Yorn
Sep 28 2004, 04:53 AM
Mon, Sept 27th - Reports have come in about a
JPEG virus released to USENET earlier today. In actuality, this appears to be primarily a trojan and not a worm, however it is unclear on what kinds of spreading capabilities (if any) might be added at a future date. The infected computers so far are being controlled by one individual.
A worm may be 24 hours or less away.
Slashdot Coverage:
http://it.slashdot.org/article.pl?sid=04/0...tid=172&tid=218Be sure to update the GDI dll on all computers. For help consult the following link:
http://isc.sans.org/gdiscan.phpThe above link is to a tool which will check for any programs that might be using an exploitable version of the GDI driver. Suggestion is to update as needed.
For more information about this exploit here on the GSO forums:
Trial Member Forums:
http://www.governmentsecurity.org/forum/in...showtopic=11524http://www.governmentsecurity.org/forum/in...showtopic=11511http://www.governmentsecurity.org/forum/in...showtopic=11212Exploit R&D Forums:
http://www.governmentsecurity.org/forum/in...showtopic=11473http://www.governmentsecurity.org/forum/in...showtopic=11406File Downloads Forums:
http://www.governmentsecurity.org/forum/in...showtopic=11495The last one (above) includes M4Z3Rs code, cross-posted
WITHOUT PERMISSION FROM M4Z3R shortly after to
K-OTik.
KuerbY
Sep 28 2004, 09:46 AM
"Virus" this is big crap
it downloads vnc,radmin,servu,servu ircu plugin,fport,nc and many more
what a crappy shit
ill hope they get him *filtered filtered*
that makes me so sad...
jpno5
Sep 28 2004, 11:58 AM
Guys its not a fuckin virus of any kind its just a bind shell an no it didnt have (filtered) ALL to do with me, one of my ex team members was testin it out , looks like it was on a honeypot lol. anyway can uz stop joing the irc server im sick of bannin ur asses
andydis
Sep 28 2004, 04:24 PM
wonder if m4z3r's abit chessed off about this?
he'll have the FBI round his soon :-)
LOL
| QUOTE |
| anyway can uz stop joing the irc server im sick of bannin ur asses |
did i miss something?żżż
KuerbY
Sep 28 2004, 04:52 PM
jpno5 gone crazy
we cant help him
wanksta
Sep 28 2004, 07:22 PM
Don't trust Microsoft's detection tool (published by The SANS). It faults. I've read that it doesn't really work. Finally the Bug still exists

Be warned don't trust only MS's detection tool! Do all steps to patch your machines.
wanksta
M4Z3R
Sep 29 2004, 02:00 PM
I'm a bit disapointed that people just post other plp's sploit on very "public" web sites, without their permission. Anyways, I guess next version will be private
Yorn
Sep 29 2004, 05:56 PM
Might be a good idea to keep it private, yeah. And that's funny that it was someone you know who posted it, jpno5. It was posted on /. earlier. So they'll keep coming in for a while.
isaiah
Sep 30 2004, 03:23 AM
you know the gso logo is a jpeg virus hehe you all infected into G-Secure and Cos BotNet / Warez Server
hehe jk
who cares if yoru smart patch up your machine.
h3llraz0r
Sep 30 2004, 09:14 PM
found this today from the sans Internet storm center
New virus behavior
Our fellow handler Patrick Nolan sent this news about the Surila.k virus. According to the VirusList.com website "In order to gain full access to the Internet, Surila registers itself in the Windows FirewallPolicy, thereby becoming a legal program with full Internet rights."
This will bypass any Firewall settings that may otherwise block the virus from contacting the IRC server is connects to for remote control. The virus installs an HTTP and SMTP proxy server. Traffic to these proxies will be permitted by the modified firewall rules.
Yorn
Sep 30 2004, 11:49 PM
Well, what's sad is that SP2 isn't vulnerable, unless they found a universal offset (it's a heap overflow, so is that even possible?) so adding registry keys to get past a firewall is a bit excessive. Unless they found the offset.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please
click here.