August 13, 2003, 22:08
|
#1
|
Chieftain
Local Time: 07:21
Local Date: November 2, 2010
Join Date: Nov 2001
Posts: 52
|
MSBlast.exe (virus)
This virus is amazing in how easy it is to catch. Yesterday I was just finished putting together a new system, and was installing W2K. My computer kept getting an RPC error and shutting down. I tried everything to fix it. (i never once had even enough time to install a single critical-up date), so I would end up reinstalling W2K (did that 3 times). Then during the 3rd install I read about the virus on another computer that was there. I was curious, so right after the install I opened search and looked for MSBLAST. Nothing. Ok, so about 2 min into installing service pack 4 and I get RPC error. I do search on my system and sure enough, MSBLAST.
I have never seen (i have heard/read though) a virus that infects a system before you have downloaded ANYTHING.
I hate to give this guy/gal any credit but whoever is responsible for this huge pain in the arse, is one smart cookie.
http://www.computing.net/windowsxp/w...rum/73575.html
__________________
" Conceit, arrogance, and egotism are the essentials of patriotism." - Emma Goldman
William Seward Burroughs
February 5, 1914 - August 2, 1997 R.I.P. Uncle Bill, you are missed.
|
|
|
|
August 13, 2003, 22:11
|
#2
|
President of the OT
Local Time: 01:21
Local Date: November 2, 2010
Join Date: Nov 1999
Location: Calgary, Alberta
Posts: 40,843
|
Actually it's very poor code and design.
It's just such an easy exploit.
__________________
"I'll never doubt you again when it comes to hockey, [Prince] Asher." - Guynemer
|
|
|
|
August 13, 2003, 22:13
|
#3
|
Emperor
Local Time: 03:21
Local Date: November 2, 2010
Join Date: Mar 2003
Location: Having tea with the Third Man...
Posts: 6,169
|
Clever, maybe, but I don't know that I'd call anybody who makes computer viruses "smart." What kind of degenerate schlep spends that much time designing newer and better ways of irritating people for no personal profit? Is there some sort of sexual pleasure in it for them, or are they too dumb to just do straight identity theft like their more enterprising nerd compatriots?
__________________
"May I be forgiven for the ills that I have done/Friends I have forsaken and strangers I have shunned/Sins I have committed, for which others had to pay/And I haven't met the whiskey that can wash those stains away."
-Brady's Leap, "Wash."
|
|
|
|
August 13, 2003, 22:14
|
#4
|
PolyCast Thread Necromancer
Local Time: 07:21
Local Date: November 2, 2010
Join Date: Jul 2002
Location: We are all Asher now.
Posts: 1,437
|
Too bad theyre wasting their talents. They could be getting quite a bit of money.
|
|
|
|
August 13, 2003, 22:14
|
#5
|
Emperor
Local Time: 19:21
Local Date: November 2, 2010
Join Date: Aug 2002
Location: Mad.
Posts: 4,142
|
Most computers have their NetBIOS port open by default (a MS Windows flaw). This enables anyone to access your files, and even set up your computer as a hidden webserver. As such, just going on the internet can let in the worm through the open port and into your computer.
It's just as easy to close the port. Why MS doesn't do this by default...
|
|
|
|
August 13, 2003, 22:17
|
#6
|
Chieftain
Local Time: 07:21
Local Date: November 2, 2010
Join Date: Nov 2001
Posts: 52
|
Quote:
|
Originally posted by Elok
Clever, maybe, but I don't know that I'd call anybody who makes computer viruses "smart." What kind of degenerate schlep spends that much time designing newer and better ways of irritating people for no personal profit? Is there some sort of sexual pleasure in it for them, or are they too dumb to just do straight identity theft like their more enterprising nerd compatriots?
|
For some of them, I think it's a kind of "stick it to MS thing" this one more so 'cause it is set up to start a DOS attack on Microsoftupdate.com (on aug 16th I think..? )
__________________
" Conceit, arrogance, and egotism are the essentials of patriotism." - Emma Goldman
William Seward Burroughs
February 5, 1914 - August 2, 1997 R.I.P. Uncle Bill, you are missed.
|
|
|
|
August 13, 2003, 22:21
|
#7
|
King
Local Time: 01:21
Local Date: November 2, 2010
Join Date: Sep 2002
Posts: 2,394
|
It's good that the worm only reboots your machine and DoS's a website. Imagine if it was truly destructive so that you could not recover from it...
