Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

W32 Blaster Worm
http://www.cert.org/advisories/CA-2003-20.html ^ | CERT

Posted on 08/12/2003 11:30:56 AM PDT by dfrussell

This thing seems to be spreading quite quickly. If you're using MS and haven't verified your system, you should.

If you're not using a firewall, you should.

http://www.sygate.com will allow you to download and install a personal firewall -- it's easy to install.

Internet Security Systems (http://www.iss.net) has released a scan tool to check for the MS03-026 patch on Windows servers.

Location:

http://www.iss.net/support/product_utilities/ms03-026rpc.php


TOPICS: News/Current Events; Technical
KEYWORDS: lovesan; mdm; ms; w32blasterworm; worm
Navigation: use the links below to view more comments.
first 1-2021-4041-6061-80 next last

1 posted on 08/12/2003 11:30:57 AM PDT by dfrussell
[ Post Reply | Private Reply | View Replies]

To: dfrussell
It's a nasty one. Doesn't move via e-mails, can actually move from one computer to another on it's own once it has found a vulnerable pc through the net.
2 posted on 08/12/2003 11:35:16 AM PDT by Bikers4Bush
[ Post Reply | Private Reply | To 1 | View Replies]

To: Bikers4Bush
Does this specific virus affect windows ME operating systems?
3 posted on 08/12/2003 11:38:32 AM PDT by Joe Hadenuf (1)
[ Post Reply | Private Reply | To 2 | View Replies]

To: dfrussell
And if you are a network administrator and you let this worm get through, you should start looking for another job.
4 posted on 08/12/2003 11:40:09 AM PDT by dfwgator
[ Post Reply | Private Reply | To 1 | View Replies]

To: Joe Hadenuf
From what I know it doesn't. It was supposedly designed to specifically attack XP.

It couldn't hurt to check at the Microsquash website though.

5 posted on 08/12/2003 11:41:02 AM PDT by Bikers4Bush
[ Post Reply | Private Reply | To 3 | View Replies]

To: dfrussell
bump for later reading.
6 posted on 08/12/2003 11:41:23 AM PDT by EagleMamaMT
[ Post Reply | Private Reply | To 1 | View Replies]

To: dfwgator
The wonderful little bastard also seems to like the tftp service as a weak port.

We're covered at our location, but our morthship just got nailed with this thing a few hours ago. Thank God for firewalls.

-Proud firewall admin watching the lava break against my defenses.

7 posted on 08/12/2003 11:43:22 AM PDT by Centurion2000 (We are crushing our enemies, seeing him driven before us and hearing the lamentations of the liberal)
[ Post Reply | Private Reply | To 4 | View Replies]

To: dfwgator
Maybe, maybe not. It's possible that it's being introduced from laptops that have been used offsite and then brought back to docking stations.

It's easy to tell folks to makes sure they load updates of virus scan programs, getting them to comply is another story.
8 posted on 08/12/2003 11:45:17 AM PDT by Bikers4Bush
[ Post Reply | Private Reply | To 4 | View Replies]

To: dfrussell
SurferBeware
9 posted on 08/12/2003 11:46:01 AM PDT by StatesEnemy
[ Post Reply | Private Reply | To 1 | View Replies]

To: Joe Hadenuf
No
10 posted on 08/12/2003 11:46:58 AM PDT by antivenom (BEING OFFENDED means never having to answer an argument)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Bikers4Bush
People don't do their microsoft updates...that was the fix available since mid July...
11 posted on 08/12/2003 11:49:01 AM PDT by antivenom (BEING OFFENDED means never having to answer an argument)
[ Post Reply | Private Reply | To 8 | View Replies]

To: dfrussell
Microsoft Security Bulletin MS03-026

http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-026.asp

Explanation of virus:
http://securityresponse.symantec.com/avcenter/venc/data/w32.blaster.worm.html


Removal tool:
http://securityresponse.symantec.com/avcenter/venc/data/w32.blaster.worm.removal.tool.html
12 posted on 08/12/2003 11:51:42 AM PDT by FAB
[ Post Reply | Private Reply | To 1 | View Replies]

To: antivenom
That too.
13 posted on 08/12/2003 11:52:17 AM PDT by Bikers4Bush
[ Post Reply | Private Reply | To 11 | View Replies]

To: Bikers4Bush
It's easy to tell folks to makes sure they load updates of virus scan programs, getting them to comply is another story.

I think firing a few of them for negligence will take care of that problem.

14 posted on 08/12/2003 11:53:56 AM PDT by dfwgator
[ Post Reply | Private Reply | To 8 | View Replies]

To: dfrussell
I got this from our ISP this morning -

Early yesterday afternoon, a worm began spreading throughout the Internet. This worm, called the RPC worm causes infected computers running Windows 4.0, NT, 2000 or XP to reboot spontaneously. This worm is not spread through e-mail, but is a flaw in the Microsoft RPC code.

If your system is infected with the worm, you will get an error message like the following:

The system is shutting down. Please save all work in progress and log off. Any unsaved changes will be lost. This shutdown was initiated by NT AUTHORITY\SYSTEM. Time before shutdown: (counts down from 60 sec to 0). Windows must now restart because the Remote Procedure Call RPC) Service terminated unexpectedly.

You can find troubleshooting steps to rid your system of the worm posted at: http://www.trueband.net/msblast.html

15 posted on 08/12/2003 11:54:25 AM PDT by Maigret
[ Post Reply | Private Reply | To 1 | View Replies]

To: dfwgator
Now THAT would make a statement.

Unfortunately that would require blasting our entire sales force.
16 posted on 08/12/2003 11:55:12 AM PDT by Bikers4Bush
[ Post Reply | Private Reply | To 14 | View Replies]

To: FAB
BTTT
17 posted on 08/12/2003 11:55:47 AM PDT by b4its2late (Why is it that most nudists are people you don't want to see naked?)
[ Post Reply | Private Reply | To 12 | View Replies]

To: FAB
Bump
18 posted on 08/12/2003 11:56:08 AM PDT by ErnBatavia (40 miles inland, California becomes Flyover Country!)
[ Post Reply | Private Reply | To 12 | View Replies]

To: dfrussell
Quick question for simpletons like me.....

How does one go about finding out if ones system has been infected?
19 posted on 08/12/2003 11:56:15 AM PDT by OXENinFLA
[ Post Reply | Private Reply | To 1 | View Replies]

To: Bikers4Bush
Well I did say to only fire a few just to send a message.
20 posted on 08/12/2003 11:57:17 AM PDT by dfwgator
[ Post Reply | Private Reply | To 16 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-6061-80 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson