Page 1 of 1

Insidious New Spam

Posted: 2002-11-30 03:44am
by Dalton
For all you people using NT/2000/XP, this page might be of interest:

http://mattdrury.net/showfile.asp?which=messpam.txt

Apparently the spamwhores have found a new, insidious way to spam your computer. They use a built-in network service in Windows to broadcast spam messages to your machine without setting off the firewall or even showing up as a suspicious process. I myself have had three of these messages show up. Go to that page to stop them.

HAHHAH

Posted: 2002-11-30 03:49am
by MKSheppard
I have Windows ME, so this won't work EHHEHE

Posted: 2002-11-30 03:54am
by Evil Sadistic Bastard
I have ZoneAlarm. No ph34r.

Re: HAHHAH

Posted: 2002-11-30 03:58am
by Dalton
MKSheppard wrote:I have Windows ME, so this won't work EHHEHE
WinME? I feel so sorry for you. WinME is an even bigger piece of crap than XP.

Posted: 2002-11-30 03:59am
by Dalton
Evil Sadistic Bastard wrote:I have ZoneAlarm. No ph34r.
Even then, it'll get through. Unless you block that port..

Posted: 2002-11-30 04:00am
by Evil Sadistic Bastard
Dalton wrote:
Evil Sadistic Bastard wrote:I have ZoneAlarm. No ph34r.
Even then, it'll get through. Unless you block that port..
I'm on highest security setting (i.e. port stealth).

Is that good enough?

Re: HAHHAH

Posted: 2002-11-30 04:17am
by MKSheppard
Dalton wrote:WinME? I feel so sorry for you. WinME is an even bigger piece of crap than XP.
Except Dell got this install to WORK RIGHT. I have less problems with this
box than my Win 98 SE box......

Posted: 2002-11-30 12:24pm
by TrailerParkJawa
Last week I took my firewall down to troubleshoot my DSL connection.
I forgot to turn the firewall back on and I got one of these spams.
It made me really mad because I know better. But it still surprised me
that they were using a NET SEND command to spam my IP address.

Anyway, if you disable the Messenger Service its not going to work. Also, if you are behind a NAT box its not going to work, since they cant even see you.
Disabling TCP/IP over NetBios should work but I have not verfied it. And yes, Zone Alarm blocks it too.

Posted: 2002-11-30 12:58pm
by Grand Admiral Thrawn
Blarg, I have my faithful '98.

Posted: 2002-11-30 01:42pm
by Alan Bolte
Yay! Been my biggest comp problem for about the past month. Just hadn't gotten around to figuring out how to fix it. That saved me some time.

Re: Insidious New Spam

Posted: 2002-11-30 08:49pm
by C.S.Strowbridge
Dalton wrote:For all you people using NT/2000/XP, this page might be of interest:

http://mattdrury.net/showfile.asp?which=messpam.txt

Apparently the spamwhores have found a new, insidious way to spam your computer. They use a built-in network service in Windows to broadcast spam messages to your machine without setting off the firewall or even showing up as a suspicious process. I myself have had three of these messages show up. Go to that page to stop them.
I got one of those messages once. Once.

Shut off that system right away. Never got a legitimate message though it. No need to assume I would.

Posted: 2002-11-30 08:57pm
by Einhander Sn0m4n

Posted: 2002-12-01 12:35am
by Vertigo1
And its not new. Its been going around for years.

Posted: 2002-12-01 12:39am
by TrailerParkJawa
And its not new. Its been going around for years.
Yeah, it is only becomming more common because more people have static IP's and more people have an OS with the messenger service (NT,2K, XP).
Even with dynamic IP you can still get these, its just less likely.

Posted: 2002-12-01 12:58am
by Exonerate
Dalton wrote:
Evil Sadistic Bastard wrote:I have ZoneAlarm. No ph34r.
Even then, it'll get through. Unless you block that port..
Port 139 is used for NetBIOS... You might need it, but probably isn't essential.

Posted: 2002-12-02 01:29am
by Enlightenment
Exonerate wrote:Port 139 is used for NetBIOS... You might need it, but probably isn't essential.
Messenger spam still gets through even if you don't expose the NetBIOS-over-TCP/IP port to the Internet. You have to disable the messenger service or use a firewall.

That said, for security reasons, port 139 should never be exposed to the Internet in the first place. NetBIOS script kiddies can't hack ports that aren't listening.