I see one of two probable answers here. The first being that your school systems were never patched and someone inadvertantly/purposely introduced blaster code into the network, thus the RPCs.
The second is that an exploit has been developed for the latest M$ exploit released last week. (Somewhere in the 48-50 range) From what I have read of the exploit it is very similar to the RPC exploit in blaster. That being the case, compiled with the fact that it uses UDP/TCP 138, 139, and 445, it should be quite easy to modify the existing blaster worm to attack the new exploit. Just a stab in the dark but it would not suprise me.




Reply With Quote