Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Get that firewall up!
view: topics flat text 
Post a:

Comments on news posted 2003-08-11 19:30:36: It appears that a new worm (for now we're calling it msblast after its executable, msblast.exe) has surfaced today. ..

page: 1 · 2 · 3

Mike
Premium,Mod
join:2000-09-17
Pittsburgh, PA
clubs:
·Verizon FIOS
·Verizon Online DSL

Host:
Site Tools
W.O.W.
FairPoint
World of Warcraft
Alltel Axcess

Can someone port this to linux

said by article:

Based on analysis posted by users psloss and Steve in our security forum, this worm will start a DDOS attack against port 80/tcp (which is basically web) of windowsupdate.com on August 16th.
hmm.... I could get away with it if I do it on my own and blame it on the worm.. hmmm
[text was edited by author 2003-08-11 21:40:57]

Jeremy341
Bye
Premium
join:2000-01-06
localhost

Re: Can someone port this to linux

And you'd want to DDoS windowsupdate.com because...?

Thasp6
The Thasps Are Everywhere.
Premium
join:2003-06-08
Your Mind.

Re: Can someone port this to linux

said by Jeremy341 See Profile:
And you'd want to DDoS windowsupdate.com because...?
Who doesn't?

Jeremy341
Bye
Premium
join:2000-01-06
localhost

Re: Can someone port this to linux

said by Thasp6 See Profile:
Who doesn't?
Uh, me.
hubs187

join:2003-01-21
Lisle, IL


HELP!!!

i got hit by it this morning.....if ive already been infected is there anytihng i can do to get it out...or quarentined?.....i put up my built in windows firewall is that enough.....now how do i stop it form infecting other computers from mine? please respond i found the msblast.exe on my computer is deleting it enough.....?????then just keep my firewall up?
[text was edited by author 2003-08-11 22:08:23]

GoD of KaOs
Agent of KaOs

join:2001-01-29
Chatsworth, CA

Re: HELP!!!

I wouldn't rely on windows firewall, I would also get zonealarm.

P8ntball Guy

join:2003-08-10
Buffalo, NY

Router

So glad I bought the firewall router. Thank you Linksys.

Doctor Four
My other vehicle is a TARDIS
Premium
join:2000-09-05
Dallas, TX
·AT&T U-Verse

Worm may have hit where I work today

Around 1:00 PM Central time, several people where I work
began seeing random crashes and shutdowns of applications
we use regularly at work, and sometimes even parts of
Windows2000 itself. In some cases, people were unable to
log onto our primary production system, which is based on
Oracle. In other cases, it was Outlook2002 that seemed to
be associated with the crashes. I noticed on my work-
station a random crash of one of the svchost.exe processes,
and at that time I wondered if a new worm that exploited
the DCOM vulnerability had gotten loose in our network. A
few people also reported being unable to log into our time
entry system, which is located on a secure server. Having
read some of what other posters in this thread have
reported, I believe the answer to my question is yes. The
time frame in which this was occurring is consistent with
the flood of DCOM port probes logged by Zone Alarm on my
home PC. I patched my system here at home the Sunday
night after the Department of Homeland Security warning
was issued about this vulnerability. I have a feeling MIS
(our IT department) where I work has not done likewise.
--
"Kayura or Badamon, whichever you are, you should know that I will never give up this battle. By the will of the Ancient, I shall succeed!" - Shuten (Anubis) from the Ronin Warriors.

TobyB

@195.137.x.x

Re: Worm may have hit where I work today

I have been hit too. The worm file was called W32.Blaster acccording to Norton AV. I cleared the msblaster.exe file out of system32 with Norton but still have trouble with SVCHOST. SVCHOST.EXE now runs for about 2 minutes on a restart and then crashes out.

