Edge Rewrite
Jump to content

Talk:Sasser (computer worm)

Page contents not supported in other languages.
Add topic
From Wikipedia, the free encyclopedia
Latest comment: 10 months ago by HamburgerRadio in topic Exploit description wording

The last bit about repairing the computer - the only way is to format the drive. Rubbish!

it is also easily stopped ... by downloading system updates from Windows Update.

[edit]

This is definitely wrong. You couldn't download and install a patch using a vulnerable PC, since the PC was infected by receiving one single packet at an open Port, no user interaction required. This regularly happened before you've got a chance for downloading and installing a patch. 2A02:908:186C:6BC0:FC88:5ECB:6C23:E6AD (talk) 14:34, 15 March 2019 (UTC)Reply

IP addresses in editing history

[edit]

I have reviewed the editing history of this article and there were many IP addresses. These can be reedited no matter. An alias is required to protect identities.

A few minor additions and adding sources

[edit]

I was writing a paper on this worm for a network security course and found several sources that supported the claims made in this article so I added them. I also added some clarifying information on the way the worm spreads itself. And according to a video by danooct1 on YouTube, the worm can be simply deleted from the registry and then from the hard drive without having to reformat the drive. I see no reason to doubt this, as the worm doesn't seem terribly complex. Wombatpandaa (talk) 17:37, 6 February 2023 (UTC)Reply

Exploit description wording

[edit]

Currently it reads: "This buffer overflow relies on an undocumented API call to Microsoft Active Directory, which both allows for arbitrary code execution and crashes LSASS.exe if given a long string."

  • It could be interpreted as the vulnerability is knowing that the undocumented API exists, and the buffer overflow is to provide the additional ability to crash LSASS.exe.
  • "API call to Microsoft Active Directory" sounds like it might require Active Directory to be present, but as many home users found out, it does not.

Thinking: "This buffer overflow gives a long string to an undocumented API in Microsoft Active Directory-related functions, which both allows for arbitrary code execution and often crashes LSASS.exe."

Might need some more work, but hopefully it's more clear. --HamburgerRadio (talk) 04:17, 4 October 2025 (UTC)Reply