| Pages: 1 [2] :: one page |
| Author |
Thread Statistics | Show CCP posts - 0 post(s) |

Drutort
|
Posted - 2003.08.13 02:07:00 -
[31]
its not so hard to have a anti vir installed and just scan every item before you run it that you d/l not hard at all...
you dont need to run the anti vir all the time LOL support Idea: QuickInfo an alternative to ShowInfo
my MoBlog |

Darkwolf
|
Posted - 2003.08.13 02:51:00 -
[32]
Quote: its not so hard to have a anti vir installed and just scan every item before you run it that you d/l not hard at all...
you dont need to run the anti vir all the time LOL
The exploit that Blaster takes advantage of will allow it to attack and infect a machine without the user intervening AT ALL.
That's right. You don't need to download ANYTHING. It can just find your machine and infect it remotely.
This assumes you are using Win2k/XP, or WinNT with the DCOM services (unpatched) installed, and you do not have a border firewall.
As I've said before, anyone who doesn't run a firewall for connecting to the Internet is just begging for this sort of thing to happen.
|

Ganja
|
Posted - 2003.08.13 03:02:00 -
[33]
OMFG
IM SORRY
I didn't mean to h4x all your computers!
HARRRR
*runs around the room in his bunny suit*
|

Intruders
|
Posted - 2003.08.13 04:07:00 -
[34]
Edited by: Intruders on 13/08/2003 04:12:38 Still no WinMe solution? Seems those guys knew what they were doing launching this thing on summer mid-vacations time, cant find anything in Google about "Blaster Worm" or "msblast.exe".
very ebil.
Every man lives..but not every man dies!
My sig sux |

RAIDAKAOZ
|
Posted - 2003.08.13 04:17:00 -
[35]
runs through a port that uses windows auto update then it goes to a remote ftp and and downloads into ur pc and runs then infects everything ,if u shut down the windows auto update u will be ok Im sure
Quote: its not so hard to have a anti vir installed and just scan every item before you run it that you d/l not hard at all...
you dont need to run the anti vir all the time LOL
The exploit that Blaster takes advantage of will allow it to attack and infect a machine without the user intervening AT ALL.
That's right. You don't need to download ANYTHING. It can just find your machine and infect it remotely.
This assumes you are using Win2k/XP, or WinNT with the DCOM services (unpatched) installed, and you do not have a border firewall.
As I've said before, anyone who doesn't run a firewall for connecting to the Internet is just begging for this sort of thing to happen.
------------------
If it looks like a duck, and sounds like a duck, it is probably a chicken that CCP ****ed up. |

Legonas Tedams
|
Posted - 2003.08.13 05:13:00 -
[36]
Quote:
Quote:
Oh and none of you *nix buffs get complacent either - there's actually far more holes in the various daemons/services (whichever you want to call them) than there are in the current version of XP Pro. Sendmail has hundreds of the buggers - since hardly anyone knows "Vogon Poetry" (sendmail.cf) and tends to just leave it alone. 
yea but who uses sendmail anyway if they want a secure linux box? there are far better mailservers nowadays.
ôThe universe is an infinitely faceted diamond, and each of our souls is reflected in its magnificence. Chose your facet, your window to the world, wisely.ö - Legonas Tedams
|

plur
|
Posted - 2003.08.13 07:50:00 -
[37]
Edited by: plur on 13/08/2003 07:53:01
Quote: runs through a port that uses windows auto update then it goes to a remote ftp and and downloads into ur pc and runs then infects everything ,if u shut down the windows auto update u will be ok Im sure
nope, sorry Raid. it gets on your machine anyway via shared folders. XP and AFAIK win2k both have network shares on by default. only way to turn them off is via the registry. (My Shared Pictures etc)
deleting these shared folders wont get rid.. they will just come back. How dumb is it that they are there on machines by default.. even if you dont have a network.
Any machine with shared files can be accessed via the command line or even internet explorer.
file://127.0.0.1
a properly configured firewall will stop this, but many people dont have this blocked. a Router does wonders here ;)
AFAIK zone Alarm, Black ICE, and windows XP firewall do not stop people accessing these shares over the network or internet like this.
Kerio is free and has excellent network features and can be told to block all network traffic, or only allow white listed addresses access (incase you are on a network and dont want to block that traffic!) http://www.kerio.com
Got a spare machine around that you dont use? install linux on it and use it as a firewall or install Smoothwall on it (software router/firewall)
There is also a small Tool out there on the net called hunt.exe that can be run via the command line and will show any accessible network shares on a machine, it has a few switches but its easy to use something like:
> c:\hunt.exe 127.0.0.1
it will then show network share info on the target ip, excellent for checking yourself or other machines to make sure they arent open to the entire internet for access.
|

Drutort
|
Posted - 2003.08.13 07:54:00 -
[38]
duh who isnt runing hardware firewall/router 
but ya this type of problem is really hmm bad 
btw only a noob would have windows update auto hehe... support Idea: QuickInfo an alternative to ShowInfo
my MoBlog |

Thano
|
Posted - 2003.08.13 08:04:00 -
[39]
"a properly configured firewall will stop this, but many people dont have this blocked. a Router does wonders here ;)"
why?? does a router automaticaly have these ports closed?? please excuse the newbishness of this question im kinda a lamen when it comes to network stuff
|

Druanna
|
Posted - 2003.08.13 08:12:00 -
[40]
Edited by: Druanna on 13/08/2003 08:12:03
Quote: Oh and none of you *nix buffs get complacent either - there's actually far more holes in the various daemons/services (whichever you want to call them) than there are in the current version of XP Pro. Sendmail has hundreds of the buggers - since hardly anyone knows "Vogon Poetry" (sendmail.cf) and tends to just leave it alone. 
LOL! sendmail???? I don't know anyone who's used that in at least 5 years! not even in those BS night classes AOLers goto to learn RedHat.
This "hack" was identified and a patch made available on July 16th of this year. Anyone who got "infected" by it has nobody to blame but themselves.
It's days like this that I'm convinced the human race is made up of mostly retards.
|

agrizla
|
Posted - 2003.08.13 08:45:00 -
[41]
Heh - that's what I meant. It gets left running and never gets patched because it works and nobody at the company (especially small ones) has a clue how it works 
|

Bald Hamster
|
Posted - 2003.08.13 10:47:00 -
[42]
Thanks for the heads up.

|

Pastora
|
Posted - 2003.08.13 11:06:00 -
[43]
My sad story:
I didn't have this virus on my computer, I didn't have any for past 5 years ('cause I know how to use my computer properly), but I decided to install this secure patch from microsoft just for the sake of it (well, because I usually install hot fixes and service packs, if I think I'l benefit from them).
So, I did, I installed it. And something went terribly wrong. :( My system absolutely forgot what a network is. My computer lost every contact whatsoever with the outside world and my home LAN. I could still see that computer manages to connect to my broadband router, and send some packets to the router, but it wasn't able to recieve any after that. :( I don't know what happened, 'cause many of my friends have installed the same patch, and it all went smooth and clean. Not in my case. I tried to uninstall it, to restore previous backups, to turn on/off different services, even to uninstall and install again network card drivers. Nothing helped. Then I tried to reinstall my OS in a repair mode -- still my computer couldn't establish any contact with LAN or web. Of course, if have checked if there were any hardware problems, there were none.
So, as the final resort, I had to completely reinstall my OS. :( Darn, it was painful, because I had to reintsall some of the most important programs as well, and all the latest drivers for my hardware.
And the worst thing is that I have missed all the action yesterday in regard to latest events in Stain. :( _______________________________________________ If ifs and ands were pots and pans, I would grow mushrooms in my pants. |

IZON
|
Posted - 2003.08.13 13:13:00 -
[44]
Edited by: IZON on 13/08/2003 13:26:25 Edited by: IZON on 13/08/2003 13:24:12
Quote: ZoneAlarm works wonders, i was on a LAN with a friend who had it.
I'm running ZoneAlarm right now, but only the freebie version. So far no problems. But to be honest I don't know what the symptoms are. 
Edit: Ok I've calmed down now, I'm running a win98se PC, so I'm in the clear I guess. 
"...master! there's a guy in the south village called IZON, he is a Ninja!" |

Laer
|
Posted - 2003.08.13 18:47:00 -
[45]
Running any virus scanner or firewall isn't going to help you not get it at all. I run the latest version of Norton and Zone Alarm at all times. The worm still got me and neither program seemed to help in the least.
|

Bad Harlequin
|
Posted - 2003.08.13 19:13:00 -
[46]
Edited by: Bad Harlequin on 13/08/2003 19:17:03
Quote: *looks at the router in the other room*
*laughs*
See all this is the reason why I always tell my brother to get lost whenever he comes to ask me because he wants ports opened for some damn game 
actually no one's bothered to mess with those yet. Most game ports are "safe," so far, because only the games listen on those ports =).
weird seeing this thread appear 24hrs after the fact - for the whole sordid history check the Issues and Workarounds, where this was already covered by a coupla people. I see Doc Brown reposted his guide, he could sell copies at this point .
If you want to see something absolutely FAScinating, check various "tech help" boards starting Monday night. It's better'n'TV 
PS: some cheapo router/firewall for $20 - $40 USD is (i find) better than software solutions for a variety of reasons. For one thing, you have more memory and CPU for Eve .
Also, if it's bouncing off the firewall, your comp doesn't have to deal with the packet storm when you get flooded with requests. Again, less resources wasted by your machines.
Software crashes... if something gets by, sneaks in an open port, you turn the firewall off to install an app and forget to yoink the cat5, whatever... something could get "over the wall" and kill it from the inside.
The only software firewalls i like is a dedicated box that IS a firewall, only, between you and everything else. Then you get to play with things like Portsentry 
You are in a maze of twisty little asteroids, all alike. |

HP Lovecraft
|
Posted - 2003.08.13 19:16:00 -
[47]
I got my msblaster worm when I was trying to log onto Explore-Eve, from the email verifcation they sent me. Right now I got more worms then a junk yard dog. This thing is a bear to get rid of because it will keep shuting your computer down as you try to download the software to get rid of it. I found that after I log on to the internet I go to the file search screen, type in msblaster. If you find msblaster.exe. delete it immediately and clear it out of your recycle bin as well. This should give you time to download the required files to protect your system. If you find msblaster.exe, file and another file that reads w32blaster it's to late your infected. If you are infact infected, another way to get around this thing to get to the downloads is to go to system restore. Go back to an earlier restore point, (pre infected) restore your computer to that point and download the removal files. 
Actually I have the heart of an Exploiter and a PKer---I keep them on my desk in a jar. |

JAXX
|
Posted - 2003.08.14 05:25:00 -
[48]
Edited by: JAXX on 14/08/2003 05:26:40 Edited by: JAXX on 14/08/2003 05:26:08 Edited by: JAXX on 14/08/2003 05:25:24 Side note... anyone with the blaster worm can buy themselves unlimited time to pursue any one of the numerous routes listed in this topic to get the patch if they have this knowledge of the Worm. It's shutting your computer down using RPC - Remote Procedure Call one of the many services running on XP or 2000(NT)
Disconnect temporarily from the internet Click 1. start 2. Control Panel (if using XP switch to classic view now) 3. administrative tools 4. Services 5. you will see 2 services here listed as Remote procedure call, the first one is the correct one, the second is RPC locator. 6. right click on remote procedure Call and click properties on the popup menu 7. Click on the recovery tab 8. notice the 3 drop down menus for actions to be taken if there is a failure of the remote procedure call. 9.Change these all to "take no action" and click OK 10. You have just taken away the worms method of shutting your computer down. reconnect to the internet and patch away.
FYI here's a cool link to a really simple scanner that will remove all of the major recent Viruses that's free and has easy instructions.
Stinger anti virus scanner
Oh yeah, Bad harlequin has a pretty comprehensive post in the Known Workarounds section. Really no need to sticky here.
Feel free to add this to his though if you're feelin saucy
Sometimes to win, you have to fight just as mean and dirty as the other guy. Nobody will beat you challenging you to the field of honor for pistols at dawn. They have to slit your throat while you lay in bed, just like you'd do them. - Jash Illian |

Mandos
|
Posted - 2003.08.14 10:11:00 -
[49]
I'm letting this sit here some more, stickied. OT or not, it's relevant and important information.
-- Mandos Polaris Forum Moderator and Bug Hunter EVE Forum rules |

vyperpit
|
Posted - 2003.08.14 11:10:00 -
[50]
Edited by: vyperpit on 14/08/2003 14:18:06 guys just to let you know there are now 2 more variants of the worm that can not be detected by the orginal tool. the company i work for (IT side) soon as i can find out some details i will post here for you all and some fixes. so far though it seems like it is just more registry keys to be removed.
ok the variats can be taken out with the newest stinger posted in topic above me. note though anyone with stinger that they got yesterday will neeed to download it again as it is a new version with added componets against the variats. ----
Fair Fighting  Quote stolen from Waagaa Ktlehr who borrowed it from ??? "If you end up in a fair fight, you planned it wrong." (Ehm yeah, or CCP ****ed with the scanner again..) |

Takumi Vetinari
|
Posted - 2003.08.14 12:21:00 -
[51]
I find it quite poor how some users are being lamented here. Not everyone is as "l33t" as you (you in general, that is).
We all have our specialised fields of knowledge, lambasting those who are ignorant to computing issues is the wrong way to go about it. People have bought PCs (hardly a cheap item) in good faith and have unwittingly fallen foul of errors outwith their control (or knowledge).
It is up to those people in the know to educate and help them, not revoke their right to use computers, the internet and all things found therein. --
Takumi Vetinari, Founder PIE Inc
|

bullwyff
|
Posted - 2003.08.14 12:25:00 -
[52]
i have lates norton and zone alarm running and it seems to work just fine on my pc using an xp corporated. 
|

The Reverend
|
Posted - 2003.08.14 12:57:00 -
[53]
Just a few more helpful hints.
1. For those of you that keep getting the message that your computer wants to shut down, fdo the following.
go to start run and type "Shutdown -a"
This will cancel the shutdown message. I'm using a copy of zone alarm atm (as the damn firewall on my router appears to be non functional - grrr) and that seems to be blocking the worm so far.
Also - keep an eye on your system restore files, it is possible for the virus to remain hidden in an old system restore file, most virus detectors will let you know if its there.
m0ovie links |

Big Al
|
Posted - 2003.08.14 13:52:00 -
[54]
I had this on my system and it took me ages to get rid of. My machine was routed through another to get internet access. The routing maching was broken (due to an inept family member...) and I hooked up to the net directly.
I made the mistake of not installing a firewall or any anti-virus software (who buy's a burglar alarm prior to be burgled?) and I got the virus.
First signs were SVCHOST errors, the inability to cut and paste, open up new explorer or netscape windows, errors whilst installing things, etc.
Thought perhaps a list of the symptoms might help people who do not know they are affected / infected.
My system is Windows 2000. If you have the virus, you will not be able to connect to Windows Update.
'It is only when your life flashes before your eyes that you realise how much you have missed.'
|

Krackken
|
Posted - 2003.08.14 14:56:00 -
[55]
I'm so tired of hearing about this worm.....
|

HP Lovecraft
|
Posted - 2003.08.14 15:43:00 -
[56]
Quote: I'm so tired of hearing about this worm.....
Krackken! Thats an easy fix. If you see a post that mentions the "worm", DON"T OPEN IT!
There now wasn't that easy????? 
Actually I have the heart of an Exploiter and a PKer---I keep them on my desk in a jar. |

Bruenor
|
Posted - 2003.08.14 17:33:00 -
[57]
"Ounce of prevention worth a pound of cure".... Zone Alarm Pro Agnitum Tauscan Hardware ADSL/Router/Switch Popup Stopper LavaSoft Ad-Aware
and Microsoft auto-updater for those who forget.
"Just because the bank doesn't get robbed doesn't mean you don't hire a security guard."
|

KillerLennart
|
Posted - 2003.08.15 11:15:00 -
[58]
Ehm i wonder, can u get this worm or one like it, if u are running win 98 ? As i sometimes get some of the things u talk abot, like cant get on windows update, when watching movies on my comp it just shut down for no reason, or it locks up. So could this be a worm or something ?
|
| |
|
| Pages: 1 [2] :: one page |
| First page | Previous page | Next page | Last page |