Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

New Virus hitting hard and furious!!!
http://www.symantec.com/avcenter/venc/data/w32.blaster.worm.html ^ | 08/11/03 | self

Posted on 08/11/2003 2:33:46 PM PDT by STFrancis

All,

Here a scoop to Freepers which is just now hitting us security pro's.

There is a first vulnerability that uses the MS Bug that MS addressed with MS 03-026 two weeks ago.

It is calling itself MSBLAST.exe and is spreading in the wild unbelievably fast. http://isc.sans.org/diary.html?date=2003-08-11

A first advisory from McAffee has just been published: http://us.mcafee.com/virusInfo/defa...&virus_k=100547 Once it finds a vulnerable system, it will spawn a shell on port 4444 and use it to download the actual worm via tftp. The exploit itself is very close to 'dcom.c' and so far appears to use the "universal Win2k" offset only.

In other words we need to make sure port 4444 is blocked inbound AND outbound.

Of course this is in addition to the MS03-026 patch being installed which Microsoft released two weeks ago (more info regarding the patch here: http://www.microsoft.com/technet/tr...n/MS03-026.asp.

Another advisory was JUST posted by Symantec: http://www.symantec.com/avcenter/ve...aster.worm.html

Just thought everyone ought to know.

Thanks...


TOPICS: Breaking News; News/Current Events; Technical
KEYWORDS: blaster; computer; firewall; internet; macuserlist; microsoft; msblast; techindex; virus; vulnerability; worm
Navigation: use the links below to view more comments.
first previous 1-20 ... 181-200201-220221-240 ... 301-308 next last
To: MrsEmmaPeel
"The flaw, discovered by an anonymous Canadian security researcher who uses the nickname "Null,"

Not me, BTW...

201 posted on 08/12/2003 7:01:21 AM PDT by null and void
[ Post Reply | Private Reply | To 191 | View Replies]

bookmark
202 posted on 08/12/2003 7:04:10 AM PDT by lonevoice
[ Post Reply | Private Reply | To 200 | View Replies]

To: Salo
I keep all of my systems patched up.

There was a hole in Mac OS X for a year - patches had no affect -- that was the point I was trying to make. Apple adopts UNIX then ignores security issues that come with UNIX. Apple will regularly say: "We're not affected" when in fact they are. THAT is a big problem- one of attitude. There is a myth that Apples are invulnerable. How can that be, when UNIX is not? I've had personal experience with this. Apple may make good computers, but they just don't know UNIX.

203 posted on 08/12/2003 7:12:11 AM PDT by MrsEmmaPeel
[ Post Reply | Private Reply | To 199 | View Replies]

To: LynnHam
Well IF you didn't do a RUN -> Regedit...and do a Find on HKEY_LOCAL_MACHINE for Msblast.exe you are still a carrier...
204 posted on 08/12/2003 7:12:23 AM PDT by antivenom (BEING OFFENDED means never having to answer an argument)
[ Post Reply | Private Reply | To 17 | View Replies]

To: STFrancis
Hello

Could someone reply in here...I need some help

I read in the paper that Microsoft has a PATCH for this new virus.

I went to the web-site that it had listed...but I do not see thePATCH on there.

Could someone direct link me to where this patch is located and tell me what it says...in other words what I am looking for on that web page?

THanks ahead of time...

Please reply on this thread....not in private email or private message.

Thanks Ahead Of Time

Appreciate It....

205 posted on 08/12/2003 7:16:22 AM PDT by I_love_weather
[ Post Reply | Private Reply | To 1 | View Replies]

To: STFrancis
.45MAN's company hit in Atlanta. All of the computers at his company are infected. This is a very malicious code.
206 posted on 08/12/2003 7:21:31 AM PDT by dansangel (America - Love it, Support it or LEAVE it!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Maurice Tift
Check your registry to for msblast as well (do a regedit). I found this on my wife's laptop last night. The "help" desk at her job is inept, to say the least.
207 posted on 08/12/2003 7:22:27 AM PDT by rdb3 (I'm not a complete idiot. Several parts are missing.)
[ Post Reply | Private Reply | To 126 | View Replies]

To: kitkat
OK, if you do not have a real mouse, then CTRL-click on the image. I have always used thrid party mice, I can't stand the Apple supplied mouse. Having a laptop, kinda forces me to get a third party mouse, before anyone clones start mouthing off.
208 posted on 08/12/2003 7:22:37 AM PDT by SengirV
[ Post Reply | Private Reply | To 185 | View Replies]

To: rdb3
Do you happen to know what kind of virus software Compaq runs on their newest laptops? My niece has this virus and can't find her virus program.....duh.
209 posted on 08/12/2003 7:43:40 AM PDT by Howlin (If we don't post, will he exist?)
[ Post Reply | Private Reply | To 207 | View Replies]

To: Timesink
Needless to say, the "mainstream" news media has been universally reporting that the exploit affects "essentially all versions of Windows."

