Short Name |
WORM:DABBER:TFTP-TRANSFER |
---|---|
Severity |
High |
Recommended |
No |
Recommended Action |
Drop |
Category |
WORM |
Release Date |
2004/05/19 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts by the Dabber worm to transfer itself to a target computer using TFTP. The Dabber worm infects targets already infected by the Sasser worm; this signature detects Dabber's fourth stage infection process. If this signature is detected in your network traffic, the target computer is infected with the Dabber worm and the attacking (requesting) computer is most likely infected with both the Sasser and Dabber worms.
WORM_DABBER.A is a worm that exploits a vulnerability in the FTP server component of Sasser worm. It opens a backdoor, modifies the Windows registry, and installs a TFTP server on a target system.