Users with Windows NT/2K/XP gather hither, security update
Moderator: Edi
- Crayz9000
- Sith Apprentice
- Posts: 7329
- Joined: 2002-07-03 06:39pm
- Location: Improbably superpositioned
- Contact:
Well, if they got full access, who knows what the hell they did to your box. Just deleting a couple files can throw Windows into complete chaos.
A Tribute to Stupidity: The Robert Scott Anderson Archive (currently offline)
John Hansen - Slightly Insane Bounty Hunter - ASVS Vets' Assoc. Class of 2000
HAB Cryptanalyst | WG - Intergalactic Alliance and Spoof Author | BotM | Cybertron | SCEF
John Hansen - Slightly Insane Bounty Hunter - ASVS Vets' Assoc. Class of 2000
HAB Cryptanalyst | WG - Intergalactic Alliance and Spoof Author | BotM | Cybertron | SCEF
- lukexcom
- Padawan Learner
- Posts: 365
- Joined: 2003-01-04 03:49am
- Location: Ah, Northern Virginia. The lone island of stability in an ocean of recession.
- Contact:
This all sounds suspiciously like Nimda or some other worm at work here. If you still have access to the search tool, find any file that has the extension "eml" on your hard drive. In other words, type in "*.eml" w/o quotes into the search bar. If you get a ton of them, then it means that you most likely have Nimda or a similar worm infecting your computer.
Either way, by now your system is most likely unrecoverable. If it is a worm, then you'll have to format. Hell, run fdisk and fry your partitions just to be safe.
When I discovered a worm on my network (nimda32 version E), I lost one computer's contents and my whole network got infected. The other computers recovered though.
Either way, by now your system is most likely unrecoverable. If it is a worm, then you'll have to format. Hell, run fdisk and fry your partitions just to be safe.
When I discovered a worm on my network (nimda32 version E), I lost one computer's contents and my whole network got infected. The other computers recovered though.
-Luke
- EmperorMing
- Sith Devotee
- Posts: 3432
- Joined: 2002-09-09 05:08am
- Location: The Lizard Lounge
- TrailerParkJawa
- Sith Acolyte
- Posts: 5850
- Joined: 2002-07-04 11:49pm
- Location: San Jose, California
I should have d/l 'd the update but I have not run it yet. Im behind a firewall and sometimes a router using NAT. I should check my logs to see if anyone is probing. I just got DSL moved to this house about a week ago. Whats cool is even though Im in a different county I got to retain the same static IP.
MEMBER of the Anti-PETA Anti-Facist LEAGUE
- Vertigo1
- Defender of the Night
- Posts: 4720
- Joined: 2002-08-12 12:47am
- Location: Tennessee, USA
- Contact:
You know what's great? The "fix" that Microsoft released DOESN'T work! I'm in still in the process of reloading everything because of it. I had to download 40MB of updates because the frelling Windows Update deletes the temp files it creates! (extremely annoying) As soon as I finish this post, I'm locking down every port with the exception of those that I need. (Good thing all the fucker did was keep my comp from loading explorer.exe. I could still use IE to access Windows Explorer to backup my data, after I scanned my machine from safe mode.)
This asshole better pray that I don't find out where he/she lives. If I do.....GALLAGHER SMASH TIME!
This asshole better pray that I don't find out where he/she lives. If I do.....GALLAGHER SMASH TIME!
"I once asked Rebecca to sing Happy Birthday to me during sex. That was funny, especially since I timed my thrusts to sync up with the words. And yes, it was my birthday." - Darth Wong
Leader of the SD.Net Gargoyle Clan | Spacebattles Firstone | Twitter
Leader of the SD.Net Gargoyle Clan | Spacebattles Firstone | Twitter
- His Divine Shadow
- Commence Primary Ignition
- Posts: 12791
- Joined: 2002-07-03 07:22am
- Location: Finland, west coast
- Vertigo1
- Defender of the Night
- Posts: 4720
- Joined: 2002-08-12 12:47am
- Location: Tennessee, USA
- Contact:
Umm....as in it failed to prevent what it was supposed to fix in the first place!His Divine Shadow wrote:What do you mean doesn't work?
Now if you'll excuse me, I've got some games to re-install.
*pops in Freespace 2 CD*
"I once asked Rebecca to sing Happy Birthday to me during sex. That was funny, especially since I timed my thrusts to sync up with the words. And yes, it was my birthday." - Darth Wong
Leader of the SD.Net Gargoyle Clan | Spacebattles Firstone | Twitter
Leader of the SD.Net Gargoyle Clan | Spacebattles Firstone | Twitter
- Faram
- Bastard Operator from Hell
- Posts: 5271
- Joined: 2002-07-04 07:39am
- Location: Fighting Polarbears
Old update.
Here is a good read about it. Linky MS
Futher down in that text there is a DL location for the patch.
