12:54 +0100, KF wrote:
> https://gtoc.iss.net/issEn/delivery/gtoc/index.jsp
> 
> hreat Forecast
> 
> Our analysts are aware of a worm actively exploiting flaws
> addressed under Microsoft Security Bulletin MS03-026 and MS03-039.
> This worm activity is consistent with a variation of the Nachi or
> LovSan worms.  Once a host is infected, it will attempt to
> propagate outbound via port 445.

Has anyone seen any evidence besides this and the two postings on
public lists?  No real trace after more than 24h it seems...


-- 
MfG/Best Regards,                  "If we keep our pride...
helmut springer                     Though paradise is lost
                                    We will pay the price,
                                    But we will not count the cost."




Full-Disclosure is hosted and sponsored by Secunia.