Apophis
Jaffa Kree
Premium
join:2001-12-27
Holmen, WI
clubs:

Re: Worm may have hit where I work today

said by TobyB:
I have been hit too. The worm file was called W32.Blaster acccording to Norton AV. I cleared the msblaster.exe file out of system32 with Norton but still have trouble with SVCHOST. SVCHOST.EXE now runs for about 2 minutes on a restart and then crashes out.
Hi, I also did what you did but in the end had to do a os-re install to get rid of the garbage.
--
Just say NO to Same-Sex Marriages, Affirmative Action, Liberals and PETA.Re-Elect George Bush 2004, The True Leader of this Country!!!
Haychance

join:2003-07-01
Lewisville, TX

way over my head

I have gotten about a billion friggin hits on 135 but since about 7:00pm central it's been hitting port 445 every 29th attempt. Somebody please tell me how long this mess is going to take. i have a pretty limited understanding of these things and I'm not sure if my firewall which is a Zone Alarm Pro that my friend installed, is idiot proof enough for me to keep from infecting my PC. What do I need to do in the simplest possible terms to protect my PC. I have been running extensive searches for the MSBLAST and any variations on that and haven't come up with anything yet, but my PC keeps shutting down.
bigbeartech
Goo?

join:2001-09-23
Saint Louis, MO

This started last night

A co-worker reported that a customer called in about this late last night. The issue did not dawn on him until today when we got hit by multiple calls about this.

FYI, your ISP does not support the operating system. The OEM, or if you built your computer, Microsoft does.
--
guycad: It may take you days and large clumps of hair to get it to work,CyberSchnook:I am so screwed--I haven't had large clumps of hair for years.
jimahrens

join:2002-05-30
Owego, NY

another virus

this one is so lame it cant get past a simple firewall
geeze...some other viruses at least offered a challenge...

Gundam_MX
Stomping Robot

join:2003-06-27

Windows NT family affected only

From what I understand Windows NT 4.0, Windows NT 4.0 Terminal Services Edition,Windows 2000, Windows XP and Windows Server 2003 are the only Windows OS affected by this worm.

Source

If you use Windows 95,98 and ME you're safe.

Of course if everybody used Linux in the first place, none of this would have happened!
cableblows3

join:2001-06-17
Indianapolis, IN

135

what else is 135 normally used for?

solarified
Premium
join:2002-11-02
Delafield, WI
clubs:

M$ does it again

Yet another MSTD unleashed. The thing that really irritates me is I still see an occasional Code Red hit. There are plenty of stupid admins and people who should not own servers out there. Another great exploit from sloppy code.

Defiance82
Computer Elite
Premium
join:2002-09-11
Reeds Spring, MO
clubs:
·Suddenlink

LOL

This bug never hit me. However it hit 6 of my friends PC's because they are total idiots for not running a Firewall or AntiVirus protection. People who do NOT run either are just asking to get screwed over and should! Common sense would tell you to protect your investments now wouldn't it?
--
My crime is that of outsmarting you, something that you will never forgive me for. I am a hacker, and this is my manifesto. You may stop this individual, but you can't stop us all... after all, we're all alike.
D31uSiOn

join:2003-07-29
Salinas, CA

Same Prob.

Wow.... My uncle and 2 of my friends got hit with it... They all called me, I was like wtf is going on? its MS blast, there is a way to kill it. first update with this shiz: »microsoft.com/downloads/details.···ylang=en then use »vil.nai.com/vil/stinger/ to kill the virus! G/L

CPUYODA

join:2003-01-25
Johnson City, TN

Re: Same Prob.

Ive disabled ZA logging for the duration....

Its gonna be a great week!!!!!

Cheers Beers and Tears!!
--
"In God We Trust,All Others Pay Cash"
ODYSSEY

join:2001-12-06
Raleigh, NC

Getting worst...

Getting about 100 hits on port 135 an hour. About 90% are from local RR users.

e144539

join:2000-11-02
San Angelo, TX
clubs:
·Verizon Online DSL

automatic updates

I don't understand why people don't have all the critical security patches applied when automatic updates has been around for a while now.
Do people just not take advantage of it?
--
Never attribute to malice that which can be adequately explained by stupidity.

Brat75
Cats rule

join:2003-02-05
Auburn, WA

Re: automatic updates

said by e144539 See Profile:
I don't understand why people don't have all the critical security patches applied when automatic updates has been around for a while now.
Do people just not take advantage of it?

Some of those patches screw your computer up further than it already is..
811493 ring a bell?

