Napada me neki .. (Helkerm/Slammer/Sapphire)

Napada me neki .. (Helkerm/Slammer/Sapphire)

offline
  • Pridružio: 26 Feb 2005
  • Poruke: 106
  • Gde živiš: Osijek

Kaspersky ANTI-HACEKER mi cesto javi da me napada neki Halkern ili tako nesto...
Dok nisam imao Kaspersky Anti-Hackera, Kaspersky AV mi je javljao istu stvar.

Je li to opasno i kako ga se rijesiti?

Hvala!



Registruj se da bi učestvovao u diskusiji. Registrovanim korisnicima se NE prikazuju reklame unutar poruka.
offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

To je crv, i jedino se moze odbijati, sto tvoj KAV lepo radi. Ne mozes ti nista protiv toga, osim da klikas ono OK kada KAV prijavi napad.



offline
  • RIA  Male
  • Prijatelj foruma
  • Pridružio: 20 Feb 2005
  • Poruke: 2841
  • Gde živiš: Around Belgrade

mozda da pokusas neki drugi firewall ?

offline
  • SINGI
  • Pridružio: 22 Avg 2003
  • Poruke: 787
  • Gde živiš: Beograd

diamond73 ::mozda da pokusas neki drugi firewall ?

A zasto kada lepo odbija napad? Smile

A ako ga smara moze da iskljuci "notification" i da vise ni ne zna sta je sve odbijeno, osim ako ode u log.

offline
  • RIA  Male
  • Prijatelj foruma
  • Pridružio: 20 Feb 2005
  • Poruke: 2841
  • Gde živiš: Around Belgrade

rekoh kao predlog. Nije sporno,ako mu se svidja antihacker moze uvek da ga vrati.

nemoras sve da shvatas licno Smile

offline
  • SVITAC 
  • Legendarni građanin
  • Pridružio: 28 Apr 2003
  • Poruke: 5919
  • Gde živiš: Beograd

Ide se offtopic .. tema je konkretno Helkerm/Slammer/Sapphire/ Netcrv ..

"Helkern" - 376 Bytes That Shook The World

Kaspersky Labs, an international data security software developer, is warning users to look our for the new Internet-worm "Helkern" (also known as "Slammer" or "Sapphire") that infects servers running under the popular Web-enabled database Microsoft SQL Server 2000. The extremely small size of the worm (only 376 bytes), a unique technology it employs for penetrating target computers and an extraordinarily high spreading speed allow us to proclaim "Helkern" one of the biggest dangers threatening the normal operation of the Internet to come along in years. There have already been reports of serious disruptions to Internet functioning in South Korea, Australia and New Zealand.

It is possible to say the worm has caused one of the largest virus outbreaks in history that has affected user from all corners of the globe: messages describing infections from "Helkern" are being received from Europe, the United States and Eastern Asia.

"Helkern" belongs to the "fileless" worms category. This type of malicious programs performs all operations (including infection and spreading) exclusively in the computer's operating memory without using any permanent or temporary files. These features seriously complicate the detection and disinfection of such worms using contemporary anti-virus technologies (on-demand and on-access scanners). The first malicious code of this type, "CodeRed", was discovered on July 20, 2001. At that time it caused a wide-scale outbreak infecting dozens of thousands of systems around the world. Up until now, with the exception of "CodeRed", "fileless" worms had not shown themselves.

"Helkern" infects only computers running Microsoft SQL Server 2000, a multi-functional database system widely used primarily on Web-servers. To home users of any Windows version without the installion of Microsoft SQL Server the worm poses no threat.

"Helkern" exploits a security breach ("Buffer Overrun") in Microsoft SQL Server that was first detected in July, 2002. To accomplish the "buffer overrun" exploit the worm sends a special request to a target computer. When the request is processed the system automatically executes the worm's code contained in this request. In this way a malefactor can run malicious code without a user's knowledge.

Next, "Helkern" initiates its spreading routine. This process features the extremely rapid sending of the worm's copies to other Internet users: "Helkern" starts an endless spawning loop that many times increases network traffic. "Within just 3 hours from the start of the outbreak began we have detected more than 20 thousand attempts by "Helkern" to penetrate our network, - says Igor Mitiurin, Head of the Information Security Department at Russlavbank, a major Russian financial institution, - Fortunately all these penetration attempts were successfully blocked thanks to our implementation of an effective information security policy that includes the timely installation of security patches for all software used in our corporate network."

Nowadays Microsoft SQL Server is one of the acknowledged leaders in the Web-enabled database market and is used on hundreds of thousands of computers the world over. These events show that many of these systems still contain the security breach allowing infection at the hands of "Helkern". "Helkern" is a real threat that can cause serious interruption to the workings of Internet because the worm generates a huge amount of redundant network traffic that jams data transmission channels. Moreover, in the future, there is a possibility that such attacks will happen with increasing frequency. These circumstances underline the necessity to develop a new approach confronting Internet virus outbreaks. Contemporary technologies have shown a low effectiveness when dealing with such challenges," said Eugene Kaspersky, Head of Anti-Virus Research for Kaspersky Labs

Ko je trenutno na forumu
 

Ukupno su 933 korisnika na forumu :: 49 registrovanih, 7 sakrivenih i 877 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: A.R.Chafee.Jr., Acivi, bagor10, bokisha253, Brana01, cifra, cincarin, darkojbn, debeli, dekan.m, Denaya, Dimitrije Paunovic, djboj, doklevise, dragoljub11987, Excalibur13, Frunze, Georgius, HrcAk47, Istman, Ivan Campo, JimmyNapoli, JOntra, Kubovac, Lubica, MB120mm, mercedesamg, mgolub, mikrimaus, milenko crazy north, MiroslavD, naki011, nenad81, nenooo, nextyamb, raketaš, rasok, Ripanjac, Romibrat, saputnik plavetnila, slonic_tonic, SR-3m, Sumadija34, tmanda323, trajkoni018, Viceroy, VJ, Wrangler, 125