It is currently Sat Apr 27, 2024 7:39 pm



Reply to topic  [ 48 posts ]  Go to page Previous  1, 2, 3, 4  Next
Blaster Worm 
Author Message
Emperor
User avatar

Joined: Tue Apr 01, 2003 3:42 am
Posts: 2005
Location: Under my wife AND son's thumbs.. in essex! chavs! everywhere!!
Reply with quote
Post 
mole wrote:
And dude, you got infected? Did the general sypmtoms occur?


yeah, a box popped up saying something like '45 seconds until your computer shuts down'. only happened like twice, and that was it, didn't keep doing it enough to mess anything up, but still damn annoying. :?

Return of the J wrote:
How you get virusses in from e-mail??

I mean if i see a mail from dunno-who with dunno-what attachment, i immediately delete it. even if it is from someone i know i delete it most of the times if i don't trust it.

zone-alarm pro pffff i can't even get my settings right, stupid thing blocks my laptop. so i just disable it .


yeah, trouble is it was someone i know from college sending a picture to me along with about 10 others, so you tend to get lazy and just open it.

thankfully nortons update sorted it out straight away.

_________________
Sleep deprivation for teh lose


Fri Aug 22, 2003 10:50 am
Profile
Felix Rex
User avatar

Joined: Fri Mar 28, 2003 6:01 pm
Posts: 16650
Location: On a slope
Reply with quote
Post 
:/ Blaster's a worm, not an email virus. It propogates itself by doing port scans and exploiting a buffer overflow vulnerability in DCOM RPC. Nothing to do with email. Unless there's a new variety, but it would have to be a complete re-write of the code.

_________________
They who can give up essential liberty to obtain a little temporary safety, deserve neither liberty nor safety.


Fri Aug 22, 2003 1:03 pm
Profile WWW
Emperor
User avatar

Joined: Tue Apr 01, 2003 3:42 am
Posts: 2005
Location: Under my wife AND son's thumbs.. in essex! chavs! everywhere!!
Reply with quote
Post 
then thats a bit worrying. :? the firewall really should have kept it out. any ideas why it didn't?

_________________
Sleep deprivation for teh lose


Fri Aug 22, 2003 2:08 pm
Profile
Minor Diety
User avatar

Joined: Tue Apr 01, 2003 10:23 am
Posts: 3956
Location: Amsterdam
Reply with quote
Post 
I haven't followed the whole topic, what firewall are you using?
I'm using Sygate Personal Firewall, it's free and I'm very content with it, except for the fact that sometimes it stops working and I have to reinstall it, but that is said to hapen only at a limited amount of users.

_________________
Melchett: As private parts to the gods are we: they play with us for their sport!


Fri Aug 22, 2003 2:13 pm
Profile
Minor Diety
User avatar

Joined: Mon Mar 31, 2003 7:23 am
Posts: 14878
Location: behind a good glass of Duvel
Reply with quote
Post 
tyranus wrote:
then thats a bit worrying. :? the firewall really should have kept it out. any ideas why it didn't?



Cos it's a sophisticated worm. :) I repeat, firewalls are the biggest load of crap ever. :D

_________________
"I find a Burger Tank in this place? I'm-a be a one-man cheeseburger apocalypse."

- Coach


Fri Aug 22, 2003 2:45 pm
Profile
Emperor
User avatar

Joined: Tue Apr 01, 2003 3:42 am
Posts: 2005
Location: Under my wife AND son's thumbs.. in essex! chavs! everywhere!!
Reply with quote
Post 
lol, i'll take your word for it. :D :wink:

arathorn: zonealarm pro.

_________________
Sleep deprivation for teh lose


Fri Aug 22, 2003 4:55 pm
Profile
Stranger
User avatar

Joined: Sat Apr 12, 2003 1:14 pm
Posts: 6312
Location: Estonia
Reply with quote
Post 
Id suggest also scanning your computer for w32Sobig.F@mm virus, we had a major trouble with that here in estonia, hell it even made it into the local newspaper :D

If you get any email containing .pif files or .scr then delete it immediatly. theres a 85% chance its the virus. Also the key text inside the email is: Please see the file attached or See the file attached.

_________________
When someone asks how rich you are, quote Rinox " I don't even have a rusty nail to scratch my butt with...!"

Be well or Get Help!!


Fri Aug 22, 2003 5:03 pm
Profile
Felix Rex
User avatar

Joined: Fri Mar 28, 2003 6:01 pm
Posts: 16650
Location: On a slope
Reply with quote
Post 
If your firewall is worth a crap, it should block it. If not, well....that's your problem. :) You need to be blocking TCP ports 135 and 4444. And supposedly also UDP port 69.

TCP port 135 is one of the file and printer sharing ports... 4444 is RPC DOM (which is the biggest problem) and UDP port 69 if TFTP, which is how the virus transfers itself to a new computer. The reason to kill TCP 135 is because it also attacks open shares, I believe. But if you don't have a network, you shouldn't have any shares anyway... and if you do, you'd be a moron not to kill access to those ports with a router or something.

_________________
They who can give up essential liberty to obtain a little temporary safety, deserve neither liberty nor safety.


Fri Aug 22, 2003 5:34 pm
Profile WWW
Emperor
User avatar

Joined: Tue Apr 01, 2003 3:42 am
Posts: 2005
Location: Under my wife AND son's thumbs.. in essex! chavs! everywhere!!
Reply with quote
Post 
yeah, that was one of the things i've done since, blocked those ports, hopefully it won't happen again. :?

_________________
Sleep deprivation for teh lose


Sat Aug 23, 2003 7:08 am
Profile
Felix Rex
User avatar

Joined: Fri Mar 28, 2003 6:01 pm
Posts: 16650
Location: On a slope
Reply with quote
Post 
don't feel bad, my girlfriend brought home a friend's laptop that was spontaneously rebooting itself. I had no clue what was going on until I checked mconfig... msblast.exe. heheh. I thought that was pretty funny. So I manually cleaned it, removed a bunch of startup crap (starts in like 30 seconds now instead of 5 minutes) and even patched it for her. Patched my own machine too, just for the hell of it. :D

_________________
They who can give up essential liberty to obtain a little temporary safety, deserve neither liberty nor safety.


Sat Aug 23, 2003 7:31 am
Profile WWW
Minor Diety
User avatar

Joined: Fri Apr 11, 2003 5:09 pm
Posts: 4003
Location: Walsall, West Mids, UK
Reply with quote
Post 
nice, i'm gunna have to go in to that config and see what i can get rid off, but i'll do it using ur help me thinks, check the site and all. This comuter takes .. well last time I timed it, 2 mins 40 to start up, So gotta fix that.

_________________
Games to complete:
GTA IV [100%] (For Multiplayer next!)
Fallout 3 [50%]
Rock Band [35%]
http://www.cafepress.com/SmeepProducts


Sat Aug 23, 2003 8:11 am
Profile WWW
Minor Diety
User avatar

Joined: Tue Apr 01, 2003 10:23 am
Posts: 3956
Location: Amsterdam
Reply with quote
Post 
Satis, the ports you mentioned, wich ones are local and wich ones are remote?

_________________
Melchett: As private parts to the gods are we: they play with us for their sport!


Sun Aug 24, 2003 8:03 am
Profile
Felix Rex
User avatar

Joined: Fri Mar 28, 2003 6:01 pm
Posts: 16650
Location: On a slope
Reply with quote
Post 
eh? Those are the incoming ports you need to close. Actually, you can close those ports inbound and outbound, I doubt you're using any of the services.

Yea, Mole, check my walkthroughs. I forget which O/S you're running. oh, btw, it's mSconfig, not mconfig... typo on my part.

_________________
They who can give up essential liberty to obtain a little temporary safety, deserve neither liberty nor safety.


Sun Aug 24, 2003 10:04 pm
Profile WWW
Minor Diety
User avatar

Joined: Tue Apr 01, 2003 10:23 am
Posts: 3956
Location: Amsterdam
Reply with quote
Post 
Sygate Personal Firewall makes a difference between local and remote ports, dunno what that is, but I've blocked everything remote and local.


You do not have the required permissions to view the files attached to this post.

_________________
Melchett: As private parts to the gods are we: they play with us for their sport!


Mon Aug 25, 2003 8:18 am
Profile
Felix Rex
User avatar

Joined: Fri Mar 28, 2003 6:01 pm
Posts: 16650
Location: On a slope
Reply with quote
Post 
ok, it's talking about inbound and outbound. Local would be inbound, I'm sure, while remote it outbound. Kind of a wierd way to write it, but whatever. That's fine. Inbound is actually all you need to worry about, but having both doesn't matter either.

_________________
They who can give up essential liberty to obtain a little temporary safety, deserve neither liberty nor safety.


Mon Aug 25, 2003 12:37 pm
Profile WWW
Display posts from previous:  Sort by  
Reply to topic   [ 48 posts ]  Go to page Previous  1, 2, 3, 4  Next

Who is online

Users browsing this forum: No registered users and 14 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group.
Designed by STSoftware.