Insidious New Spam

OT: anything goes!

Moderator: Edi

Post Reply
User avatar
Dalton
For Those About to Rock We Salute You
For Those About to Rock We Salute You
Posts: 22639
Joined: 2002-07-03 06:16pm
Location: New York, the Fuck You State
Contact:

Insidious New Spam

Post by Dalton »

For all you people using NT/2000/XP, this page might be of interest:

http://mattdrury.net/showfile.asp?which=messpam.txt

Apparently the spamwhores have found a new, insidious way to spam your computer. They use a built-in network service in Windows to broadcast spam messages to your machine without setting off the firewall or even showing up as a suspicious process. I myself have had three of these messages show up. Go to that page to stop them.
Image
Image
To Absent Friends
Dalton | Admin Smash | Knight of the Order of SDN

"y = mx + bro" - Surlethe
"You try THAT shit again, kid, and I will mod you. I will
mod you so hard, you'll wish I were Dalton." - Lagmonster

May the way of the Hero lead to the Triforce.
User avatar
MKSheppard
Ruthless Genocidal Warmonger
Ruthless Genocidal Warmonger
Posts: 29842
Joined: 2002-07-06 06:34pm

HAHHAH

Post by MKSheppard »

I have Windows ME, so this won't work EHHEHE
"If scientists and inventors who develop disease cures and useful technologies don't get lifetime royalties, I'd like to know what fucking rationale you have for some guy getting lifetime royalties for writing an episode of Full House." - Mike Wong

"The present air situation in the Pacific is entirely the result of fighting a fifth rate air power." - U.S. Navy Memo - 24 July 1944
User avatar
Evil Sadistic Bastard
Hentai Tentacle Demon
Posts: 4229
Joined: 2002-07-17 02:34am
Location: FREE
Contact:

Post by Evil Sadistic Bastard »

I have ZoneAlarm. No ph34r.
Believe in the sign of Hentai.

BotM - Hentai Tentacle Monkey/Warwolves - Evil-minded Medic/JL - Medical Jounin/Mecha Maniacs - Fuchikoma Grope Attack!/AYVB - Bloody Bastards.../GALE Force - Purveyor of Anal Justice/HAB - Combat Medical Orderly

Combat Medical Orderly(Also Nameless Test-tube Washer) : SD.Net Dept. of Biological Sciences
User avatar
Dalton
For Those About to Rock We Salute You
For Those About to Rock We Salute You
Posts: 22639
Joined: 2002-07-03 06:16pm
Location: New York, the Fuck You State
Contact:

Re: HAHHAH

Post by Dalton »

MKSheppard wrote:I have Windows ME, so this won't work EHHEHE
WinME? I feel so sorry for you. WinME is an even bigger piece of crap than XP.
Image
Image
To Absent Friends
Dalton | Admin Smash | Knight of the Order of SDN

"y = mx + bro" - Surlethe
"You try THAT shit again, kid, and I will mod you. I will
mod you so hard, you'll wish I were Dalton." - Lagmonster

May the way of the Hero lead to the Triforce.
User avatar
Dalton
For Those About to Rock We Salute You
For Those About to Rock We Salute You
Posts: 22639
Joined: 2002-07-03 06:16pm
Location: New York, the Fuck You State
Contact:

Post by Dalton »

Evil Sadistic Bastard wrote:I have ZoneAlarm. No ph34r.
Even then, it'll get through. Unless you block that port..
Image
Image
To Absent Friends
Dalton | Admin Smash | Knight of the Order of SDN

"y = mx + bro" - Surlethe
"You try THAT shit again, kid, and I will mod you. I will
mod you so hard, you'll wish I were Dalton." - Lagmonster

May the way of the Hero lead to the Triforce.
User avatar
Evil Sadistic Bastard
Hentai Tentacle Demon
Posts: 4229
Joined: 2002-07-17 02:34am
Location: FREE
Contact:

Post by Evil Sadistic Bastard »

Dalton wrote:
Evil Sadistic Bastard wrote:I have ZoneAlarm. No ph34r.
Even then, it'll get through. Unless you block that port..
I'm on highest security setting (i.e. port stealth).

Is that good enough?
Believe in the sign of Hentai.

BotM - Hentai Tentacle Monkey/Warwolves - Evil-minded Medic/JL - Medical Jounin/Mecha Maniacs - Fuchikoma Grope Attack!/AYVB - Bloody Bastards.../GALE Force - Purveyor of Anal Justice/HAB - Combat Medical Orderly

Combat Medical Orderly(Also Nameless Test-tube Washer) : SD.Net Dept. of Biological Sciences
User avatar
MKSheppard
Ruthless Genocidal Warmonger
Ruthless Genocidal Warmonger
Posts: 29842
Joined: 2002-07-06 06:34pm

Re: HAHHAH

Post by MKSheppard »