And most people want to have control over their computer's settings/applications. Like WMP9 sends info back to MS, I only keep WMP8.

I wait at least a week b4 installing a patch due to errors from a patch.

Brat
--
I sometimes feel that I'm playing hockey, and God wants to throw me a curveball.

e144539

join:2000-11-02
San Angelo, TX
clubs:
·Verizon Online DSL

So then some people trust crackers more than Microsoft?

I don't remember 811493 because I'm running Win2k, and I as far as I know none of the patches released for it has caused any problems.

You still have complete control over settings/applications.
You can set it so it just downloads updates and then asks you if you want to install them, and automatic updates only downloads critical updates. WMP9 is a recommended update, so Auto updates wouldn't even do anything with it. Furthermore, WMP9 doesn't send info back to MS if you uncheck the box under 'Customer Experience Improvement Program', and I believe it asks you if you would like to participate or not during the install.

I usually wait too, I try to access if the hole they're patching will really affect me, but it's nice too have automatic updates tell me when a patch is released so I don't have to go to Windows update all the time.
--
Never attribute to malice that which can be adequately explained by stupidity.
Phatty

join:2000-05-10
Valley Park, MO
·Vonage
·Charter Pipeline


Re: automatic updates

I wouldn't think people wanting to have more control over system or waiting to see if a patch messes up a system would be the reason the majority of the people do not enable those features. Those features are not enabled because most people do not pay attention to updates, or care about keeping there system properly patched and updated. For those who do not enable it for the reason of waiting, something like this would still probably never affect them because MS releases patches well before something like this spreads most of the time.
[text was edited by author 2003-08-12 14:38:23]
Bytezboy

join:2001-05-17
New York, NY

glad i'm protected

Man, I'm glad I had a D-Link firewall up. I just check my logs and I got a lot of hits for port 445, haven't seen port 137 yet on my logs... not sure if it's because I disabled logging of "dropped packets" but I did enable logging of "attacks".

aw3dhg

join:2001-09-05
Middletown, NY

fromCA about 20 minutes after I saw this article

Just got this from my av supplier they have renamed it apparently

Virus Alert Notification

Win32.Poza

Alias: W32.Blaster.Worm (Symantec) ,
W32/Lovsan.worm (McAfee),
W32/Msblast.A (F-Secure),
Win32/Poza.Worm ,
WORM_MSBLAST.A (Trend)
Category: Win32
Type: Worm
Published Date: 8/11/2003
Last Modified: 8/11/2003

CHARACTERISTICS

Win32.Poza is a worm using the exploit described in MS03-026 to gain access to unpatched Windows installation. More information about the exploit can be found in our Vulnerabilities Library or at the Microsoft site here: »www.microsoft.com/technet/securi···-026.asp

Method of Installation

It creates a mutex "BILLY" to avoid running multiple instances of itself, and creates a registry value to activate on Windows restart:

SOFTWARE\Microsoft\Windows\CurrentVersion\Run\windows auto update = "msblast.exe"

The worm runs a FTP service listening on port 69 waiting for exploited machine to connect.

Method of Distribution

It starts by scanning the entire subnet for open 135 ports, then moves on to scan randomly selected class B subnets (255.255.0.0) to start scanning. If an open 135 port is found, it uses the exploit mentioned above to gain entry and create a remote shell on the exploited machine. It then assumes the exploit succeeded and attempts to connect to port 4444 of the remote machine. If successfully connected, it instructs the remote machine to download MSBLAST.EXE (size: 6,176 bytes, UPX packed) from its FTP service using TFTP.EXE. It then sends an instruction to start MSBLAST.EXE on the remote machine.

Note: TFTP.EXE is an utility included by default in Windows installation of Windows 2000 and later versions.

The worm is capable of keeping live connections to 20 exploited machines simultaneously.

Payload

If the day of the month is 16 or later, or the month is between January and August, the worm creates a working thread to send random data to windowsupdate.com almost continuously. This effectively launches a Distributed Denial of Service attack against windowsupdate.com.

Additional Information

The worm body contains these strings:

I just want to say LOVE YOU SAN!!
billy gates why do you make this possible ? Stop making money and fix your software!!

