Craftix Technical Solutions
Web Design, Networks, Data and Voice Cabling, Systems, IS/IT Consulting and more.
Affordable solutions to your IT problems.
 [Home]  [About Craftix]  [Web Services]  [Networking Services]  [Cabling Services]  [Other Services]  [Frequently Asked Questions]  [Contact Us] Search

 


Sasser Information


The Short and Skinny of It:
The Sasser Worm takes advantage of a known LSASS vulnerability in Windows 2000/XP/NT systems described in Microsoft Security Bulletin MS04-011.

Once a system is infected with the worm, Sasser will create a mutex, add a registry key, and open an FTP server on port 5554 to attempt to spread itself by connecting to randomly generated IP addresses on TCP port 445. If a connection is made it will then send shell code to open a remote shell on port 9996. The shell is then used to reconnect to the FTP server on port 5554 to retreive the worm. There are a number of variants of the worm and each has minor deviations from this description.

More Detailed Information:

Microsoft Security Bulletin MS04-011 Fixes by Operating System to prevent the LSASS exploit:

Free Removal Tool:
FxSasser Removal Tool from Symatec

Preventing Infections of this Nature in the Future:
Sometimes the tried and tested solutions are among the best to implement. In this case, and in many others, the impact of viruses/trojans/worms can be reduced or even eliminated by the installation of antivirus software on all systems in your network and by the use of either a hardware firewall (the preferred choice) and use of NAT (Network Address Translation) for your entire network, or firewall software on each station.

Need Help?:
If the above information is too overwhelming or confusing or you need help either dealing with the present threat or strengthening your network defenses for the future, please contact us here at Craftix and we'll be glad to assist.


 



| Home | About Craftix | Employment | Company News | Website Design | Web Hosting | Web Design Portfolio |
| Network Engineering Services | Networking Capabilities | Data/Voice Cabling Services | Cabling Service Request Form |
| PC Services | Data Recovery Services | Logo Design Services | FAQ's | Contact Us |

    Website Design and Hosting by Craftix Technical Solutions
    www.craftix.com
    Email: info@craftix.com
    © 2004 Craftix Technical Solutions