Just a Warning

Korittke

Member!
Joined
Dec 30, 2002
Messages
5,993
Reaction score
0
Website
Visit site
old news :p but its already a shitload of comps infected so better take this as a bump so more ppl would read it. btw the worm spreads by scanning ip ranges for vulnerable systems and installs itself on found comps via ftp and the dcom exploit. oh and beginning from aug 15 it will start attacking microsoftupdate.com with DoS attacks so you cant download the patch. hurry hurry.
 

Siphon

Member!
Joined
Jul 31, 2003
Messages
261
Reaction score
0
Location
TCP Port 8080
Website
slashdot.org
bump 4 more computers at work just went down cause some idiot left his computer on connected to Bank of America. BOA now has this ^_^ Might wana keep an eye on your credit card
 

johnnq

Member!
Joined
Jun 22, 2003
Messages
301
Reaction score
0
Website
www.burke-books.com
wut is taht? i have norton security professional...does that cover wut u posted up there? and wut does that protect-just ur copmuter in general?
 

Siphon

Member!
Joined
Jul 31, 2003
Messages
261
Reaction score
0
Location
TCP Port 8080
Website
slashdot.org
Umm I'm assuming your running Windoz (cause Gates is an asshat). There are security updates that it constantly nags you to download and install. If you havent installed the newest one you're vulnerable to this worm and you should go to the link i posted earlier to get all the details on it. You'll have to reformat or chkdsk and remove the virus if you get it which are both lengthy. =(
 

johnnq

Member!
Joined
Jun 22, 2003
Messages
301
Reaction score
0
Website
www.burke-books.com
ya my bro knows everything about computers (but i dont feel like asking him)...more than u guys! hes a freakin genius. u know those mind puzzles where u gotta get the ring off the contraption? he solved the most difficult 1 in 7 minutes. i guess ill dl it
 

Siphon

Member!
Joined
Jul 31, 2003
Messages
261
Reaction score
0
Location
TCP Port 8080
Website
slashdot.org
Ummm I doubt that your brother is so much a genius he can provide more help than a forum community... That's like Open Source vs Closed Source =)
 

Ebay.God

Member!
Joined
Jul 15, 2003
Messages
1,785
Reaction score
0
Location
Canada
Website
www.xtreme-host.net
Thats like saying your king shit, never say you are, because there is always someone smellyer!
 

Sicloan

BattleForums Senior Member
Joined
May 18, 2003
Messages
2,104
Reaction score
0
Location
visualdesigncore
Website
www.visualdesigncore.com
this worm attacked my ISP it was down for 25 hours with little or no connectivity! the technicions got it up and running again but this is some scary sh*t! it made the local / probably national news. there was also a message telling bill gates to fix his software :rofl anyway just a heads up on how bad this worm is!
 

laserjim

Member!
Joined
May 20, 2003
Messages
108
Reaction score
0
Website
Visit site
no really... its called a worm, they have had it on the news for a long time.


Please close this line
 

Ultimate Empire

BattleForums Addict
Joined
May 18, 2003
Messages
701
Reaction score
0
Question: Will my firewall(s) block this worm?
 

Torubu

Member!
Joined
Feb 19, 2003
Messages
722
Reaction score
0
Website
Visit site
Asnwer: Firewall's are meant to stop incoming connections, it most likely won't be able to stop a worm from doings it's work in your system.. because an active connection wouldn't be necessarily needed.
 

seddes

Member!
Joined
Jun 18, 2003
Messages
88
Reaction score
0
Location
Greece
Website
Visit site
IF you stop the incoming traffic on ports TCP4444 , TCP135 , and UDP69 you wont have any problems...
 

GhostBomber

New Member
Joined
Aug 7, 2003
Messages
3
Reaction score
0
Website
Visit site
Ok.. just to help you all out a little. It spreads via a buffer overflow of the rpc service causing a hidden window cmd line to be active. And Korrittke, they put the files on there via tftp, not ftp. And blocking port 134 and 139? Uh, the rpc service runs through 135 guy. And yes to 69 though (tftp) - Of course, since windows has had an update out since July, if you're infected, it's your own fault. I demonstrated the ease and quickness of this on someone in the irc channel if anyone was there.. Of course, if you are behind your router, you're fairly safe unless you're an idiot who just has every port accessed on the router fowarded to the same port on your computer. And no, your firewall is not going to stop it. If you're running zonealarm and out of nowhere the scvhost.exe program asks for rights to access the local internet/act as server, deny it and count it as you being almost infected. You don't need to allow scvhost to access the net anyway.
http://www.informationweek.com/story/showArticle.jhtml?articleID=13100032 - article released as the worm started spreading. It was only a matter of time before it came out so no suprise there.

By the way johnq, just so you know, having norton is like having 5 year old virus protection. It seems to be the easiest virus scanner to avoid.

anti
 

Hackstation

Member!
Joined
Jul 22, 2003
Messages
157
Reaction score
0
Website
Visit site
Originally posted by GhostBomber

By the way johnq, just so you know, having norton is like having 5 year old virus protection. It seems to be the easiest virus scanner to avoid.

anti
correct u just pay for the name "Symantec .. "Norton" Antivirus its the same like Coca Cola or any noname Cola ;P


there are many unknown or even Free Antivirus Programs out there which pwn Norton 100times
 

NewPosts

New threads

Top