Tilted Forum Project Discussion Community

Tilted Forum Project Discussion Community (https://thetfp.com/tfp/)
-   Tilted Technology (https://thetfp.com/tfp/tilted-technology/)
-   -   Blaster Worm RPC patch (https://thetfp.com/tfp/tilted-technology/21991-blaster-worm-rpc-patch.html)

merkerguitars 08-12-2003 06:11 AM

Blaster Worm RPC patch
 
heres a hotlink for you people for the patch to fix the vulnerbility in Microsoft Windows NT® 4.0
Microsoft Windows NT 4.0 Terminal Services Edition
Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Server™ 2003
Details:
Microsoft Security Bulletin MS03-026 Print


Buffer Overrun In RPC Interface Could Allow Code Execution (823980)
Originally posted: July 16, 2003

Revised: July 21, 2003

Summary
Who should read this bulletin: Users running Microsoft ® Windows ®

Impact of vulnerability: Run code of attacker’s choice

Maximum Severity Rating: Critical

Recommendation: Systems administrators should apply the patch immediately
LINK FOR DOWNLOAD

MSD 08-12-2003 06:40 AM

Oh, nice, when the school IT "experts" emailed it to us they said that it only affected 2000, not XP. Thanks for the heads-up

candyman 08-12-2003 07:34 AM

This worm is currently hitting my network pretty hard trying to find a hole. Luckily, all it is doing is eating up bandwidth (not my users files and OSs).

TIO 08-12-2003 08:03 AM

I just had to whip out the crowbar and pry Blaster out of our network (~150 pooters, about half of them NT-200-XP). What a way to spend a birthday.

We got it out without too much damage, but it did take out one guy's OS on a bad shutdown. And it took down at least one local radio station. Has anyone heard if the Macy's billboard went down?
:p

What time did it strike you guys, out of curiosity? 30 pooters on our network died right on the dot of 11AM (local time).

candyman 08-12-2003 08:23 AM

It started here (Michigan) yesterday at about 2:00 EST. I was getting hit from Qwest IPs in Tenn. Pretty much all the traffic is spawning from 63.146.*.*

What a mess!

cliche 08-12-2003 08:37 AM

I was wondering why my firewall has been flagging up attempts to connect 135 all day! I just put it on auto-deny and forgot about it. I think I'll turn back on the logging so I can warn friends etc...

Arc101 08-12-2003 08:58 AM

This got me yesterday, and yes it bloody well does affect XP. Anyway for more help and support (and to read people crying about how it affected them) click on below:
http://computing.net/hardware/wwwboard/forum/15396.html

Dragonlich 08-12-2003 09:59 AM

I saw the news mentioning it, and saw the reports online. To be honest, I had not seen any real evidence until just moments ago, when I checked my firewall logs - lots of 135s there.

If I'm not mistaken, I've been patched since the update was posted - my liveupdate keeps bugging me everytime it's essential.

Speed_Gibson 08-12-2003 04:22 PM

no problems here - but I do have a 3com router as my primary firewall and kaspersky anit-hacker in stealth mode on the software side. (running winXP pro corporate w/o SP1)
looked at the anti-hacker logs and no activity shows up there at all.

Speed_Gibson 08-12-2003 04:26 PM

Quote:

Originally posted by Arc101
This got me yesterday, and yes it bloody well does affect XP. Anyway for more help and support (and to read people crying about how it affected them) click on below:
http://computing.net/hardware/wwwboard/forum/15396.html

after reading those posts it is more than bit alarmingy - but not surprising - how many poeple are running without any kind of firewall. I would hate to have to rely on just a software option now after having both for several months.

Latch 08-12-2003 05:43 PM

Disrupted our whole uni. Classes got cancelled because no one could use the computers.

Then the damn thing hit res (the dorms).. I got about 5 calls in 20 minutes... and they just kept going.

juanvaldes 08-12-2003 06:38 PM

I bet a few admins just lost their jobs.

Mr.Deflok 08-12-2003 08:27 PM

Yesterday I got called out to five different locations having to heal up this worm problem, then once I was done with my clients a couple of friends called up to ask for my assistance.

Word of advice to you all, DOWNLOAD AND INSTALL THE PATCH NOW

If one techie (me) had to fix 7 instances of this problem in one day imagine how far stretched this problem really is.

p.s. the only positive thing to come of this mess is that yesterday I went to sleep a rich man.

Mr.Deflok 08-12-2003 08:33 PM

Oh and here's another link regarding the Worm and how to fix it.
http://www.techspot.com/vb/showthread.php?threadid=6651

YaWhateva 08-13-2003 01:10 AM

http://securityresponse.symantec.com...oval.tool.html

Yet another fix. That worm was a bitch.

Mr.Deflok 08-13-2003 02:54 AM

and another
http://www.freevideo.nu/rpc/

Reese 08-13-2003 04:07 PM

I just patched my moms machine yesterday and today on my 98 machine I see 192 attempts to access port 135 in my firewall logs...

RoadRage 08-13-2003 07:57 PM

Hey Mods, can you put some tag on this thread so it stays near the top? People are going to be needing this info for quite a while.

Nooze2k 08-13-2003 08:36 PM

Man has this worm caused alot of hell. The question I'm wondering about is do they have any idea who is responsible for it? From my personal experience, its not like any virus I've ever seen, from an execution point of view anyways. I'm not trying to give the wrong impression or anything, but its the most clever worm I've seen in a long time. Not real devasting to the home user (just annoying), but could cause havok on servers and such... primarily WinXP/2000 servers..... hmmmm.... perhaps a disgruntled former MS employee? Sure, abusing Windows flaws is nothing new, but then shutting down RPC services, subsequently shutting down the PC as well. Ingenious, if not evil. I could see a hefty charge against the culprit if caught, but in this case I wouldn't be surprised if he was hired after it all settles. I'm just wondering how I got it after doing a fresh install and seconds after my first dialup connection to the 'net after the install..... makes you think....

Flippy 08-13-2003 09:35 PM

Quote:

Originally posted by Nooze2k
Man has this worm caused alot of hell. The question I'm wondering about is do they have any idea who is responsible for it? From my personal experience, its not like any virus I've ever seen, from an execution point of view anyways. I'm not trying to give the wrong impression or anything, but its the most clever worm I've seen in a long time. Not real devasting to the home user (just annoying), but could cause havok on servers and such... primarily WinXP/2000 servers..... hmmmm.... perhaps a disgruntled former MS employee? Sure, abusing Windows flaws is nothing new, but then shutting down RPC services, subsequently shutting down the PC as well. Ingenious, if not evil. I could see a hefty charge against the culprit if caught, but in this case I wouldn't be surprised if he was hired after it all settles. I'm just wondering how I got it after doing a fresh install and seconds after my first dialup connection to the 'net after the install..... makes you think....
While I agree the impact of this worm was *huge*, it wasn't really all that "clever..." Public information about the vulnerability this worm exploits was released on July 16, and public exploit code was released ~1.5 weeks after. The author of this worm just wrapped some self-spreading code around a plain vanilla public exploit code, and voila! Instant havoc ;)

This has happened before too, just not with such widespread vulnerabilities. Examples include Code Red, Nimda, and SQL Slammer.

Batman976 08-13-2003 11:01 PM

I'm running Windows 98... which patch do I need to install?

Mr.Deflok 08-14-2003 12:10 AM

Quote:

Originally posted by Batman976
I'm running Windows 98... which patch do I need to install?
Windows 98 users need not worry about the Worm, you're in the clear buddy! It's only us Win2k/XP users (and 2003...)

billege 08-14-2003 12:26 AM

I had the patch installed on both of our home network computers when the patch came out, a couple of months ago.

Behind the hardware and software firewall, everything is cool. This is one of those days where I'm glad I do as much as I understand to protect my network.

Whew.

Speed_Gibson 08-14-2003 01:53 AM

just checked my logs in kaspersky again and there has been ZERO hits on my ports in the past umpteenth weeks - I am assuming that my router and stealthed ports via software are the reason for that.

did look at my router logs before posting this and it did show "unauthorised HTTP access" on a few times in the week or so

Batman976 08-14-2003 09:56 AM

Ahh, sweet. Thanks for your help. None of the sites I found mentioned anything about '98... even in the unaffected software parts.

...I guess I just need to upgrade my computer one of these days.

Pragma 08-14-2003 02:23 PM

billege - the patch came out in July, not several months ago, but yea, I understand what you mean. I had it patched on all of my personal computers the day after the patch was out.

I heard a really interesting conspiracy theory today at work that some government agency (NSA? who knows) created and released the worm to get people to update, as everyone (Dep't Homeland Security, etc.) has been really worried about how this vulnerability hasn't been getting patched. Because if you'll notice, this worm (strangely enough) does nothing at all malicious, except bounce your computer.

I don't believe it, but it gives you something to think about.

juanvaldes 08-14-2003 03:42 PM

Pragma: apparently everyone infected is set to DOS windows update on Saturday.

Pragma 08-14-2003 04:38 PM

Amusing - when it first broke, they only "thought" it was set to DDoS WindowsUpdate. I guess I've been too busy working on other stuff at work to read updates.

I guess no "white hat" group would DDoS WindowsUpdate. So much for that conspiracy theory.

merkerguitars 08-14-2003 10:35 PM

******** UPDATE *******EASIEST WAY TO REMOVE**************

First Download this tool. Make sure you store it in a place where you can find it. http://securityresponse.symantec.com...r/FixBlast.exe this is the link to download the tool from. Don't run it or open it yet.

Next shut down your computer. Before the computer Boots press the F8 button. Then select the safe mode option. When the computer is fully booted up run the utitliy. (The screen will look funky but dont' worry about it, it's perfectly normal.)

Then after the tool has removed all the files. Download this patch and install it.

http://www.microsoft.com/technet/tre...n/MS03-026.asp here is the link for the patch...the download option is on the right hand side of the screen. Once you install that you should be virus free.

billege 08-15-2003 01:03 AM

I thought it was June, ahhh heck.

almostaugust 08-15-2003 01:35 AM

Glad it doesnt attack Windows 98, cause the worm window just appeared before.

Hanxter 08-15-2003 05:28 AM

http://tfproject.org/tfp/showthread.php?threadid=22022

Brewmaniac 08-15-2003 10:55 AM

Hell, I'm more of a novice, I checed and my auto-update on XP it did download the patch but i'm not using a firewall. Do I need to?
Is the firewall that comes with XP good enough? Is easy set up? Are there any drawbacks to firewalls?

Thanks all!

raeanna74 08-15-2003 01:32 PM

How long does this take to download over dialup? http://securityresponse.symantec.com...r/FixBlast.exe

A friend and client got the virus and I'm going to try to fix her computer tonight. She's tried to download the patch but it takes too long and is too big to get in time before the worm shuts down her windows. I'm hoping this file is smaller and takes less time. Is it possible to load this onto disk?
Any suggestions?

steveincolumbus 08-15-2003 05:31 PM

I guess everyone has seen MS's site where they have details how to remove this worm... http://www.microsoft.com/security/incident/blast.asp


All times are GMT -8. The time now is 01:12 PM.

Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0 PL2
© 2002-2012 Tilted Forum Project


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360