Solved

sasser worm question

Posted on 2004-09-10
6
408 Views
Last Modified: 2010-04-11
I have the sasser worm on my network (b/c my users do not update their computers when instructed to)... i have about 600 PCs in one flat subnet,,, what is the easiest way to track down the PCs that have sasser?  Could i use ethereal?  and if so what specifically do i need to look for to recognize computers with the sasser worm?
0
Comment
Question by:mikeleebrla
  • 3
  • 2
6 Comments
 
LVL 57

Accepted Solution

by:
Pete Long earned 500 total points
ID: 12030555
Hi mikeleebrla,
http://www.shavlik.com/

Cheers!
0
 
LVL 57

Expert Comment

by:Pete Long
ID: 12030569
Retina Sasser Worm Scanner from eEye Digital Security

Current Version: 1.0
Release Date: May 1, 2004

The Retina Sasser Worm Scanner is being made available free of charge by eEye. The tool will scan up to 256 IP addresses at once to determine if any are vulnerable to the Sasser worm which is currently propagating. If an IP address is found to be vulnerable, the Retina Sasser Worm Scanner will flag that IP address.

This tool does not require administrative privileges on the scanned machines in order to determine if the systems are vulnerable.

To determine if your network has any devices vulnerable to this worm, download the FREE Retina Sasser Worm Scanner here:
http://www.eeye.com/html/Research/Tools/Download.asp?file=RetinaSasser

For pricing on Class B and Class A versions of the scanning utility please contact eEye Sales.

Read a detailed analysis of the Sasser worm here:
http://www.eeye.com/html/Research/Advisories/AD20040501.html

The vulnerability audit in the Retina Sasser Worm Scanner is one of thousands that the full-featured Retina® Network Security Scanner, PC Magazine's Editor's Choice Award winner, checks for during a network scan. To download the trial version of Retina that checks for Sasser and other critical vulnerabilities, click here:
http://www.eeye.com/html/Products/Retina/Download.html
0
 
LVL 15

Expert Comment

by:Yan_west
ID: 12030700
Check this out:

http://www.eeye.com/html/Research/Tools/Sasser.html

To determine if your network has any devices vulnerable to this worm, download the FREE Retina Sasser Worm Scanner here:
http://www.eeye.com/html/Research/Tools/Download.asp?file=RetinaSasser
0
Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

 
LVL 15

Expert Comment

by:Yan_west
ID: 12030701
Oups, Sorry Pete :)
0
 
LVL 57

Expert Comment

by:Pete Long
ID: 12030732
np Yan :)
0
 
LVL 32

Expert Comment

by:LucF
ID: 12031390
Ok... the mess is allready been created :o)

mikeleebrla, please, next time, don't cross-post your question, it causes confusion. Please get one of these closed, and ask the experts in the other question to move their comments to the one you'd like to keep.

LucF

0

Featured Post

VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
How to configure this in fortinet firewall 2 61
Cisco switch suggestion 5 63
exclude a user from a deny permisssion 4 53
Windows PE .WIM files WDS issue 4 27
PRTG Network Monitor lets you monitor your bandwidth usage, so you know who is using up your bandwidth, and what they're using it for.
Examines three attack vectors, specifically, the different types of malware used in malicious attacks, web application attacks, and finally, network based attacks.  Concludes by examining the means of securing and protecting critical systems and inf…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

791 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question