Open Tech Support
Open 

Tech Support Community
Back to HomeCommunityReviewsGuidesDownloadsLinkageMarketplaceContact Us

 »  Forum Navigation

Home
Post a Question
About Our Site
Support Our Site

What is this site?
Who are we?

Tolitz.Com - The Cynic Eye of the Third World Guy

Enhanced with Snapshots

 

 »  Advertisement


Go Back   Open Tech Support Community > NEWS FORUMS > General News




Comment

 

LinkBack Article Tools
Remote Procedure Call Errors? Web Worm is the Blame...
Published by Canis Lupus
08-11-2003
Remote Procedure Call Errors? Web Worm is the Blame...

SAN FRANCISCO (Reuters) - An Internet worm that takes advantage of a recently discovered, widespread security hole in Microsoft Corp.'s MSFT.O Windows software emerged around the United States on Monday, crashing systems and spreading to vulnerable computers, security experts said.

The worm, dubbed LoveSan, Blaster, or MSBlaster, exploits a vulnerability in the Distributed Component Object service that is hosted by a Remote Procedure Call feature in Windows 2000 and Windows XP.

Once it gets onto a vulnerable computer, the program downloads code from a previously infected machine that enables it to propagate itself. Then, it scans the Internet for other vulnerable machines and attacks them, said Johannes Ullrich, chief technology officer at the Internet Storm Center at the SANS Institute.


Those who have been experiencing "Remote Procedure Call" errors resulting in countdowns to shutdowns (heh) should visit this link: http://www.microsoft.com/technet/tre...n/MS03-026.asp

And make sure to download the corresponding patch for your Windows operating system.
Click here for more info on the worm.

Article Tools


Search on Newegg.Com



  #1 (permalink)  
By d!g!talhardcore on 08-11-2003, 08:21 PM
I got that garbage today, I was reformatting my computer and I was wondering what the hell was going on. I got it taken care of, fortunately it was something simple, but a major pain.
Reply With Quote
  #2 (permalink)  
By Null Actor on 08-11-2003, 09:03 PM
Also fun is how hackers and script kiddies can use the RPC bug to get in your system. My box was compromised for about 8 minutes saturday night. Till I ousted them with extreme prejudice.
Reply With Quote
  #3 (permalink)  
By fibbi on 08-11-2003, 09:24 PM
what did you oust em with?
Reply With Quote
  #4 (permalink)  
By Null Actor on 08-11-2003, 09:30 PM
Evil.
Reply With Quote
  #5 (permalink)  
By d!g!talhardcore on 08-11-2003, 09:33 PM
Quote:
Originally posted by Null Actor
Evil.
Nice, teach those beehotches a lesson
Reply With Quote
  #6 (permalink)  
By Daedleus on 08-11-2003, 09:43 PM
Link to the security patch here.
Last edited by Daedleus; 08-11-2003 at 09:50 PM..
Reply With Quote
  #7 (permalink)  
By Shalome on 08-11-2003, 09:59 PM
For the Good of the Internet, Patch your Windows!

Update posted by Shalome:

So due to the recent Microsoft Security Bulletin regarding the vulnerability of Microsoft RPC (Remote Procedure Call) ports.. please, for the love of the internet, patch your Windows operating system!

Between the botnets that are currently attempting to exploit this hole in the operating system and the general malicious things people can do with this code exploit, it's in your best interest (and the general interest of the internet around you) to patch your system and avoid becoming a victim of what security experts are calling MSBILLY or MSBLASTER.

The guys at DShield.org posted the first analysis of this worm, which does the following damage:

1. SOURCE sends packets to port 135 tcp with variation of dcom.c exploit to TARGET
2. this causes a remote shell on port 4444 at the TARGET
3. the SOURCE now sends the tftp get command to the TARGET, using the shell on port 4444,
4. the target will now connect to the tftp server at the SOURCE.

Keep the internet safe! Patch your systems as soon as possible! If you can't patch your systems, at least block ports 135, 137, 445, and 4444 at your firewalls, both inbound and outbound. If you're in charge of routers and gateways, block these Microsoft ports if you haven't already...

One more update... if you've got this worm, Symantec has released a Removal Tool.
Last edited by Shalome; 08-12-2003 at 07:39 AM..
Reply With Quote
  #8 (permalink)  
By SKYHN on 08-11-2003, 10:04 PM
Whenever I run windows update after one of these "patches" come out, theres never anything for me to download.
Reply With Quote
  #9 (permalink)  
By Shalome on 08-11-2003, 10:07 PM
Good for you, SKYHN. Now. of only the rest of the internet would follow your example...
Reply With Quote
  #10 (permalink)  
By Null Actor on 08-11-2003, 10:10 PM
I blame you for me getting hacked you know.
Reply With Quote
  #11 (permalink)  
By SKYHN on 08-11-2003, 10:14 PM
Quote:
Originally posted by Shalome
Good for you, SKYHN. Now. of only the rest of the internet would follow your example...
But why is it that theres never anything for me to download? Is it because Im still living in the past using WinME and im unaffected?
Reply With Quote
  #12 (permalink)  
By Null Actor on 08-11-2003, 10:14 PM
Actually, this particular bug doesn't affect WinME. Funny, that.
Reply With Quote
  #13 (permalink)  
By Shalome on 08-11-2003, 10:18 PM
Null, it was me who hacked you anyway. So NNYAAAH. :P
Reply With Quote
Comment

Bookmarks

Article Tools


Similar Threads

Article Article Starter Category Comments Last Post
Windows 98...internet explorer won't launch dadeogba Software 1 03-04-2004 02:38 AM
The Windows 2000 Corporate Workstation Performance Guide OTS Staff Software 0 02-21-2002 09:48 PM
XP's Gotchas Tweaker Software 2 12-15-2001 11:44 AM
Windows xp & internet security rondon Software 1 11-19-2001 05:10 PM
Why you should buy Windows 2000 Ion Silverbolt Software 6 12-22-2000 11:14 PM







Powered by vBulletin® Version 3.8.2. Copyright © 2000-2010, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.2

Article powered by GARS 2.1.9 ©2005-2006
Copyright 2000-2008 Open Tech Support.  All Rights Reserved.  Site Design and Development by Tolitz Rosel.