PC Review


Reply
Thread Tools Rate Thread

W32.Welchia.Worm studying

 
 
kowts
Guest
Posts: n/a
 
      27th Oct 2003
Hi All,

Does anyone did a research or know how this malware made the HTTP request
with the WebDav of MicroSoft?

Anyone know a web site talking about that?

Additionally, it also uses a WebDAV exploit in order to propagate to
vulnerable systems. For detailed information about the said exploit, please
refer to the following Microsoft Web page:


Microsoft Bulletin MS03-007

Using these exploits, it sends a shell code to a vulnerable system, which in
turn will execute a remote shell on the target system. The remote shell
connects to a random selected port between port 666 to port 765 of the
infected host where it receives commands to download the worm copy via TFTP.

Thanks for your help

Kowts.


 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
welchia worm =?Utf-8?B?S2lyc3Rlbg==?= Windows XP Security 1 15th Dec 2003 06:45 PM
welchia worm Donnie Waymire Windows XP General 0 30th Aug 2003 05:27 PM
Re: W32.Welchia.Worm Icy Windows XP Basics 0 25th Aug 2003 09:34 PM
Re: w32.welchia.worm Jupiter Jones [MVP] Windows XP Security 0 25th Aug 2003 06:53 AM
Re: w32.Welchia.Worm Doug Knox MS-MVP Windows XP General 0 24th Aug 2003 09:03 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 03:39 PM.