Here is a good read about it. Linky MS
Futher down in that text there is a DL location for the patch.
[img=right]http://hem.bredband.net/b217293/warsaban.gif[/img]
"Either God wants to abolish evil, and cannot; or he can, but does not want to. ... If he wants to, but cannot, he is impotent. If he can, but does not want to, he is wicked. ... If, as they say, God can abolish evil, and God really wants to do it, why is there evil in the world?" -Epicurus
Fear is the mother of all gods.
Nature does all things spontaneously, by herself, without the meddling of the gods. -Lucretius
"Either God wants to abolish evil, and cannot; or he can, but does not want to. ... If he wants to, but cannot, he is impotent. If he can, but does not want to, he is wicked. ... If, as they say, God can abolish evil, and God really wants to do it, why is there evil in the world?" -Epicurus
Fear is the mother of all gods.
Nature does all things spontaneously, by herself, without the meddling of the gods. -Lucretius
heh heh, and now MS Blaster takes advantage of the exploit. Symantec link here... http://securityresponse.symantec.com/av ... .worm.html
Did you clear out MSBLAST first? Even when you install the patch you still have to nuke it, and you need to firewall your box.Vertigo1 wrote:You know what's great? The "fix" that Microsoft released DOESN'T work! I'm in still in the process of reloading everything because of it. I had to download 40MB of updates because the frelling Windows Update deletes the temp files it creates! (extremely annoying) As soon as I finish this post, I'm locking down every port with the exception of those that I need. (Good thing all the fucker did was keep my comp from loading explorer.exe. I could still use IE to access Windows Explorer to backup my data, after I scanned my machine from safe mode.)
- Vertigo1
- Defender of the Night
- Posts: 4720
- Joined: 2002-08-12 12:47am
- Location: Tennessee, USA
- Contact:
Oddly enough, it is firewalled. However, I just started using a new software firewall at the time, and hadn't finished setting up the rules. (Went from AtGuard 3.22 to Norton's PF, which is just an upgraded version of Atguard that got n00bified. I'm only using this until I find something better.)phongn wrote:Did you clear out MSBLAST first? Even when you install the patch you still have to nuke it, and you need to firewall your box.Vertigo1 wrote:You know what's great? The "fix" that Microsoft released DOESN'T work! I'm in still in the process of reloading everything because of it. I had to download 40MB of updates because the frelling Windows Update deletes the temp files it creates! (extremely annoying) As soon as I finish this post, I'm locking down every port with the exception of those that I need. (Good thing all the fucker did was keep my comp from loading explorer.exe. I could still use IE to access Windows Explorer to backup my data, after I scanned my machine from safe mode.)
"I once asked Rebecca to sing Happy Birthday to me during sex. That was funny, especially since I timed my thrusts to sync up with the words. And yes, it was my birthday." - Darth Wong
Leader of the SD.Net Gargoyle Clan | Spacebattles Firstone | Twitter
Leader of the SD.Net Gargoyle Clan | Spacebattles Firstone | Twitter
- Uraniun235
- Emperor's Hand
- Posts: 13772
- Joined: 2002-09-12 12:47am
- Location: OREGON
- Contact:
Long since patched.
BUT, sometimes they get in without crashing RPC... and then they have complete, total, unrestricted access to your computer, with all the rights of SYSTEM.
Then they can do as they please. Infect you with viruses, look at your files, plant trojans on your system... there's going to be some massive DDOS attacks stemming from this, I'm sure, because a lot of people will just patch and not clean their system of viruses. I've heard there's already one supposedly going to happen against the Windows Update website (which should be known by heart to any Windows user) on the 16th or something like that.
It's not a specific "bug"... it's an exploit in the RPC service. A lot of tools out there right now that take advantage of it have a tendency to crash RPC while they're doing it and hence the 60-second "Windows will restart now" countdown.Apparently if you get infected with this thing
BUT, sometimes they get in without crashing RPC... and then they have complete, total, unrestricted access to your computer, with all the rights of SYSTEM.
Then they can do as they please. Infect you with viruses, look at your files, plant trojans on your system... there's going to be some massive DDOS attacks stemming from this, I'm sure, because a lot of people will just patch and not clean their system of viruses. I've heard there's already one supposedly going to happen against the Windows Update website (which should be known by heart to any Windows user) on the 16th or something like that.
- Trytostaydead
- Sith Marauder
- Posts: 3690
- Joined: 2003-01-28 09:34pm
- Uraniun235
- Emperor's Hand
- Posts: 13772
- Joined: 2002-09-12 12:47am
- Location: OREGON
- Contact:
God, I took two years of high school classes involving Windows 2000, I feel like such a fool... where do I find the W2K firewall?phongn wrote:W2K and WXP have a built-in firewall. Kerio is a good solution if you want to block outgoing stuff.otter wrote:I've been meaning to install a firewall. Can anyone make some good recommendations?