Got Blasted?!

This forum is for actual topics of discussion that do not fit the above categories.
Locked
danielwang
Village Idiot
Joined: Fri May 03, 2002 12:17 am
Location: Denver, CO Banned: Several times!
Contact:
Org Profile

Got Blasted?!

Post by danielwang » Sat Aug 16, 2003 1:15 am

It seems I've found the source of my hardware woes... they happened to coincide with A Not To Be Named Worm and I thought it was me... how silly...

Got blasted?

The blaster worm?

You know, WinXP?

If you don't know what I mean by those non-sentecned and you run XP, you need to install the latest hotfix and enable Firewall.

Instead of getting infected, thank bofh, the newer Dot Net Gundam builds recover the thread... but that leaves some dependent services hanging and Svchost initiates a 60-second shutdown.exe (this is changeable in MMC). You may recieved this message:
Windows .NET, Generic Patch wrote: The system is shutting down. Please save all your work and log off. Any unsaved changes will be lost. This shutdown was initiated by NT AUTHORITY\SYSTEM. Shutdown will begin in 60 seconds. Shutdown message: Windows must now restart because the remote Procedure Call (RPC) service terminated unexpectedly.
If you have installed a korean RPG such as Fagnarok Online, Project Farkturus, Priston Tale, or any other similar app, you are not affected.
Just open up Priston Tale etc and it'll start "nProtect"... start firewall, scan for the virus and of course defrag your hard drive and call your mom... annoying software.
<a href="http://www.animetheory.com/" title="AnimeTheory" class="gensmall">AnimeTheory.</a>
<a href="http://www.animemusicvideos.org/search/ ... %20park%22" title="Seach videos NOT by danielwang" class="gen">Make sure you don't download videos that suck!</a>

danielwang
Village Idiot
Joined: Fri May 03, 2002 12:17 am
Location: Denver, CO Banned: Several times!
Contact:
Org Profile

Post by danielwang » Sat Aug 16, 2003 1:21 am

I'm running the basic firewall off of RRAS now like MS suggested, but I'm having problems with non-established connections to random ports. I'm going to either have to type in an entire port range, exclude a huge block of IPs, or more likely figure out how to get IP Fitering to work on dialup.

The patch refuses to install, Windows Update says no updates...
<a href="http://www.animetheory.com/" title="AnimeTheory" class="gensmall">AnimeTheory.</a>
<a href="http://www.animemusicvideos.org/search/ ... %20park%22" title="Seach videos NOT by danielwang" class="gen">Make sure you don't download videos that suck!</a>

User avatar
Jebadia
Joined: Fri Jun 01, 2001 8:54 pm
Location: Parkersburg, WV
Contact:
Org Profile

Post by Jebadia » Sat Aug 16, 2003 1:59 am

Son...I run win98...it don't touch this shit..

the blaster worm became almost harmless 36 hours after it was found out. though it kicked a lot of ass within that time. Every anti-virus and security company should have it under control by now.

For those who missed out on the news about it:

Brief Description

Blaster is a worm that infects only Windows 2003/XP/2000/NT computers. Blaster exploits the Buffer Overrun in RPC Interface vulnerability to spread to as many computers as possible.

Blaster launches denial of service (DoS) attacks against the windowsupdate.com website. Whenever the system date is between August 16 and December 31, 2003, Blaster sends a 40 byte packet every 20 milliseconds, using the TCP port 80.

Blaster spreads by attacking IP addresses generated at random and exploits the vulnerability takes advantage of the exploit mentioned above to download a copy of itself to the compromised computer a copy of itself. In order to do this, Blaster incorporates its own TFTP (Trivial File Transfer Protocol) server.


Visible Symptoms

Some clear indications that Blaster has reached the computer are the following:

The network traffic increases on the TCP 135 and 4444 and UDP 69 ports.
The attacked computer blocks and restarts, due to programming errors in the code of the worm.
"If you believe in yourself, eat all your school, stay on milk, drink your teeth, don't do sleep, and get your eight hours of drugs, you can get WORK!"
Paperskunk:...PENIS!!!!!!!!! GIANT PENIS!!!!!!!!!! ERMAC WHAT HAVE YOU DONE!!!!!!!! GIANT JUICY PENIS!!!!!!!!! AHHHHHHHHH MY EYES!!!!!!

danielwang
Village Idiot
Joined: Fri May 03, 2002 12:17 am
Location: Denver, CO Banned: Several times!
Contact:
Org Profile

Post by danielwang » Sat Aug 16, 2003 2:37 am

Jebadia wrote:Son...I run win98...it don't touch this shit..
So it's an inane post. but:

I Wasted Hours Fixing This Issue!
<a href="http://www.animetheory.com/" title="AnimeTheory" class="gensmall">AnimeTheory.</a>
<a href="http://www.animemusicvideos.org/search/ ... %20park%22" title="Seach videos NOT by danielwang" class="gen">Make sure you don't download videos that suck!</a>

User avatar
Jebadia
Joined: Fri Jun 01, 2001 8:54 pm
Location: Parkersburg, WV
Contact:
Org Profile

Post by Jebadia » Sat Aug 16, 2003 2:59 am

then my job here is done...
"If you believe in yourself, eat all your school, stay on milk, drink your teeth, don't do sleep, and get your eight hours of drugs, you can get WORK!"
Paperskunk:...PENIS!!!!!!!!! GIANT PENIS!!!!!!!!!! ERMAC WHAT HAVE YOU DONE!!!!!!!! GIANT JUICY PENIS!!!!!!!!! AHHHHHHHHH MY EYES!!!!!!

User avatar
AbsoluteDestiny
Joined: Wed Aug 15, 2001 1:56 pm
Location: Oxford, UK
Contact:
Org Profile

Post by AbsoluteDestiny » Sat Aug 16, 2003 4:16 am

danielwang wrote:
Jebadia wrote:Son...I run win98...it don't touch this shit..
So it's an inane post. but:

I Wasted Hours Fixing This Issue!
That will teach you to regularly download the security updates, then. The patch for it was available a month before the worm actually spread.

User avatar
Stoic
Joined: Fri Feb 14, 2003 12:23 am
Location: Land Of Confusion
Org Profile

Post by Stoic » Sat Aug 16, 2003 4:43 am

I use a Free Firewall and a Free Virus Scanner and they both seem to be very effective against this worm. :)
"More than hundred fucking takes." - Jackie Chan.
Murphy's Law of Combat Number 6:
If it's stupid but it works, it isn't stupid.
My Profile::Your Profile

User avatar
Warpwind
Joined: Mon Oct 07, 2002 4:19 am
Location: middle of the desert
Contact:
Org Profile

Post by Warpwind » Sat Aug 16, 2003 5:49 am

My firewall seems to be doing a decent job as well since I haven't got the worm... but that could just be luck.

Still two of my friends got the thing and came running to me for help since I'm mildly computer literate. So I in turn ran to a friend of my brother who already had the fix and patch. At the moment I feel like a courier service :wink:

It's not that bad a virus since it doesn't do any permanent damage still someone might rewrite the code and make it into a real monster. At the moment it's just time consuming.

Locked

Return to “General Off Topic”