CA has also received reports from several sources that this worm may be seen, associated with crashes of svchost.exe.

For more information about Win32.Poza worm click here.

To obtain the latest EZ Antivirus Signature files directly from your pc follow the easy steps below for your specific version number:

Product Versions 5.3 and 5.4 - Signature file Version 2554

Product Version 6.0 - Signature file Version 4828

Product Version 6.1 - Signature file Version 4828

For instructions on how to autodownload or download signature files manually click here

Unsure of your product version number?

To find your product version number, right click on the eTrust EZ Antivirus taskbar icon and select "Version". Your product version number will be presented in a pop-up box on your screen.

Please remember that these signature file updates are cumulative: therefore the latest update includes everything from all previous updates as well as the new virus information.

--------------------------------------------------------------------------------

Additional Information on viruses, worms, and trojans can be found in our virus encyclopedia: »www.my-eTrust.com/products/encyclopedia and on our Virus Alerts page: »www.my-eTrust.com/products/virusalerts

fancydancer
Perception is reality
Premium
join:2002-08-28
Springfield, IL
clubs:
·Comcast
·Insight Communicat..

Check it out Yo!

Uh, yeah, like mentioned above, this isn't new. Anyone with a HSI connection should of gotten this critical update, I will be more lenient towards dial up users (but that's still no excuse). Everyone needs to make time to do a Windows Update every once in awhile. And if you're the lazy type configure your Automatic updates to download and install in the middle of the night (3am is default). But, if you did fall prey to this nasty exploit, help is here at the link below. Includes removal instructions as well.

»securityresponse.symantec.com/av···orm.html
--
MCSE- Minesweeper Consultant Solitaire Expert

nil
Java Geek
join:2000-11-27

Host:
Webmasters and Dev..
Forum Feature Requ..

Re: Check it out Yo!

They published this information less than a month ago.. people who do not make it a habit to read geek-websites (that would be 95% of the population) probably have no idea this vulnerability exists.

It's nice to want to blame this on the users.. but no.. it's not their fault the software they paid good money for is full of security holes. Perhaps the multi-billion dollar company that insists on releasing software before it's fully white-box tested has something to do with it.
--
Life is too short to be boring

fancydancer
Perception is reality
Premium
join:2002-08-28
Springfield, IL
clubs:
·Comcast
·Insight Communicat..

Re: Check it out Yo!

That's why everything is becoming so automated anymore. Look at online-bill pay. You don't even have to write checks, or mail them out. Convenience is the key. What I'm getting at is that you can keep your security holes filled without much effort or knowledge.
said by nil See Profile:
it's not their fault the software they paid good money for is full of security holes. Perhaps the multi-billion dollar company that insists on releasing software before it's fully white-box tested has something to do with it.
Good point, I agree. But the patch was available before it became a large problem. Available through windowsupdate, which is only a click of a mouse away.
--
MCSE- Minesweeper Consultant Solitaire Expert

nanofever
Liberal Democrats, You Know We're Right

join:2001-08-19
Modesto, CA

No worries

Got the worm, ZAP told me I had the worm, Cleaned the worm, life is good...

seifertim

join:2003-05-30
Valley Park, MO

Detection

Hmm... so what should I look for to diagnose my pc if I don't notice any random shut-downs? I have Norton, and I have a router, but not too sure that I am clean and free... are there certain files I can/should look for, or just try and run "Lions" techniques if I notice something screwy (which doesn't give me a lot to go on, after my wife's been on the computer, there isn't anything that's not screwy!)

inciter
Noobie
Premium
join:2000-08-30
Rohnert Park, CA

Two words Steve Gibson

»https://grc.com/

[text was edited by author 2003-08-12 01:54:38]

machater

join:2003-04-30
Turlock, CA

this will end this

If you create and release a virus/trojan...etc, you go to jail for life, if you hack a public or private commercial or government institution/business you go to jail for 10 years, $25,000 fine for first attempt, life imprisonment for the second offense. This type of punishment will GREATLY reduce this increase in stupidity.
Forums » Get that firewall up!page: 1 · 2 · 3


Sunday, 29-Nov 03:24:13 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF