[Dshield] DCOM morning after

Jonathan Rickman jonathan at xcorps.net
Tue Aug 12 13:50:22 GMT 2003

On Tuesday 12 August 2003 09:07, Paul Marsh wrote:
> Good Morning All:
> 	Unfortunately I was unable to watch as things developed last night so
> I'm trying to find out where we are this morning.  InfoCon is still at
> yellow, looks like everything we knew yesterday @ 6:00pm EST is still
> true, nothing new?  It also looks like all AV vendors have signatures for
> msblaster and things at least in my tiny little section of the forest are
> starting to calm down.  I did notice that Trend has another worm listed
> called Worm_RPCSDBOT http://www.trendmicro.com/vinfo/ .  It looks like a
> re-worked version of msblaster.

There have been several reports on the incidents list suggesting that 
patched machines are being infected in some cases.

Jonathan Rickman
X Corps Security

More information about the list mailing list