__________________
meet the new boss, same as the old boss
|
|
|
|
August 13, 2003, 22:28
|
#8
|
Emperor
Local Time: 02:21
Local Date: November 2, 2010
Join Date: Oct 2000
Location: In Exile
Posts: 4,140
|
I think people who **** with other people's computers should be taken out by a bunch of illiterate rednecks and beaten twice a day.
__________________
Which side are we on? We're on the side of the demons, Chief. We are evil men in the gardens of paradise, sent by the forces of death to spread devastation and destruction wherever we go. I'm surprised you didn't know that. --Saul Tigh
|
|
|
|
August 13, 2003, 22:29
|
#9
|
King
Local Time: 01:21
Local Date: November 2, 2010
Join Date: Sep 2002
Posts: 2,394
|
Well, viruses are both good and bad.
If there were no viruses, people wouldn't give a **** about virus security. (They wouldn't need to if there were no viruses, though, right? Although there's no shortage of 14 year olds looking for holes in MS products.)
On the other hand, malicious virus writers should be taken out and shot.
__________________
meet the new boss, same as the old boss
|
|
|
|
August 13, 2003, 22:33
|
#10
|
Emperor
Local Time: 03:21
Local Date: November 2, 2010
Join Date: Mar 2003
Location: Having tea with the Third Man...
Posts: 6,169
|
Quote:
|
Originally posted by Blisterz
For some of them, I think it's a kind of "stick it to MS thing" this one more so 'cause it is set up to start a DOS attack on Microsoftupdate.com (on aug 16th I think..? )
|
Maybe, but with their collective skills you'd think they'd be able to just design some sort of assassin robot, sic it on Gates, and leave the rest of us alone. Or just sublimate their rage through porno and Starcraft like good little nerds. Whatever. Anything's better than making MS software harder and more contrary to use than it already is, right? You'd think...
__________________
"May I be forgiven for the ills that I have done/Friends I have forsaken and strangers I have shunned/Sins I have committed, for which others had to pay/And I haven't met the whiskey that can wash those stains away."
-Brady's Leap, "Wash."
|
|
|
|
August 13, 2003, 23:57
|
#11
|
Deity
Local Time: 09:21
Local Date: November 2, 2010
Join Date: Sep 2001
Location: Republic of Flanders
Posts: 10,747
|
Who's to say, Norton and affiliates don't write them themselves...
__________________
#There’s a city in my mind
Come along and take that ride
And it’s all right, baby, it’s all right #
|
|
|
|
August 14, 2003, 00:10
|
#12
|
Civ4: Colonization Content Editor
Local Time: 08:21
Local Date: November 2, 2010
Join Date: Dec 2001
Posts: 11,117
|
An operating is **** if it can be knocked out with such an amazing ease. But still Asher is right, it's crappy coded. It was designed to DoS the Windows update website, but in the most cases it fails its purpose and just makes the computer crash. Probably the product of some geek who should better care about his acne.
|
|
|
|
August 14, 2003, 00:10
|
#13
|
President of the OT
Local Time: 01:21
Local Date: November 2, 2010
Join Date: Nov 1999
Location: Calgary, Alberta
Posts: 40,843
|
Sir Ralph: Tell everyone where the RPC code comes from...
