标题: 校园网络病毒警报!Blaster and Welchia "worms"。 [打印本页] 作者: lianxu1014 时间: 2003-10-11 05:29 标题: 校园网络病毒警报!Blaster and Welchia "worms"。 The infection of PCs by the Blaster and Welchia "worms" has severely degraded
the performance of the Lancaster University Student Network (LusNet) since
Friday. The Blaster and Welchia worms exploit a security weakness in selected
Microsoft Operating Systems (see: http://www.lancs.ac.uk/iss/a-virus/v-welchia.htm.)
The systems at risk are PCs running Windows NT4, Windows 2000 and Windows XP.
The LusNet CD issued at registration includes instructi##被过滤## and the "software
patch" that you need to apply to Microsoft Windows. The CD also includes "extractor
tools" to remove a Welchia or Blaster infection from a PC, however the extraction
tool is only effective if the appropriate "security patch" has been applied
beforehand.
Additionally, the LusNet CD also contains a licenced copy of the Norton Anti-Virus
software. If installed, this will alert you to future attaempts to infecti##被过滤##
by computer virus and worms.
ISS is progressively removing infected PC from LusNet so as to restore network
performance for everyone else.
Finally, please validate your computer for the residence network at http://www.lancs.ac.uk/net-reg/
Registering your computer provides youwith additional services, these are:
* Access to Wing (university email)
* Access to \\central-files
* Access to exchange mail servers for postgraduates
* Offsite access to POP servers, ssh, IRC, ICQ and some instant messengers
* Unrestricted web access (unvalidated machines will soon be redirected to
the validation page) unrestricted local web access.
The validation is required so that we can contact you faster in theevent of
problems caused by your computer such as virus infection.
Although most of the network can handle worm infecti##被过滤## it has serious effects
on offsite access to anything other than web acccess, it poses major security
problems to any infected computer and lowers performance significantly, as
a result we have to take severe action against infected machines and remove
them from the network.
All replies should be directed to: resnet-faults@lancs.ac.uk
David Lomas (Head of User Services)
附加说明
IIS漏洞:
Microsoft Windows 2000支持World Wide Web Distributed Authoring and Versioning (WebDAV)
protocol.WebDAV是一套扩展的HTTP协议,是Internet上的文件管理、编辑的标准,它存在一个漏洞,攻击者
通过发送一个特定格式的HTTP请求给运行IIS的机器,导致server运行
失败,从而执行攻击者的代码.由于病毒的特殊传播方式,可能造成网络交通堵塞
冲击波(Worm.Blaster)病毒档案
警惕程度:★★★★
发作时间:随机
病毒类型:蠕虫病毒
传播途径:网络/RPC漏洞
依赖系统: Microsoft Windows NT 4.0 / Microsoft Windows 2000 / Microsoft Windows XP /Microsoft Windows Server 2003