Dalton wrote:WinME? I feel so sorry for you. WinME is an even bigger piece of crap than XP.
Except Dell got this install to WORK RIGHT. I have less problems with this
box than my Win 98 SE box......
"If scientists and inventors who develop disease cures and useful technologies don't get lifetime royalties, I'd like to know what fucking rationale you have for some guy getting lifetime royalties for writing an episode of Full House." - Mike Wong

"The present air situation in the Pacific is entirely the result of fighting a fifth rate air power." - U.S. Navy Memo - 24 July 1944
User avatar
TrailerParkJawa
Sith Acolyte
Posts: 5850
Joined: 2002-07-04 11:49pm
Location: San Jose, California

Post by TrailerParkJawa »

Last week I took my firewall down to troubleshoot my DSL connection.
I forgot to turn the firewall back on and I got one of these spams.
It made me really mad because I know better. But it still surprised me
that they were using a NET SEND command to spam my IP address.

Anyway, if you disable the Messenger Service its not going to work. Also, if you are behind a NAT box its not going to work, since they cant even see you.
Disabling TCP/IP over NetBios should work but I have not verfied it. And yes, Zone Alarm blocks it too.
User avatar
Grand Admiral Thrawn
Ruthless Imperial Tyrant
Posts: 5755
Joined: 2002-07-03 06:11pm
Location: Canada

Post by Grand Admiral Thrawn »

Blarg, I have my faithful '98.
"You know, I was God once."
"Yes, I saw. You were doing well, until everyone died."
Bender and God, Futurama
User avatar
Alan Bolte
Sith Devotee
Posts: 2611
Joined: 2002-07-05 12:17am
Location: Columbus, OH

Post by Alan Bolte »

Yay! Been my biggest comp problem for about the past month. Just hadn't gotten around to figuring out how to fix it. That saved me some time.
Any job worth doing with a laser is worth doing with many, many lasers. -Khrima
There's just no arguing with some people once they've made their minds up about something, and I accept that. That's why I kill them. -Othar
Avatar credit
User avatar
C.S.Strowbridge
Sore Loser
Posts: 905
Joined: 2002-07-03 05:32pm
Location: Burnaby, BC, Canada
Contact:

Re: Insidious New Spam

Post by C.S.Strowbridge »

Dalton wrote:For all you people using NT/2000/XP, this page might be of interest:

http://mattdrury.net/showfile.asp?which=messpam.txt

Apparently the spamwhores have found a new, insidious way to spam your computer. They use a built-in network service in Windows to broadcast spam messages to your machine without setting off the firewall or even showing up as a suspicious process. I myself have had three of these messages show up. Go to that page to stop them.
I got one of those messages once. Once.

Shut off that system right away. Never got a legitimate message though it. No need to assume I would.
User avatar
Einhander Sn0m4n
Insane Railgunner
Posts: 18630
Joined: 2002-10-01 05:51am
Location: Louisiana... or Dagobah. You know, where Yoda lives.

Post by Einhander Sn0m4n »

Image Image
User avatar
Vertigo1
Defender of the Night
Posts: 4720
Joined: 2002-08-12 12:47am
Location: Tennessee, USA
Contact:

Post by Vertigo1 »

And its not new. Its been going around for years.
"I once asked Rebecca to sing Happy Birthday to me during sex. That was funny, especially since I timed my thrusts to sync up with the words. And yes, it was my birthday." - Darth Wong

Leader of the SD.Net Gargoyle Clan | Spacebattles Firstone | Twitter
User avatar
TrailerParkJawa
Sith Acolyte
Posts: 5850
Joined: 2002-07-04 11:49pm
Location: San Jose, California

Post by TrailerParkJawa »

And its not new. Its been going around for years.
Yeah, it is only becomming more common because more people have static IP's and more people have an OS with the messenger service (NT,2K, XP).
Even with dynamic IP you can still get these, its just less likely.
User avatar
Exonerate
Sith Marauder
Posts: 4454
Joined: 2002-10-29 07:19pm
Location: DC Metro Area

Post by Exonerate »

Dalton wrote:
Evil Sadistic Bastard wrote:I have ZoneAlarm. No ph34r.
Even then, it'll get through. Unless you block that port..
Port 139 is used for NetBIOS... You might need it, but probably isn't essential.

BoTM, MM, HAB, JL
User avatar
Enlightenment
Moderator Emeritus
Posts: 2404
Joined: 2002-07-04 07:38pm
Location: Annoying nationalist twits since 1990

Post by Enlightenment »

Exonerate wrote:Port 139 is used for NetBIOS... You might need it, but probably isn't essential.
Messenger spam still gets through even if you don't expose the NetBIOS-over-TCP/IP port to the Internet. You have to disable the messenger service or use a firewall.

That said, for security reasons, port 139 should never be exposed to the Internet in the first place. NetBIOS script kiddies can't hack ports that aren't listening.
It's not my place in life to make people happy. Don't talk to me unless you're prepared to watch me slaughter cows you hold sacred. Don't talk to me unless you're prepared to have your basic assumptions challenged. If you want bunnies in light, talk to someone else.
Post Reply