__________________
"I'll never doubt you again when it comes to hockey, [Prince] Asher." - Guynemer
|
|
|
|
August 14, 2003, 00:12
|
#14
|
President of the OT
Local Time: 01:21
Local Date: November 2, 2010
Join Date: Nov 1999
Location: Calgary, Alberta
Posts: 40,843
|
People overestimate how hard it is to make worms like this...and somehow that equates to the guy doing it being intelligent or something.
If somebody went in and shot up a bank, the guy isn't exactly that smart, regardless of how well planned out it was.
__________________
"I'll never doubt you again when it comes to hockey, [Prince] Asher." - Guynemer
|
|
|
|
August 14, 2003, 00:18
|
#15
|
Civ4: Colonization Content Editor
Local Time: 08:21
Local Date: November 2, 2010
Join Date: Dec 2001
Posts: 11,117
|
Quote:
|
Originally posted by Asher
Sir Ralph: Tell everyone where the RPC code comes from...
|
Ummm, that was Solaris, wasn't it? Not sure, though. Makes me wonder why Solaris apparently doesn't have any problems (and never had). Ah well, some people can't even properly steal . Perhaps it's so, because next to nobody runs Solaris and no cracker could be arsed to write a worm to attack some 52 or 53 computers.
|
|
|
|
August 14, 2003, 00:23
|
#16
|
President of the OT
Local Time: 01:21
Local Date: November 2, 2010
Join Date: Nov 1999
Location: Calgary, Alberta
Posts: 40,843
|
No, it was an open source OS...think on it.
Hint: It wasn't a GNU-licensed OS.
__________________
"I'll never doubt you again when it comes to hockey, [Prince] Asher." - Guynemer
|
|
|
|
August 14, 2003, 00:39
|
#17
|
Emperor
Local Time: 03:21
Local Date: November 2, 2010
Join Date: Sep 1999
Posts: 3,361
|
Honestly, the worm wasn't a big deal, but I am sorta glad for msblast: it made MS get off their butts and come up with a fix before some SERIOUSLY malicious software abused this security hole.
I think that was the point of it anyway.
|
|
|
|
August 14, 2003, 00:42
|
#18
|
President of the OT
Local Time: 01:21
Local Date: November 2, 2010
Join Date: Nov 1999
Location: Calgary, Alberta
Posts: 40,843
|
Um. The fix for the hole MSBlast exploits was out almost a month before MSblast...
__________________
"I'll never doubt you again when it comes to hockey, [Prince] Asher." - Guynemer
|
|
|
|
August 14, 2003, 00:44
|
#19
|
Emperor
Local Time: 03:21
Local Date: November 2, 2010
Join Date: Sep 1999
Posts: 3,361
|
Was it really? oh well, must have missed it. Was a pretty stupid worm, and it didn't even work like it was supposed to on my system.
|
|
|
|
August 14, 2003, 00:47
|
#20
|
President of the OT
Local Time: 01:21
Local Date: November 2, 2010
Join Date: Nov 1999
Location: Calgary, Alberta
Posts: 40,843
|
I told people to patch immediately as a worm was inevitable, last month: http://apolyton.net/forums/showthrea...threadid=93099
__________________
"I'll never doubt you again when it comes to hockey, [Prince] Asher." - Guynemer
|
|
|
|
August 14, 2003, 00:57
|
#21
|
Emperor
Local Time: 03:21
Local Date: November 2, 2010
Join Date: Sep 1999
Posts: 3,361
|
Ahh! See, I was getting ready to move, and I didn't have internet in the new place till recently. Just wasn't paying attention.
|
|
|
|
August 14, 2003, 01:41
|
#22
|
Emperor
Local Time: 03:21
Local Date: November 2, 2010
Join Date: Mar 1999
Location: San Antonio, TX
Posts: 4,264
|
That Asher... always looking after our asses.
...uhhhh...
|
|
|
|
August 14, 2003, 03:46
|
#23
|
Civ4: Colonization Content Editor
Local Time: 08:21
Local Date: November 2, 2010
Join Date: Dec 2001
Posts: 11,117
|
Quote:
|
Originally posted by Asher
No, it was an open source OS...think on it.
