Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

WORM:DABBER:TFTP-TRANSFER

Severity

High

Recommended

No

Recommended Action

Drop

Category

WORM

Release Date

2004/05/19

Update Number

1213

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

WORM: Dabber TFTP File Transfer


This signature detects attempts by the Dabber worm to transfer itself to a target computer using TFTP. The Dabber worm infects targets already infected by the Sasser worm; this signature detects Dabber's fourth stage infection process. If this signature is detected in your network traffic, the target computer is infected with the Dabber worm and the attacking (requesting) computer is most likely infected with both the Sasser and Dabber worms.

Extended Description

WORM_DABBER.A is a worm that exploits a vulnerability in the FTP server component of Sasser worm. It opens a backdoor, modifies the Windows registry, and installs a TFTP server on a target system.

References

  • URL: http://www.lurhq.com/dabber.html

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out