 |
       |
User CP
:: Log in to check your private messages
:: Chat
:: Register
:: Log in

Board Index
:: Album
:: FAQ
:: Calendar
:: Members
:: Groups
:: Staff
:: Search
|
 |
|
 |
I posted this everywhere else - sorry if it's been done before |
 |
|
Author |
Message |
PO Info |
 |
Kid Icarus Senior Otaku

Joined: 24 Sep 2002 |
Posted: Tue Aug 12, 2003 1:42 am Post subject: |
Quote: | SAN FRANCISCO (Reuters) - An Internet worm that takes advantage of a recently discovered, widespread security hole in Microsoft Corp.'s Windows software emerged around the United States on Monday, crashing systems and spreading to vulnerable computers, security experts said.
The worm, dubbed LoveSan, Blaster, or MSBlaster, exploits a vulnerability in the Distributed Component Object service that is hosted by a Remote Procedure Call feature in Windows 2000 (news - web sites) and Windows XP (news - web sites) that lets computers share files, among other activities.
Once it gets onto a vulnerable computer, the program downloads code from a previously infected machine that enables it to propagate itself. Then, it scans the Internet for other vulnerable machines and attacks them, said Johannes Ullrich, chief technology officer at the Internet Storm Center at the SANS Institute.
In some cases, the worm crashes the victim machine, but does not infect it, he said.
It is spreading rapidly and has infected several thousand machines, Ullrich said.
The worm also appears to instruct the computer to launch a distributed denial of service (DDOS) attack on Aug. 16 against a Microsoft Web site, he added. In a DDOS attack, a Web site is temporarily paralyzed after receiving requests from numerous multiple computers.
"It's dangerous from the perspective that it can consume a lot of bandwidth," said Russ Cooper of TruSecure Corp. "Every compromised machine is constantly attacking."
The worm contains code that includes a phrase: "Billy Gates why do you make this possible? Stop making money and fix your software!!," according to SANS.
Anti-virus provider Network Associates rated it a medium risk for consumers and corporate computer users, while rival Symantec Corp. rated it a high risk for distribution and a low risk for damage.
Last month, Microsoft warned of the vulnerability, which experts said was one of the worst to hit a software program in a few years because of the number of Windows systems affected.
The U.S. government issued a warning about the security flaw, and then released another advisory warning after thousands of machines began scanning the Internet looking for vulnerable computers. After that, experts said it was only a matter of time before a worm would appear.
In January, a worm dubbed "Slammer" that exploited a hole in Microsoft SQL database software brought automatic teller machines in the United States to a standstill, paralyzed corporate networks worldwide and nearly shut down Web access to South Korea (news - web sites). |
This MSBlaster creates a registry key, and uses your IP to launch a DOS attack on Microsoft.
So there's two ways to tell if you have it, one run a up to date virus checker. It should catch it.
If not, hit control-alt-delete to bring up the taskmanager, and check for MSBlaster.exe in your processes. If it's running, kill the process and delete the file.
Do a search for MSBlaster.exe to find it. |
|
|
|
|
Back to top |
|
 |
Happo Senior Otaku

Joined: 03 Jul 2003 |
Posted: Tue Aug 12, 2003 7:04 pm Post subject: |
Thanks bub, I don't know anyone infected yet but I will bear your message in mind. |
_________________
 |
|
|
|
Back to top |
|
 |
Ultrawolf Mr. Roarke

Gender:  Joined: 04 Jul 2003 |
Posted: Tue Aug 12, 2003 9:03 pm Post subject: |
alot of people i know in swg say that their friends ahve had this worm in their system, its amazing what a few jerks will do to make the rest of us miserable |
_________________ Welcome... |
|
|
 |
 |
Wins 115 - Losses 130 Level 17 |
EXP: 831 HP: 2800
 |
STR: 1000 END: 900 ACC: 1100 AGI: 1000
|
Legacy (Shotgun) (400 - 550) |
|
|
Back to top |
|
 |
Silver Adept Otaku Lord

Age: 42 Gender:  Joined: 20 May 2003 |
Posted: Tue Aug 12, 2003 9:07 pm Post subject: |
There have been a couple on some of my other boards that were caught with this virus. They said it was nasty stuff and that it could take out the virus scanner as well. So if you even think you have it, go check manually and toast it at the source. |
_________________ Sir Silver Adept, KCI. Check out the Knights of Jubal if you want to revive chivalrous behavior.
 |
|
|
 |
 |
Wins 293 - Losses 240 Level 23 |
EXP: 2163 HP: 3375
 |
STR: 1125 END: 1125 ACC: 1225 AGI: 1225
|
Sander's Asylum (Partisan) (505 - 655) |
|
|
Back to top |
|
 |
Ultrawolf Mr. Roarke

Gender:  Joined: 04 Jul 2003 |
Posted: Tue Aug 12, 2003 9:10 pm Post subject: |
omg it wasnt nerds who did this! its SKYNET!!!! |
_________________ Welcome... |
|
|
 |
 |
Wins 115 - Losses 130 Level 17 |
EXP: 831 HP: 2800
 |
STR: 1000 END: 900 ACC: 1100 AGI: 1000
|
Legacy (Shotgun) (400 - 550) |
|
|
Back to top |
|
 |
|
|
|
|
 |
|
 |
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
|