Hint: It wasn't a GNU-licensed OS.
|
Must have been a BSD then. On Linux I've heard them called SunRPC, that's why I thought they came from Solaris. I don't use RPCs at all, they are a security risk on either OS. By the way, my router gets bombed with 135 requests. Just drops them of course.
A friend of my wife caught the worm already. She was shocked and helpless when she called me. Made me think... 3 months ago I set her up that computer. It came shipped with XP Home, but I seriously considered to install a Debian+Gnome on it, since she is a bloody newbie. I should have done so, even more since she lives 700 km away, and these service calls every 2 weeks drive me nuts.
|
|
|
|
August 14, 2003, 04:04
|
#24
|
Deity
Local Time: 15:21
Local Date: November 2, 2010
Join Date: May 1999
Location: The City State of Noosphere, CPA special envoy
Posts: 14,606
|
Quote:
|
Originally posted by Asher
Actually it's very poor code and design.
It's just such an easy exploit.
|
Thanks to MS, of course.
__________________
(\__/) 07/07/1937 - Never forget
(='.'=) "Claims demand evidence; extraordinary claims demand extraordinary evidence." -- Carl Sagan
(")_(") "Starting the fire from within."
|
|
|
|
August 14, 2003, 05:01
|
#25
|
King
Local Time: 00:21
Local Date: November 2, 2010
Join Date: Dec 1969
Location: Melbourne
Posts: 2,963
|
I probably should have done something about it last month rather than yesterday.
__________________
Hold my girlfriend while I kiss your skis.
|
|
|
|
August 14, 2003, 06:52
|
#26
|
Emperor
Local Time: 02:21
Local Date: November 2, 2010
Join Date: Feb 2002
Location: Back in BAMA full time.
Posts: 4,502
|
I cant be sure its MSBlast but a worm has brought down bagfulls of PC's at my work. They just try to boot up and get into some kinda loop.
|
|
|
|
August 14, 2003, 07:07
|
#27
|
King
Local Time: 09:21
Local Date: November 2, 2010
Join Date: Jun 2001
Location: of genial epicuri
Posts: 1,570
|
I blame MicroSoft, it's their fault, their shitty software, that is causing all this pain in my ass
__________________
Que l’Univers n’est qu’un défaut dans la pureté de Non-être.
- Paul Valery
|
|
|
|
August 14, 2003, 10:18
|
#28
|
Deity
Local Time: 10:21
Local Date: November 2, 2010
Join Date: Sep 2000
Location: Latvia, Riga
Posts: 18,355
|
ILOVEYOU was excellent code .
They don't cause any harm, people. OK, this one restarts your data. But it's very easy to make it erase all data on harddrive after 3 days. I think, if ILOVEYOU did that, how bad would it have been?
__________________
Solver, WePlayCiv Co-Administrator
Contact: solver-at-weplayciv-dot-com
I can kill you whenever I please... but not today. - The Cigarette Smoking Man
|
|
|
|
August 14, 2003, 10:23
|
#29
|
Emperor
Local Time: 03:21
Local Date: November 2, 2010
Join Date: Mar 1999
Location: San Antonio, TX
Posts: 4,264
|
Quote:
|
Originally posted by laurentius
I blame MicroSoft, it's their fault, their shitty software, that is causing all this pain in my ass
|
So, if somebody pours sugar in your gas tank, that is the fault of the manufacturer?
|
|
|
|
August 14, 2003, 10:30
|
#30
|
King
Local Time: 07:21
Local Date: November 2, 2010
Join Date: Oct 2002
Location: Birmingham, AL
Posts: 1,595
|
Quote:
|
It's just as easy to close the port. Why MS doesn't do this by default...
|
But this virus attacks through port 135 instead of 137, 138, or 139, which I don't think can be closed on a Microsoft machine.
|
|
|
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is On
|
|
|
All times are GMT -4. The time now is 03:21.
|
|