OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Gerald Carter (gcarterVALINUX.COM)
Date: Tue Sep 18 2001 - 21:29:02 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    On Tue, 18 Sep 2001, Avinesh Bangar wrote:

    > Hi,
    >
    > It seems that open Samba (Linux) shares are also affected -- possibly
    > because the Samba server is emulated as a Windows NT 4.2 Server? I
    > just searched the shares for *.eml and *.nws and deleted the
    > respective files. It seems as though not all shares were affected,
    > just the ones that had FTP access.

    After talking to a few people it seems I was wrong. Apparently
    it tries to drop its files onto CIFS/SMB servers by logging in
    as guest. If Samba had a valid user named guest with no password,
    then it would suceed ...

    or if you have "map to guest" in smb.conf set to anything other
    than the default of "Never", you might see this as well. Of course,
    this also assumes that "guest" has write access to shares.

    Apologies for the previous hasty and incorrect response. Hope this
    helps.

    cheers, jerry
     ---------------------------------------------------------------------
     www.samba.org SAMBA Team jerry_at_samba.org
     www.plainjoe.org jerry_at_plainjoe.org
     --"I never saved anything for the swim back." Ethan Hawk in Gattaca--

    ============================================================================
    Delivery co-sponsored by Trend Micro, Inc.
    ============================================================================
    TREND MICRO SCANMAIL FOR EXCHANGE 2000 -- SECOND to NONE

    If you are worried about email viruses, you need Trend Micro ScanMail for
    Exchange. ScanMail is the first antivirus solution that seamlessly
    integrates with the Microsoft Exchange 2000 virus-scanning API 2.0. ScanMail
    ensures 100% inbound and outbound email virus scanning and provides remote
    software management. Download a FREE 30-day trial copy of ScanMail and find
    out why it is the best:
    http://www.antivirus.com/banners/tracking.asp?si=8&BI;=240&UL;=/smex2000
    ============================================================================