|
Posted by manu on June 3, 2005, 12:24 am
If you were Registered and logged in, you could reply and use other advanced thread options
Hiii all
There is a question in my mind forcing me to put it in front of u all.
Question is
Suppose one system is infected from SQL Slammer (or any self
propagating malicious codes ) . it exploits a vulnerability in the
Resolution Service of Microsoft SQL Server 2000 and Microsoft Desktop
Engine (MSDE) 2000. Now it tries to propagate in the network. In
portscanning what it will do?
1)after establishing TCP connection between infected system and
uninfected system, will the worm first copies itself on that machine ,
then look for vulnerability or
2) will it look for vulnerability in the Resolution Service of
Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000,
Then copies itself
In the first case if it copies itself first then lookin for
vulnerability, in that case will the virus die when it wont find
Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000..
Please clarify.
Rgds
Bhaskar Gupta
|