Table of Contents
This updated guide examines Sasser Attacks Windows Servers and Other Versions and organizes the essential facts, background, and practical takeaways in clear American English.
Sasser virus can infect any computer connected to the Internet service provider, and unlike most other computer viruses, it does not spread via email, according to Hyppoenen. He said: 'This is one of the new viruses that can automatically spread. As long as your computer is turned on, it can be invaded. Sasser has the unique ability to turn off the computer and then start the computer again, repeatedly like that. Hyppoenen said the firewall-protected computers may not be attacked by the virus. Hyppoenen said that while annoyed, Sasser is harmless and other experts say he can remove it easily. '
Sasser first appeared at 0001 GMT on Saturday, and infected computers that didn't install the latest Microsoft software were updated within the last 18 days. ( According to TTO )
Sasser - the return of the Blaster?
The new Internet worm, exploiting a defect of LSASS in Windows, has caused some network interruptions over the weekend. Security experts say it could spread faster when agencies returned to work early next week.
The virus, called Sasser, began spreading from May 1, easily accessible to any unprotected computer connected to the global information network. It attacks through a defect in a Windows component called the Local Security Authority Subsystem Service (LSASS) which belongs to some of the latest versions of Windows such as 2000, Server 2003 and XP. After scanning the entire system of unpatched PCs, Sasser creates a remote connection to the machine, installs a file transfer server (FTP) server and then downloads itself to the target machine. Sasser can shut down the computer (shutdown), then start automatically and repeat this process several times even though it doesn't seem to cause any serious damage to the system.
According to Mikko Hyppoenen, chief technology officer of F-Secure (Finland), the situation seems quite serious when the security firm predicts that several million computers worldwide have been infected with Sasser. 'We are not sure how big the numbers are, but one thing is for sure, the situation will get worse on the first day of the week when people bring laptops to work after a few days' vacation, Hyppoenen. warning. Because laptop computers are not protected by corporate firewall systems if employees carry them out and use them on other servers, they may be at risk of being infected with viruses and spread throughout their networks. business when bringing back to the office.
Bernard Ourghanlian, Microsoft's technical director in France, where a lot of network malfunctions were caused by Sasser last Saturday, said that despite the emergence of new worms from May 1, it was confirmed but it seems that F-Secure's number of millions of devices infected with Sasser is an exaggeration. He said that based on statistics at some of its virus testing points, only France and some Southeast Asian countries were attacked. Ourghanlian added that last month Microsoft released an upgrade to fix the vulnerability that viruses like Sasser could exploit and since mid-April there have been millions of copies of the software available.
In Russia, Kaspersky Security Software also warned of a major outbreak when offices returned to work today. 'Today, the scale of the Sasser spread is not serious enough because most people who just finished the weekend and many people' s computers are of course off, 'said Denis Zenkin, the company's expert. identify.
According to security software companies, despite being the third largest virus spread this year, after Mydoom. A in January and Bagle. B in February, Sasser is still not considered a global pandemic. same as Blaster in August 2003. Symantec (USA) has so far only recorded about 100 announcements, of which 20 are from businesses. Network Associates said it received only a few virus announcements from a few dozen companies, some of which said there were several hundred new machines - a small number compared to 10 million PCs attacked by Blaster last year.. Network Associates didn't even list Sasser in the top 10 most contagious viruses.
Alfred Huger, Symantec's chief technology officer, said that the virus author's motivation has not yet been determined because Sasser does not cause any damage to the hard drive and does not install any back-end ports on the system. Other Internet worms are often made to invade other viruses later. The only thing Sasser did, as mentioned above, is to slow down the system and make the computer restart. 'The virus is written so carelessly that its impact may not be terrifying.' Alfred Huger evaluated. ( According to VNE )
To protect your computer against Sasser Virus, you can follow these steps: (In English)
Step 1: Enable a Firewall
?ang tr??c khi t?o các cách khác, Make sure b?n ?ã ???c ho?t ??ng firewall ?? b?o v? b?n máy tính ??i v?i infection. N?u b?n có m?t firewall hardware trong ??a ch? cho nhà b?n ho?c k?t n?i tr??ng, ho?c n?u b?n s? d?ng b?ng phân vùng v?i Microsoft® Windows® XP, the Sasser worm is most likely blocked. N?u b?n ?ã b? g? b?, ho?t ??ng máy ph?c v? máy ph?c v? s? g? b? các ?i?u khi?n c?a m?ng Hãy ki?m tra ?? ki?m tra ?? cài ??t và t?o m?t máy ph?c v?, xem các Microsoft Protect Your PC site.
Step 2: Install the Required Update
Hãy h? tr? b?o m?t c?a máy tính v?i các t?p tin Sasser và nó b? t?t, b?n c?n ph?i t?i v? t?p tin và cài ??t thông báo c?p nh?t 835732, which was released with Microsoft Security Bulletin MS04-011. B?n có th? tìm c?p nh?t 835732 trên Windows Update Web site ?ã ???c ??ng nh?p trong Critical Updates và Service Packs section. B?n có th? t?i v? và cài ??t này c?p nh?t t? ??ng t? Microsoft Download Center. ?? tìm th?y t?i v? h? th?ng hành ??ng c?a b?n, Refer ??n Technical Security Bulletin MS04-011.
Chú ý If b?n cài ??t c?p nh?t cho MS04-011 t? ??ng hay qua các vi?c t? ??ng tr??c
Step 3: Automatically Check For and Remove Sasser. A and Sasser. B
B?n có th? s? d?ng công c? này ?? tìm th?y ??a c?ng c?a b?n ?? th? g? b? Sasser. A and Sasser. B. To do so, click Check My PC for Infection .
Quan tr?ng ?? dùng công c? này, b?n c?n ph?i ch?y Windows XP ho?c Windows 2000, và b?n c?n ph?i ?ã ???c cài ??t ???c c?p nh?t update v?i Microsoft Security Bulletin MS04-011.
Chú ý If b?n có l?i ?ang ch?y công c? t? trang này, nó có th? vì b?n Browser's security settings. N?u b?n có l?i nào, hãy th? t?i t?p tin này directly t? Download Microsoft.com và Then ch?y nó t? ??ng.
Step 4: Review Additional Technical Resources
Không th? làm vi?c làm vi?c làm vi?c làm vi?c x? lý, không th? làm vi?c ?? s? d?ng, hãy dùng m?t c?a vi?c làm vi?c g? b? g? b? s?n sàng ? các máy ph?c v? antivirus vendors' Web sites:
- Computer Associates
- F-secure
- Network Associates
- Norman
- Panda
- Sophos
- Symantec
- Trend Micro
N?u b?n mu?n g? b? b?n tay này (?? dùng ch? ng??i dùng), see the Microsoft Product Support Services (PSS) Security Response Team alert for technical guidance.
Step 5: Learn How to Protect Your PC
To help protect your computer against a wide variety of security threats, see Protect Your PC
FAQ
What is Sasser Attacks Windows Servers and Other Versions about?
It provides a structured overview of sasser, explains the main context, and highlights practical takeaways for readers.
Why does this topic matter?
Understanding the main concepts helps readers evaluate the issue, avoid common mistakes, and make better-informed decisions.
How should readers use this information?
Use the guidance as a practical starting point, confirm details that may have changed, and follow current product, safety, or security recommendations.
Reader Comments 0
Sign in with email or Google to join the discussion.