Aren't something like 30% of PC owners still running Win98? This sort of piss-poor journalism can cause these people a lot of grief as they run around looking for patches to their systems that are not needed and, indeed, do not exist.

IIRC, this exploit affects all versions of Windows dating back to Win95, except for Windows Millenium. I think they got it right this time, unless I'm thinking of one of the other dozens of remote exploits for Microsoft OSes.

210 posted on 08/12/2003 7:53:37 AM PDT by cashion
[ Post Reply | Private Reply | To 91 | View Replies]

To: I_love_weather
If you follow the steps in post #17 you'll be fine.
211 posted on 08/12/2003 7:53:55 AM PDT by Hoboken
[ Post Reply | Private Reply | To 205 | View Replies]

To: STFrancis
bump for home
212 posted on 08/12/2003 7:57:52 AM PDT by Born Conservative
[ Post Reply | Private Reply | To 1 | View Replies]

To: livius
What is services.msc? And where do I find it on my computer?

Thanks, Axel

213 posted on 08/12/2003 8:04:18 AM PDT by AxelPaulsenJr (Ozzy Osborne says that pot leads to harder drugs.)
[ Post Reply | Private Reply | To 78 | View Replies]

To: Howlin
Do you happen to know what kind of virus software Compaq runs on their newest laptops?

I have no idea, but I'm willing to bet it's McAfee.

214 posted on 08/12/2003 8:07:39 AM PDT by rdb3 (I'm not a complete idiot. Several parts are missing.)
[ Post Reply | Private Reply | To 209 | View Replies]

To: ironwill
I think I have it too ...

I have never had any thing before....

How do I rid my computer of this...

It has been automatically shutting off by its self all day yeaterday and through the nite...

Called Dell no help there...


HELP!!! what do I do?


215 posted on 08/12/2003 8:19:40 AM PDT by bellas_sister ((I love a man in a uniform))
[ Post Reply | Private Reply | To 13 | View Replies]

To: dansangel
It hit the school I work at too. It is nasty. We got the initial version of this at home when it was just a trojan and not a virus. I downloaded the patch and fix and everything was ok. Now someone mutated it and eek what a mess. I work at the help desk in our IT dept and we told everyone to update their Windows OS 2 weeks ago. The ones who did are fine, the ones who I guess thought we were not serious, well they are now waiting in line for the guys to go around and fix their machine.

I am a little ticked that our tech guys, especially our network guy, didn't catch this before it happened.

I just can't believe the speed at which this spread.
216 posted on 08/12/2003 8:26:54 AM PDT by eyespysomething (You've a loose screw. Can I tighten that for you?)
[ Post Reply | Private Reply | To 206 | View Replies]

To: STFrancis
I went to Microsoft to download the patch, but apparently I don't need it?? because I'm running Windows ME. At least there's SOMETHING good about Windows ME. Both my children are running XP in their computers, and both got the virus.
217 posted on 08/12/2003 8:29:54 AM PDT by Tuscaloosa Goldfinch
[ Post Reply | Private Reply | To 1 | View Replies]

To: AxelPaulsenJr
Here is a good description of services.msc: http://www.theeldergeek.com/services_guide.htm
218 posted on 08/12/2003 8:30:24 AM PDT by Born Conservative
[ Post Reply | Private Reply | To 213 | View Replies]

To: SengirV
While not descending the depths of schaenfraud, let me say that I'm in the same boat. Yet another windows virus? I have a mac. No probs!

219 posted on 08/12/2003 8:33:37 AM PDT by =Intervention= (White devils for Sharpton Central Florida chapter)
[ Post Reply | Private Reply | To 11 | View Replies]

To: MrsEmmaPeel
Of course Apple doesn't know UNIX -- they just make an OS that uses it...hmm. Your hyperbole and bias is showing.
220 posted on 08/12/2003 8:36:05 AM PDT by =Intervention= (White devils for Sharpton Central Florida chapter)
[ Post Reply | Private Reply | To 41 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-20 ... 181-200201-220221-240 ... 301-308 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson