Log in

View Full Version : How long surf you until see shutdown...


ppera2
1st September 2003, 22:16
Win98/Me users ignore this.

How long is your average surf without firewall, until you see message about shutdown in 60 sec? (Msblast).

The Edge
1st September 2003, 23:11
usually 2-5min from the few dozen systems i've come across.
One way to prolong this is to goto start/run and type "shutdown /a" when the shutdown box appears.

Have you not got the patch yet?

SeeMoreDigital
2nd September 2003, 13:27
The Msblast virus is certainly an odd one!

I reinstalled WinXP Home on a friends PC a couple of weeks ago and when the 'setup' stage got to the point where it registers/confirms that the O/S is legit........ the PC got infected and shut down!

All very amusing. I think not! But just goes to show how far the virus had got into M$'s servers.

The Edge
2nd September 2003, 13:35
That's a pain. At least the FBI have identified the teenager for the .b strain of the virus.
I'll be formatting soon anyway.....system was never right since infection.:(
I read somewhere that MS are using Apache Servers at the moment? Or am I just talking jibbereish? :cool:

Edge

Tuning
2nd September 2003, 13:51
I have been infected by this virus 2 times!.Day after day.It nearly took 45 seconds to show the Dialoge Box after the net connection was enabled.

bilu
2nd September 2003, 13:55
First thing to do:

http://securityresponse.symantec.com/avcenter/venc/data/w32.blaster.f.worm.html



In many cases, on both Windows 2000 and XP, changing the settings for the Remote Call Procedure (RPC) service may allow you to connect to the Internet without the computer shutting down.

Follow these steps:

1. Do one of the following:
* Windows 2000: Right-click the My Computer icon on the Windows desktop, and then click Manage. The Computer Management window opens.
* Windows XP: Click the Start button, right-click the My Computer icon, click Manage. The Computer Management window opens.
2. In the left pane, double-click Services and Applications, and then select Services. A list of services appears.
3. In the right pane, locate the Remote Procedure Call (RPC) service.

CAUTION: There is also a service named Remote Procedure Call (RPC) Locator. Do not confuse the two.
4. Right-click the Remote Procedure Call (RPC) service, and then click Properties.
5. Click the Recovery tab.
6. Using the drop-down lists, change First failure, Second failure, and Subsequent failures to "Restart the Service."
7. Click Apply, and then click OK.

CAUTION: Make sure that you change these settings back when you have removed the worm.



Bilu

The Edge
2nd September 2003, 13:58
Cheers bilu...that could prove useful for me.

Edge

Uli
2nd September 2003, 14:07
Never without firewall!

Quote from pilotfish:

Surfing without firewall is like a girl wearing a T-shirt with "F*ck me" on it!

Response:

No! It is like a nude girl with a "F*ck me"-tattoo on it.

greetz, Uli

PS: No offense ;)

bilu
2nd September 2003, 14:14
@Uli

It may happen that you have to download the firewall software first :D

Like having a "F*ck me" tatoo in the back and running for pants :D



Bilu

SeeMoreDigital
2nd September 2003, 14:18
I/we must be quite lucky as none of our PC's got infected (Well I've gone and said it now!).

I find that it's useful to keep a copy of all of M$'s updates in their own folder anyway. As, after initial download they can be found in the 'temporary internet folder'.

It also just goes to show how important it is to visit, download and install the necessary M$ updates. And making sure your 'firewall' is on.

"Damn those pesky virus makers"!

Uli
2nd September 2003, 14:21
@bilu:

Good point! ;)


That's why it is so important to act *BEFORE* you have to react :D


greetz, Uli

stax76
2nd September 2003, 14:48
I never had any problems with viruses, never used any firewall or virus scanner, I'm running Mozilla, Outlook 98 and WinXP

bilu
2nd September 2003, 15:00
Then you're damn lucky :)

Mozilla avoids a lot on spyware, but Blaster exploits an RPC vulnerability. No way to avoid that without updates and firewalls.


Bilu

stax76
2nd September 2003, 15:04
actually I'm a little bit scared right now with all the virus activities lately, most likely I'll do some research about security soon

The Edge
2nd September 2003, 15:06
Zonealarm was stopping me from downloading some files so I disabled it for a couple of hours. Bang!....got the virus. Hadn't had a virus in years previous to that.
Has to be the most annoying virus in a long,long time. :mad:

Edge

SeeMoreDigital
2nd September 2003, 15:10
Originally posted by Dolemite
I never had any problems with viruses, never used any firewall or virus scanner, I'm running Mozilla, Outlook 98 and WinXP Why don't you use the firewall that comes free with XP? Unless you did'nt know (which quite alot of our customers don't) you get to it by going to: Start, Settings, Network Connections. And then under your particular 'internet connection' you can find the 'firewall' on/off button!

