Page 1 of 2

Users with Windows NT/2K/XP gather hither, security update

Posted: 2003-08-11 05:37pm
by His Divine Shadow
Simple question, anyone of you had RPC related problems that lead to reboots this last day? Well they're not your fault but that of a group of hackers that have found a security flaw.

I myself was hit twice before I realized this is not because of me, this XP installation has been stable for over one year, I saw my firewall was not engaged, gah, so on the next reboot I started it up and lo and behold, some whore from IP: 209.86.255.197 trying to send me shit through ports 135-4491.

Get the updates from Microsoft now please, or atleast get a firewall, prefferably both.

Posted: 2003-08-11 05:42pm
by Crayz9000
Script kiddies, not hackers. These are just 14-year-olds with nothing better to do.

Posted: 2003-08-11 05:43pm
by His Divine Shadow
Crayz9000 wrote:Script kiddies, not hackers. These are just 14-year-olds with nothing better to do.
Conceeded :P

Posted: 2003-08-11 06:12pm
by phongn
Long since patched, though my firewall at home should be blocking it.

Posted: 2003-08-11 06:29pm
by otter
I've been meaning to install a firewall. Can anyone make some good recommendations?

Posted: 2003-08-11 06:31pm
by Dalton
otter wrote:I've been meaning to install a firewall. Can anyone make some good recommendations?
Kerio Personal Firewall and ZoneAlarm are the two top choices.

kerio.com
zonelabs.com

Posted: 2003-08-11 06:37pm
by RedImperator
otter wrote:I've been meaning to install a firewall. Can anyone make some good recommendations?
Zone Alarm is freeware. I don't know about the other one Dalton mentioned.

I'll get the update, even though I'm behind not one but two firewalls.

Posted: 2003-08-11 06:44pm
by Crayz9000
Kerio (it used to be Tiny Personal Firewall version 2) is also freeware, and it's a good sight better than ZoneAlarm.

Posted: 2003-08-11 07:02pm
by phongn
otter wrote:I've been meaning to install a firewall. Can anyone make some good recommendations?
W2K and WXP have a built-in firewall. Kerio is a good solution if you want to block outgoing stuff.

Posted: 2003-08-11 07:05pm
by otter
Dalton wrote:
otter wrote:I've been meaning to install a firewall. Can anyone make some good recommendations?
Kerio Personal Firewall and ZoneAlarm are the two top choices.

kerio.com
zonelabs.com

Thanks for the input.....I go check 'em out

Posted: 2003-08-11 07:27pm
by Trytostaydead
HELP! I did the security update from the Microsoft homepages! It just jacked up my computer more!

It takes like 5 minutes now for me to load up my computer and my taskbar seems locked. I can't unlock it or resize it which means I can't even see it. Driving me insane! Anyone else have this happen to them?

Posted: 2003-08-11 07:38pm
by phongn
Do an immediate system restore to the last point before the patch was applied and try again. Something went wrong there.

Posted: 2003-08-11 07:43pm
by Trytostaydead
phongn wrote:Do an immediate system restore to the last point before the patch was applied and try again. Something went wrong there.
How do I do that?

Posted: 2003-08-11 08:17pm
by phongn
Use the Help, it is in there.

Posted: 2003-08-11 08:20pm
by Trytostaydead
phongn wrote:Use the Help, it is in there.
You bastard :-P

Actually, help doesn't work. Almost nothing works but basic browsing ability.

Posted: 2003-08-11 08:27pm
by Brother-Captain Gaius
Trytostaydead wrote:
phongn wrote:Use the Help, it is in there.
You bastard :-P

Actually, help doesn't work. Almost nothing works but basic browsing ability.
Control Panel, System, Restore tab, if it will let you do that.

Posted: 2003-08-11 08:29pm
by Trytostaydead
System Restore has nothing in it that says restore. The only option is to turn the settings off or change the max amount of space. I have searched high and low.

Posted: 2003-08-11 08:30pm
by phongn
Go into Start Menu->Programs->Accessories->System Restore

Posted: 2003-08-11 08:34pm
by Trytostaydead
phongn wrote:Go into Start Menu->Programs->Accessories->System Restore
Unfortunately.. tool bar is unaccessible to me.

Re: Users with Windows NT/2K/XP gather hither, security upda

Posted: 2003-08-11 08:41pm
by aphexmonster
His Divine Shadow wrote:Simple question, anyone of you had RPC related problems that lead to reboots this last day? Well they're not your fault but that of a group of hackers that have found a security flaw.

I myself was hit twice before I realized this is not because of me, this XP installation has been stable for over one year, I saw my firewall was not engaged, gah, so on the next reboot I started it up and lo and behold, some whore from IP: 209.86.255.197 trying to send me shit through ports 135-4491.

Get the updates from Microsoft now please, or atleast get a firewall, prefferably both.


It happened to me ... but i fixed the problem ... it was quite annoying. I was woken up by the sound of my computer restarting ... and kept awake by the sound of it restarting. I cant wait til i get linux -_-

Posted: 2003-08-11 09:06pm
by Crayz9000
Trytostaydead wrote:
phongn wrote:Go into Start Menu->Programs->Accessories->System Restore
Unfortunately.. tool bar is unaccessible to me.
Try Win+R and see if you can get the Run prompt. I don't know what the system restore command is, though.

Posted: 2003-08-11 09:15pm
by phongn
Run this:

Code: Select all

%SystemRoot%\System32\restore\rstrui.exe 

Posted: 2003-08-11 09:25pm
by Trytostaydead
phongn wrote:Run this:

Code: Select all

%SystemRoot%\System32\restore\rstrui.exe 
Yeah, already got someone to tell me that.. does not run either. I'm beginning to suspect I'm going to need to format.. DAMN YOU BILL GATES!

Posted: 2003-08-11 09:30pm
by phongn
What happens when you try to execute it ?

Something else is wrong with your box if a simple patch caused such catastrophic damage. Have you attempted to reboot into safe mode?

Posted: 2003-08-11 09:32pm
by Trytostaydead
phongn wrote:What happens when you try to execute it ?

Something else is wrong with your box if a simple patch caused such catastrophic damage. Have you attempted to reboot into safe mode?
Tried just about everything.. something is majorly fouled up. Perhaps someone was using more than one security flaw when they were accessing my computer.. who knows.