Blaster Worm - Details & Technical Analysis
Date:
8/11/2003 12:00:00 AM
Severity:
High
Affected Software:
Microsoft Windows NT Workstation 4.0
Microsoft Windows NT Server 4.0
Microsoft Windows NT Server 4.0, Terminal Server Edition
Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Server 2003
Overview:
The worm begins by targeting Microsoft systems that have not been properly patched for the known RPC DCOM vulnerability. Once the worm detects an unpatched system, it will attempt to download and run a file called msblast.exe. If successful in infecting a system, the worm will propagate itself, modify Windows registry settings, and initiate a SYN flood denial-of-service attack on windowsupdate.com.
The worm payload does not contain any additional malicious content; however, because of the nature of the worm and the speed at which it attempts to impact systems, it can potentially create a denial-of-service attack against windowsupdate.com.
For further information and a technical description of the Blaster worm please visit:
http://www.eeye.com/html/Research/Advisories/AL20030811.html
Technical Analysis:
Detection:
eEye is offering a free tool that scans network machines and detects if any are vulnerable to the Blaster worm. The Retina RPC DCOM Scanner is based off of eEye's vulnerability assessment solution, Retina® Network Security Scanner. Users of Retina do not need the tool since Retina already checks for the RPC DCOM vulnerability and presence of the Blaster worm. The free Retina RPC DCOM Scanner can be found by visiting:
http://www.eeye.com/html/Research/Tools/RPCDCOM.html
Prevention:
The full version of Retina Network Security scanner can not only identify vulnerable machines, it can also detect whether the worm has already infected systems on a network. In addition to the security weakness being exploited by the Blaster worm, Retina detects over one thousand vulnerabilities to provide ongoing, comprehensive security audits for any network.
Retina Network Security Scanner
Links:
Copyright ©1998-2010 eEye Digital Security
Permission is hereby granted for the redistribution of this alert electronically. It is not to be edited in any way without express consent of eEye. If you wish to reprint the whole or any part of this alert in any other medium excluding electronic medium, please email alert@eEye.com for permission.
Disclaimer
The information within this paper may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are no warranties, implied or express, with regard to this information. In no event shall the author be liable for any direct or indirect damages whatsoever arising out of or in connection with the use or spread of this information. Any use of this information is at the user's own risk.