Common Tasks

Recent Posts

Community

Email Notifications

Personal Links

Archives

Security Protection - Harry Waldron (CS)

Security Best Practices, Breaking News, & Updates

Big Yellow worm - Exploits SAV update vulnerability if unpatched

A second round of the SAV worm is circulated on unpatched Symantec PCs (vulnerable to the buffer overflow exploit)

Big Yellow worm -  Exploits SAV update vulnerability if unpatched
http://www.incidents.org/diary.php?storyid=1945
http://research.eeye.com/html/alerts/AL20061215.html

QUOTE: This file was being downloaded by a large number of machines that were recently exploited using the SAV remote exploit. The sequence of events for these compromises were:

1. Exploit comes in from an IP address
2. Stops the Windows firewall service,
3. Creates an ftp command script named "x" which is later run by ftp.exe -s:x
4. which downloads NL.eXe
5. May include keylogger

SOLUTION: Users need to apply the SYM06-010 patch

Symantec Client Security and Symantec AntiVirus Elevation of Privilege
http://www.symantec.com/avcenter/security/Content/2006.05.25.html