Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

This site is deprecated. Please CLICK HERE for latest updates

Short Name

WORM:SASSER:A-D-F-SHELL-CMD

Severity

Major

Recommended

No

Recommended Action

Drop

Category

WORM

Keywords

Sasser A/B/C/D/F Backdoor Command (9995/6)

Release Date

2004/05/01

Update Number

1213

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+

WORM: Sasser A/B/C/D/F Backdoor Command (9995/6)


This signature detects successful connection attempts to a Sasser.A, B, C, D, or F backdoor shell running on port 9996. Sasser uses the connection to download the Sasser worm from the attacker to the newly exploited target. If this signature is detected, the destination machine (the target) was successfully exploited with the LSASS vulnerability, but it is not yet infected by the worm. To prevent the worm from installing on the target, configure a rule to drop all traffic that matches this Attack Object.

Extended Description

Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via a packet that causes the DsRolerUpgradeDownlevelServer function to create long debug entries for the DCPROMO.LOG log file, as exploited by the Sasser worm.

Affected Products

  • Microsoft netmeeting
  • Microsoft windows_2000 (sp2)
  • Microsoft windows_2000 (sp4:)
  • Microsoft windows_2000 (sp4)
  • Microsoft windows_2000 (sp4::fr)
  • Microsoft windows_2003_server r2
  • Microsoft windows_98 (gold)
  • Microsoft windows_me
  • Microsoft windows_nt 4.0 (sp6a)
  • Microsoft windows_xp (sp1)
  • Microsoft windows_xp (sp1:tablet_pc)

References

  • BugTraq: 10108
  • CVE: CVE-2003-0533
  • URL: http://secunia.com/virus_information/9142/sasser/
  • URL: http://www.lurhq.com/sasser.html
  • URL: http://www.kb.cert.org/vuls/id/753212

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out