As an extra security precaution, we don't use any 'Outlook' products or 'Messenger'. All our email is done thru' hotmail/msn. So it's automatically checked for viruses at msn's end - Well that's the theory!

Cheers

int 21h
2nd September 2003, 21:58
Originally posted by Dolemite
actually I'm a little bit scared right now with all the virus activities lately, most likely I'll do some research about security soon

I hope you at least regularly apply hot fixes and service packs via WindowsUpdate... if not, I have seen some rootkits using the same vulnerabilities that Blaster exploited to infect systems...

Hiro2k
3rd September 2003, 00:23
Originally posted by SeeMoreDigital
Why don't you use the firewall that comes free with XP? Unless you did'nt know (which quite alot of our customers don't) you get to it by going to: Start, Settings, Network Connections. And then under your particular 'internet connection' you can find the 'firewall' on/off button!


I've Personaly had to much trouble with this built in firewall. Too many time a computer with the firewall on has trouble seeing the network server, or vise versa, no one can access there shares in Network Neighborhood. I try to avoid that by using a router with a built in firewall. I to this day have not updated my PC's for the blaster worm and have not had my computer reboot from it. (good ol Dlink) I also don't run Anti Virus scanners on my machine as I never download things that could have viruses on them. Spyware, now thats another matter entirely, but Adaware and Spybot working together do a great job.

Well that's my 2 cents

ppera2
3rd September 2003, 00:58
XP's firewall is crap. Beside limited efficiency it's buggy. By me it will not activate anymore btw. Not big deal, we have lot of better and free firewalls.

ppera2
3rd September 2003, 16:32
I just read in one Magazine interesting things about M$ and RPC volnurability. There is a message in initial worm: "I just want to say LOVE YOU SAN! billY gates why do you make this possible! Stop making money and fix your software!"

It was planned DDoS attack on main M$ update server in August 16. But M$ prevented it by removing that site from DNS records. They used then resources from Akmai provider, which is tolerant on DDoS attacks. And yes, they work under Linux :)

The Edge
3rd September 2003, 16:35
Ah, so maybe that's what I read a few weeks ago.
Steve Gibson seen it comming way way back :rolleyes:

Edge

int 21h
3rd September 2003, 19:32
Yea, the person that wrote the virus was obviously not thinking when they pointed the DDoS to http://windowsupdate.com instead of windowsupdate.microsoft.com...

In any event, like I said, I've seen a couple rootkits based on the same RPC vulnerability, so make sure you patch against it.

Also grab DirectX 9.0b, while I haven't seen any actual code against it, the same sort of exploit exists in 9.0a.

dvd2svcd
3rd September 2003, 21:00
Well, I haven't been infected at work nor at home since the Melissa virus. The reason is that I'm updating my virus each day at home and every 2 hours at work. I'm the sysadm at work and we're using Norton Antivirus Corporate Edition 7.6. But as some of you might know the Liveupdate data is only updated every wednesday (according to Symantec). However, there's another way to get the updates as they are made at symantec. You can run the below batch file whenever you want. I'm using it from my Scheduled tasks on our servers at work (every 2 hours) and at home every morning.

cescript.txt
open ftp.symantec.com
anonymous
user@
cd /public/english_us_canada/antivirus_definitions/norton_antivirus/static
lcd C:\temp
binary
hash
prompt
get symcdefsx86.exe
quit

cegetter.bat
ftp -s:cescript.txt
c:\temp\symcdefsx86.exe /q

I hope that can help some of you. Anyway the above is for Norton Antivirus only. And you will get the latest virus defs. for NAV that way.

And ofcourse I've set the Windows Autoupdate to update automatically every night at 3.00am, and this has not failed once, as some might suspect. Of course you can only do this if you don't mind your servers to reboot from time to time at 3am ;)

int 21h
3rd September 2003, 22:02
Both of these are very handy tips, and especially handy to add to a domain policy if you admin a domain :)

The DirectX 9.0b download isn't a critical update though, so I don't think the automatic windows update will grab it.. not 100% sure though.