Emuforums.com

Go Back   Emuforums.com > General Discussion > Software Discussion
About Us Register FAQ Members List Calendar Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
Old September 18th, 2003   #1 (permalink)
:3
 
Yeloazndevil's Avatar
 
Join Date: Jul 2002
Posts: 10,147
Exclamation Blaster Worm 2!

Quote:
Security researchers yesterday detected hackers distributing software to break into computers using flaws announced last week in some versions of Microsoft Corp.'s Windows operating system. The threat from this new vulnerability -- which already has drawn stern warnings from the Homeland Security Department -- is remarkably similar to one that allowed the Blaster virus to infect hundreds of thousands of computers last month.

Researchers from iDefense Inc. of Reston, Va., who found the new attack software being distributed from a Chinese Web site, said it already was being used to break into vulnerable computers and implant eavesdropping programs. They said they expect widespread attacks similar to the Blaster infection within days.

Microsoft confirmed last night it was studying the new attack tool.
source: Neowin
Quote:
Remote Procedure Call (RPC) is a protocol used by the Windows operating system. RPC provides an inter-process communication mechanism that allows a program running on one computer to seamlessly access services on another computer. The protocol itself is derived from the Open Software Foundation (OSF) RPC protocol, but with the addition of some Microsoft specific extensions.

There are three identified vulnerabilities in the part of RPCSS Service that deals with RPC messages for DCOM activation— two that could allow arbitrary code execution and one that could result in a denial of service. The flaws result from incorrect handling of malformed messages. These particular vulnerabilities affect the Distributed Component Object Model (DCOM) interface within the RPCSS Service. This interface handles DCOM object activation requests that are sent from one machine to another.
get the patch here

I knew this was coming oh yea this only affects NT based OS's
Yeloazndevil is offline   Reply With Quote
Old September 18th, 2003   #2 (permalink)
Registered User
 
gamezonline's Avatar
 
Join Date: Apr 2002
Posts: 212
here we go again, thx for the update
__________________
Abit Motherboard w/800 FSB
P4 3.4 w/HT 1mb L2 @ 4.0
GeForce FX 5700 Ultra
Emprex 8x DVD+-RW
250gig Maxter HD
80gig Maxter HD
1 Gig DDR 3700
SB Live
gamezonline is offline   Reply With Quote
Old September 19th, 2003   #3 (permalink)
Registered User
 
scottlc's Avatar
 
Join Date: Sep 2002
Location: St Andrews, Scotland
Posts: 1,575
Re: Blaster Worm 2!

Just use DCOMbobulator. It turns off the unnecessary DCOM service and protects you against all current (and future) DCOM exploits. Get it from:

http://grc.com/
__________________
OS: Arch Linux w/ Kernel 2.6.23.8 + GNOME 2.20.1 - CPU: Intel Pentium M 1.5GHz - Memory: 1280MB DDR PC2700 - Browser: Mozilla Firefox 2.0.0.10
scottlc is offline   Reply With Quote
Old September 19th, 2003   #4 (permalink)
:3
 
Yeloazndevil's Avatar
 
Join Date: Jul 2002
Posts: 10,147
Re: Blaster Worm 2!

um no, don't like that program
Yeloazndevil is offline   Reply With Quote
Old September 20th, 2003   #5 (permalink)
General of Tangerines
 
RZetlin's Avatar
 
Join Date: Jun 2001
Location: Defending the Sea
Posts: 3,885
Re: Blaster Worm 2!

Quote:
Originally Posted by scott_uk5
Just use DCOMbobulator. It turns off the unnecessary DCOM service and protects you against all current (and future) DCOM exploits. Get it from:

http://grc.com/
I just ran the test. My port is closed shut.
__________________


AMD Athlon 64 3700+ | 2 GB RAM | XFX Nvidia 6800 GS 256 MB XXX Edition | Win XP Pro SP2
RZetlin is offline   Reply With Quote
Old September 20th, 2003   #6 (permalink)
RF
Canadian Spaceman
 
RF's Avatar
 
Join Date: May 2002
Location: Canada
Posts: 8,594
Re: Blaster Worm 2!

What does it mean when my ports are "stealth" 'd?

edit:

Quote:
If your system is unprotected, without any personal firewall or NAT router, any ports showing as stealth are being blocked somewhere between your computer and the public Internet. This is probably being done by your ISP. Internet traffic directed to your computer at the stealth ports will be dropped before reaching your machine.
nm
__________________
RF is offline   Reply With Quote
Old September 21st, 2003   #7 (permalink)
Ada...
 
Phoenix's Avatar
 
Join Date: Jan 2002
Location: GDL, MX
Posts: 2,229
Re: Blaster Worm 2!

easy as this, open your registry and do the following:

System Key: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole]
Value Name: EnableDCOM
Data Type: REG_SZ (String Value)
Value Data: "Y" = enabled, "N" = disabled

that is exactly what grc.com's DCOMBobulator does I guess, disabling via the registry such service besides testing the vulnerability, the port 135 and such.

It's safer installing those patches and disabling the service if you're not using it.

I find handy Steve Gibson's programs.
Phoenix is offline   Reply With Quote
Old September 21st, 2003   #8 (permalink)
Banned
 
Join Date: Apr 2002
Location: From Kuching in Malaysia now stuck in Houston Texas
Posts: 9,110
Re: Blaster Worm 2!

Why don't they just disable RPC by default
Player-X is offline   Reply With Quote
Old September 21st, 2003   #9 (permalink)
Has an extra GOTO 10 Line
 
Quark's Avatar
 
Join Date: Dec 2001
Posts: 250
Re: Blaster Worm 2!

Quote:
Originally Posted by Player-X
Why don't they just disable RPC by default
Actually, DCOM. RPC is quite necessary for XP/2000, but DCOM is just a part of it that's not.

And disabling it would be smart, something microsoft is not.
Quark is offline   Reply With Quote
Old September 21st, 2003   #10 (permalink)
Link to the Underworld
 
l3illyl3ob's Avatar
 
Join Date: Aug 2003
Location: Detroit
Posts: 1,147
Re: Blaster Worm 2!

Quote:
Originally Posted by Player-X
Why don't they just disable RPC by default
because there's about 30 different services that depend on RPC.
l3illyl3ob is offline   Reply With Quote
Old September 22nd, 2003   #11 (permalink)
Banned
 
Join Date: Apr 2002
Location: From Kuching in Malaysia now stuck in Houston Texas
Posts: 9,110
Re: Blaster Worm 2!

Hi n00bs

I ment DCOM Thanks for correcting me
Player-X is offline   Reply With Quote
Old September 24th, 2003   #12 (permalink)
Registered User
 
Recca's Avatar
 
Join Date: Feb 2002
Location: Where ever fate shall lead me.
Posts: 3,946
Re: Blaster Worm 2!

how can you install the patch before the comp shuts down. I find it near impossible
Recca is offline   Reply With Quote
Old September 24th, 2003   #13 (permalink)
Has an extra GOTO 10 Line
 
Quark's Avatar
 
Join Date: Dec 2001
Posts: 250
Re: Blaster Worm 2!

Quote:
Originally Posted by Recca
how can you install the patch before the comp shuts down. I find it near impossible
Sounds like you're infected with the original blaster worm.
As soon as your computer is finished booting, hit ctrl-alt-delete and get into task manager. Under processes there's a program, either blaster.exe or msblaster.exe (I forget which), end that process. Then you should be good until the next reboot, at least.

Install the patches and you'll no longer be vulnerable to it and such, though you may want to run a FixBlaster program to clean the computer out (I'm not sure where it resides).

Of course, you may also be infected with Welchia, but I haven't heard of Welchia-infected computers crashing.
Quark is offline   Reply With Quote
Old September 24th, 2003   #14 (permalink)
Registered User
 
Recca's Avatar
 
Join Date: Feb 2002
Location: Where ever fate shall lead me.
Posts: 3,946
Re: Blaster Worm 2!

This is not the blaster Virus, it's the one that infects the RCP protocol. I can't seem to fix it, i tried Ctrl+alt+del but couldn't find anything that isn't supposed to be there.
Recca is offline   Reply With Quote
Old September 24th, 2003   #15 (permalink)
Banned
 
Bispoo's Avatar
 
Join Date: Sep 2003
Location: Portugal
Posts: 26
Thumbs up Re: Blaster Worm 2!

Hi, To stop the Computer From restarting and Install the patch, when the Countdown Begins, open a Dos Command Prompt (execute: CMD) and then write: ' shutdown -a ' That's all. install the patch and Voila! I hope it helps anybody

Last edited by Bispoo; September 25th, 2003 at 00:38.
Bispoo is offline   Reply With Quote
Old September 26th, 2003   #16 (permalink)
Registered User
 
gigaX's Avatar
 
Join Date: Jul 2003
Posts: 50
Re: Blaster Worm 2!

ending task dosnt work but i had to restarrt my comp 3 times to finish dloading and installing the patch for the blaster worm wehoich i was infeced by 1 month ago...
__________________
Mah PC specs 8D >>

hp pavilon 743a >> p4 processor >> 2.4 Ghz >> 80GIG ultra DMA hd >>GeForce4 MX420 video card >> "visit me site," the irish guy said: www.sting3r-net.tk
gigaX is offline   Reply With Quote
Old September 26th, 2003   #17 (permalink)
:3
 
Yeloazndevil's Avatar
 
Join Date: Jul 2002
Posts: 10,147
Re: Blaster Worm 2!

I was one of the lucky ppl that wasn't affected by the blaster worm
Yeloazndevil is offline   Reply With Quote
Old September 26th, 2003   #18 (permalink)
Registered User
 
elachys's Avatar
 
Join Date: Jan 2003
Location: England, drinking tea.
Posts: 547
Re: Blaster Worm 2!

nah i wasn't infected either
elachys is offline   Reply With Quote
Old September 26th, 2003   #19 (permalink)
Banned
 
GKort's Avatar
 
Join Date: May 2003
Location: Ohio
Posts: 766
Re: Blaster Worm 2!

patch=prevents you from getting it (again)

once you have it the patch wont help you at that point...you have to get an AV prog like mcaffee...ive used mcaffee for several weeks and i havnt been hit with a single virus/worm/trojan

also you might wanna search @download.com for "Spybot: Search & Destroy" to remove AD/SPY ware...it eats your comp alive...
GKort is offline   Reply With Quote
Old September 27th, 2003   #20 (permalink)
:3
 
Yeloazndevil's Avatar
 
Join Date: Jul 2002
Posts: 10,147
Re: Blaster Worm 2!

>>also you might wanna search @download.com for "Spybot: Search & Destroy" to remove AD/SPY ware...it eats your comp alive...

actually it slows down your pc
Yeloazndevil is offline   Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

All times are GMT. The time now is 23:53.

© 2006 - 2008 Emu Forums | About Emu Forums | Legal | A member of the Crowdgather Forum Community


Powered by vBulletin® Version 3.7.0 Release Candidate 3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC5