Users with Windows NT/2K/XP gather hither, security update

OT: anything goes!

Moderator: Edi

User avatar
Crayz9000
Sith Apprentice
Posts: 7329
Joined: 2002-07-03 06:39pm
Location: Improbably superpositioned
Contact:

Post by Crayz9000 »

Well, if they got full access, who knows what the hell they did to your box. Just deleting a couple files can throw Windows into complete chaos.
A Tribute to Stupidity: The Robert Scott Anderson Archive (currently offline)
John Hansen - Slightly Insane Bounty Hunter - ASVS Vets' Assoc. Class of 2000
HAB Cryptanalyst | WG - Intergalactic Alliance and Spoof Author | BotM | Cybertron | SCEF
User avatar
lukexcom
Padawan Learner
Posts: 365
Joined: 2003-01-04 03:49am
Location: Ah, Northern Virginia. The lone island of stability in an ocean of recession.
Contact:

Post by lukexcom »

This all sounds suspiciously like Nimda or some other worm at work here. If you still have access to the search tool, find any file that has the extension "eml" on your hard drive. In other words, type in "*.eml" w/o quotes into the search bar. If you get a ton of them, then it means that you most likely have Nimda or a similar worm infecting your computer.

Either way, by now your system is most likely unrecoverable. If it is a worm, then you'll have to format. Hell, run fdisk and fry your partitions just to be safe.

When I discovered a worm on my network (nimda32 version E), I lost one computer's contents and my whole network got infected. The other computers recovered though.
-Luke
User avatar
EmperorMing
Sith Devotee
Posts: 3432
Joined: 2002-09-09 05:08am
Location: The Lizard Lounge

Post by EmperorMing »

This bug just shut down one client network, and a big one at that. Exchange servers, produciton servers, you name it...
Image

DILLIGAF: Does It Look Like I Give A Fuck

Kill your God!
User avatar
TrailerParkJawa
Sith Acolyte
Posts: 5850
Joined: 2002-07-04 11:49pm
Location: San Jose, California

Post by TrailerParkJawa »

I should have d/l 'd the update but I have not run it yet. Im behind a firewall and sometimes a router using NAT. I should check my logs to see if anyone is probing. I just got DSL moved to this house about a week ago. Whats cool is even though Im in a different county I got to retain the same static IP.
MEMBER of the Anti-PETA Anti-Facist LEAGUE
User avatar
lukexcom
Padawan Learner
Posts: 365
Joined: 2003-01-04 03:49am
Location: Ah, Northern Virginia. The lone island of stability in an ocean of recession.
Contact:

Post by lukexcom »

EmperorMing wrote:This bug just shut down one client network, and a big one at that. Exchange servers, produciton servers, you name it...
Time to bring out the heavy artillery: Skynet. I'm looking forward to 6:18 PM tommorow. (dons NBC suit and waits) :twisted:
-Luke
User avatar
phongn
Rebel Leader
Posts: 18487
Joined: 2002-07-03 11:11pm

Post by phongn »

EmperorMing wrote:This bug just shut down one client network, and a big one at that. Exchange servers, produciton servers, you name it...
Ugh. Apparently if you get infected with this thing, RPC goes down and takes down much of Windows with it - patch or no patch.
User avatar
Vertigo1
Defender of the Night
Posts: 4720
Joined: 2002-08-12 12:47am
Location: Tennessee, USA
Contact:

Post by Vertigo1 »

You know what's great? The "fix" that Microsoft released DOESN'T work! I'm in still in the process of reloading everything because of it. :mad: I had to download 40MB of updates because the frelling Windows Update deletes the temp files it creates! (extremely annoying) As soon as I finish this post, I'm locking down every port with the exception of those that I need. (Good thing all the fucker did was keep my comp from loading explorer.exe. I could still use IE to access Windows Explorer to backup my data, after I scanned my machine from safe mode.)

This asshole better pray that I don't find out where he/she lives. If I do.....GALLAGHER SMASH TIME! :evil:
"I once asked Rebecca to sing Happy Birthday to me during sex. That was funny, especially since I timed my thrusts to sync up with the words. And yes, it was my birthday." - Darth Wong

Leader of the SD.Net Gargoyle Clan | Spacebattles Firstone | Twitter
User avatar
His Divine Shadow
Commence Primary Ignition
Posts: 12791
Joined: 2002-07-03 07:22am
Location: Finland, west coast

Post by His Divine Shadow »

What do you mean doesn't work?
Mine seemed to work.
Those who beat their swords into plowshares will plow for those who did not.
User avatar
Vertigo1
Defender of the Night
Posts: 4720
Joined: 2002-08-12 12:47am
Location: Tennessee, USA
Contact:

Post by Vertigo1 »

His Divine Shadow wrote:What do you mean doesn't work?
Umm....as in it failed to prevent what it was supposed to fix in the first place!

Now if you'll excuse me, I've got some games to re-install.

*pops in Freespace 2 CD*
"I once asked Rebecca to sing Happy Birthday to me during sex. That was funny, especially since I timed my thrusts to sync up with the words. And yes, it was my birthday." - Darth Wong

Leader of the SD.Net Gargoyle Clan | Spacebattles Firstone | Twitter
User avatar
Faram
Bastard Operator from Hell
Posts: 5271
Joined: 2002-07-04 07:39am
Location: Fighting Polarbears

Post by Faram »

Old update.

Here is a good read about it. Linky MS

Futher down in that text there is a DL location for the patch.
[img=right]http://hem.bredband.net/b217293/warsaban.gif[/img]

"Either God wants to abolish evil, and cannot; or he can, but does not want to. ... If he wants to, but cannot, he is impotent. If he can, but does not want to, he is wicked. ... If, as they say, God can abolish evil, and God really wants to do it, why is there evil in the world?" -Epicurus


Fear is the mother of all gods.

Nature does all things spontaneously, by herself, without the meddling of the gods. -Lucretius
User avatar
Hethrir
Jedi Master
Posts: 1095
Joined: 2003-03-25 05:37am
Location: Brisbane, Australia
Contact:

Post by Hethrir »

heh heh, and now MS Blaster takes advantage of the exploit. Symantec link here... http://securityresponse.symantec.com/av ... .worm.html
User avatar
phongn
Rebel Leader
Posts: 18487
Joined: 2002-07-03 11:11pm

Post by phongn »

Vertigo1 wrote:You know what's great? The "fix" that Microsoft released DOESN'T work! I'm in still in the process of reloading everything because of it. :mad: I had to download 40MB of updates because the frelling Windows Update deletes the temp files it creates! (extremely annoying) As soon as I finish this post, I'm locking down every port with the exception of those that I need. (Good thing all the fucker did was keep my comp from loading explorer.exe. I could still use IE to access Windows Explorer to backup my data, after I scanned my machine from safe mode.)
Did you clear out MSBLAST first? Even when you install the patch you still have to nuke it, and you need to firewall your box.
User avatar
Vertigo1
Defender of the Night
Posts: 4720
Joined: 2002-08-12 12:47am
Location: Tennessee, USA
Contact:

Post by Vertigo1 »

phongn wrote:
Vertigo1 wrote:You know what's great? The "fix" that Microsoft released DOESN'T work! I'm in still in the process of reloading everything because of it. :mad: I had to download 40MB of updates because the frelling Windows Update deletes the temp files it creates! (extremely annoying) As soon as I finish this post, I'm locking down every port with the exception of those that I need. (Good thing all the fucker did was keep my comp from loading explorer.exe. I could still use IE to access Windows Explorer to backup my data, after I scanned my machine from safe mode.)
Did you clear out MSBLAST first? Even when you install the patch you still have to nuke it, and you need to firewall your box.
Oddly enough, it is firewalled. However, I just started using a new software firewall at the time, and hadn't finished setting up the rules. (Went from AtGuard 3.22 to Norton's PF, which is just an upgraded version of Atguard that got n00bified. I'm only using this until I find something better.)
"I once asked Rebecca to sing Happy Birthday to me during sex. That was funny, especially since I timed my thrusts to sync up with the words. And yes, it was my birthday." - Darth Wong

Leader of the SD.Net Gargoyle Clan | Spacebattles Firstone | Twitter
User avatar
Uraniun235
Emperor's Hand
Posts: 13772
Joined: 2002-09-12 12:47am
Location: OREGON
Contact:

Post by Uraniun235 »

Long since patched.
Apparently if you get infected with this thing
It's not a specific "bug"... it's an exploit in the RPC service. A lot of tools out there right now that take advantage of it have a tendency to crash RPC while they're doing it and hence the 60-second "Windows will restart now" countdown.

BUT, sometimes they get in without crashing RPC... and then they have complete, total, unrestricted access to your computer, with all the rights of SYSTEM.

Then they can do as they please. Infect you with viruses, look at your files, plant trojans on your system... there's going to be some massive DDOS attacks stemming from this, I'm sure, because a lot of people will just patch and not clean their system of viruses. I've heard there's already one supposedly going to happen against the Windows Update website (which should be known by heart to any Windows user) on the 16th or something like that.
User avatar
Trytostaydead
Sith Marauder
Posts: 3690
Joined: 2003-01-28 09:34pm

Post by Trytostaydead »

You know what this is.. right?

SKYNET IS TRYING TO TAKE OVER THE WORLD!!

Damn, actually now that I'm talking to my friends and such.. it seems like a lot of people, those security patches Microsoft put up really fucked with their computers as well. What's going on?
User avatar
phongn
Rebel Leader
Posts: 18487
Joined: 2002-07-03 11:11pm

Post by phongn »

Correct. Infected computers will execute a DOS attack on WindowsUpdate on the 16th.
User avatar
Uraniun235
Emperor's Hand
Posts: 13772
Joined: 2002-09-12 12:47am
Location: OREGON
Contact:

Post by Uraniun235 »

phongn wrote:
otter wrote:I've been meaning to install a firewall. Can anyone make some good recommendations?
W2K and WXP have a built-in firewall. Kerio is a good solution if you want to block outgoing stuff.
God, I took two years of high school classes involving Windows 2000, I feel like such a fool... where do I find the W2K firewall? :oops:
User avatar
phongn
Rebel Leader
Posts: 18487
Joined: 2002-07-03 11:11pm

Post by phongn »

Go into your Network Connections and open up the relevant one. Fire up the properties and go into TCP/IP properties. Head into Advanced, then into the Options tab. TCP/IP Filtering (IPSEC) should be there.
Post Reply