Got to love the constant reboot.

|

This in from the SANS ISC


McAfee released information as well: W32/IRCbot.worm

This is an IRC bot worm, and will scan for TCP port 445, and for file shares. McAfee reports in it's bulletin that systems not patched for MS05-039 will continually reboot. (emphesis added)

Actually they may do us a favor. If a tree falls in the woods and no one hears it does anyone care? To put it another way, if a system gets infected with zotob and no one knows it does anyone care? You can probably ignore zotob, just as people are ignorant of their botnet infections. You cannot however ignore your computer constantly rebooting. You'll scream to high heaven about that. That will result it you being able to clean, and having more leverage in patching (though it is already too late for that).

Categories

About this Entry

This page contains a single entry by Roger published on August 16, 2005 11:52 PM.

An update regarding zotob and null sessions was the previous entry in this blog.

Microsoft Security Response Center on ms05-039 attacks is the next entry in this blog.

Find recent content on the main index or look in the archives to find all content.

Add to Google
Please contact me by leaving a comment where appropriate. Otherwise, you can click here to reveal an email address for me.
Got Backups? Get Safe Online Remember Rick Rescorla Powered by Movable Type 4.2-en