Solved

sasser worm question

Posted on 2004-09-10
6
395 Views
Last Modified: 2010-04-11
I have the sasser worm on my network (b/c my users do not update their computers when instructed to)... i have about 600 PCs in one flat subnet,,, what is the easiest way to track down the PCs that have sasser?  Could i use ethereal?  and if so what specifically do i need to look for to recognize computers with the sasser worm?
0
Comment
Question by:mikeleebrla
  • 3
  • 2
6 Comments
 
LVL 57

Accepted Solution

by:
Pete Long earned 500 total points
ID: 12030555
Hi mikeleebrla,
http://www.shavlik.com/

Cheers!
0
 
LVL 57

Expert Comment

by:Pete Long
ID: 12030569
Retina Sasser Worm Scanner from eEye Digital Security

Current Version: 1.0
Release Date: May 1, 2004

The Retina Sasser Worm Scanner is being made available free of charge by eEye. The tool will scan up to 256 IP addresses at once to determine if any are vulnerable to the Sasser worm which is currently propagating. If an IP address is found to be vulnerable, the Retina Sasser Worm Scanner will flag that IP address.

This tool does not require administrative privileges on the scanned machines in order to determine if the systems are vulnerable.

To determine if your network has any devices vulnerable to this worm, download the FREE Retina Sasser Worm Scanner here:
http://www.eeye.com/html/Research/Tools/Download.asp?file=RetinaSasser

For pricing on Class B and Class A versions of the scanning utility please contact eEye Sales.

Read a detailed analysis of the Sasser worm here:
http://www.eeye.com/html/Research/Advisories/AD20040501.html

The vulnerability audit in the Retina Sasser Worm Scanner is one of thousands that the full-featured Retina® Network Security Scanner, PC Magazine's Editor's Choice Award winner, checks for during a network scan. To download the trial version of Retina that checks for Sasser and other critical vulnerabilities, click here:
http://www.eeye.com/html/Products/Retina/Download.html
0
 
LVL 15

Expert Comment

by:Yan_west
ID: 12030700
Check this out:

http://www.eeye.com/html/Research/Tools/Sasser.html

To determine if your network has any devices vulnerable to this worm, download the FREE Retina Sasser Worm Scanner here:
http://www.eeye.com/html/Research/Tools/Download.asp?file=RetinaSasser
0
Maximize Your Threat Intelligence Reporting

Reporting is one of the most important and least talked about aspects of a world-class threat intelligence program. Here’s how to do it right.

 
LVL 15

Expert Comment

by:Yan_west
ID: 12030701
Oups, Sorry Pete :)
0
 
LVL 57

Expert Comment

by:Pete Long
ID: 12030732
np Yan :)
0
 
LVL 32

Expert Comment

by:Luc Franken
ID: 12031390
Ok... the mess is allready been created :o)

mikeleebrla, please, next time, don't cross-post your question, it causes confusion. Please get one of these closed, and ask the experts in the other question to move their comments to the one you'd like to keep.

LucF

0

Featured Post

IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

Phishing is at the top of most security top 10 efforts you should be pursuing in 2016 and beyond. If you don't have phishing incorporated into your Security Awareness Program yet, now is the time. Phishers, and the scams they use, are only going to …
Meet the world's only “Transparent Cloud™” from Superb Internet Corporation. Now, you can experience firsthand a cloud platform that consistently outperforms Amazon Web Services (AWS), IBM’s Softlayer, and Microsoft’s Azure when it comes to CPU and …
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

746 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now