Iraq Oil Worm Targeting TCP Port 445
Posted on 18.12.2002
Bookmark and Share
On December 14, 2002 at 11:00 UTC the myNetWatchman system identified a worm-like surge in port scanning activity targeting TCP port 445. This port is associated with Microsoft's networking protocol (Server Message Block - SMB) when used with Windows 2000 and XP systems.

The worm propagates by generating a psuedo-random IP address and exploiting hosts which have the following weak security configuration:
  • Anonymous Null Sessions fully enabled
  • Weak (or null) passwords on privileged user accounts
Detailed analysis of the worm can be read from myNetWatchman.



OBrien, Brennan posted the following to the Incidents mailing list:
Apparently this has been identified as WORM_LIOTEN.A through TREND, W32.HLLW.Lioten via Symantec and W32/Lioten.worm via McAfee.



Internet Storm Center reports an increase in port 445 scans, which can be seen from their report located at:
http://isc.incidents.org/port_details.html?port=445



Steve Friedl: "Iraq Oil" worm reverse engineering & analysis
http://www.unixwiz.net/iraqworm/






Spotlight

Experts highlight top data breach vulnerabilities

Posted on 22 May 2013.  |  Hidden vulnerabilities lie in everyday activities that can expose personal information and lead to data breach, including buying gas with a credit card or wearing a pacemaker.


Daily digest

By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
  

Weekly newsletter

With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.
  

 
DON'T
MISS

Wed, May 22nd
    COPYRIGHT 1998-2013 BY HELP NET SECURITY.   // READ OUR PRIVACY POLICY // ABOUT US // ADVERTISE //