] A malicious worm that exploits last month's RPC ] DCOM vulnerability struck the Internet Monday ] afternoon, targeting unpatched Windows 2000 and ] Windows XP machines. ] ] The worm, dubbed "Blaster" and "LovSan" by security ] and anti-virus companies, attacks vulnerable ] machines over TCP port 135, then spawns a shell ] and initiates a TFTP file transfer to retrieve the ] worm's code. Well get ready the worm is set to DoS windowsupdate.microsoft.com starting this Saturday, 09/15/2003. For more information Symantec has a good write up on the worm at http://www.sarc.com/avcenter/venc/data/w32.blaster.worm.html SecurityFocus HOME News: RPC DCOM Worm Hits the Net |