RE: MSBLASTER Infecting despite 03-026 patch?

From: James C. Slora, Jr. (Jim.Slora_at_phra.com)
Date: 08/13/03

  • Next message: Charles Hamby: "RE: MSBLASTER Infecting despite 03-026 patch?"
    Date: Tue, 12 Aug 2003 19:56:32 -0400
    To: <incidents@securityfocus.com>
    
    

    enigmatech wrote
    > I can confirm this. I discovered the worm when it attempted (and
    failed)
    > to infect my machine (Win XP pro) this afternoon. Immediately after
    > securing the firewall setting that left me vulnerable to the port 135
    > attack I checked windowsupdate.microsoft.com and confirmed that I had
    in
    > fact installed the patch a few weeks earlier. While security software
    on
    > my system prevented the overflow payload from using tftp the payload
    > managed to terminate the RPC svchost process twice forcing a system
    > halt. This is similar to the effects of the WinNuke exploitation of a
    > similar overflow bug in RPC earlier in the year.

    It sounds like your system may be vulnerable to other RPC exploits
    besides Blaster, and like it might be worthwhile reapplying the patch.

    Windows Update definitely is not a good indicator of whether the patch
    is installed. Neither is add/remove programs. Windows Update and
    UpdateExpert don't verify the files that are on the system because they
    are optimized for speed rather than accuracy. They merely check a
    registry entry that gets added by the patch. So they can't tell you if
    your system is patched, but they can give an indication that the patch
    installation routine was run at some time or another. Add/remove
    programs tells you that the patch was installed but does not tell you if
    the patch's files were overwritten by some other installation or update.

    One specific case in Win2K that causes the machine to appear patched
    when it is not:
    Install Win2K SP4, don't reboot, then install the RPC patch and reboot.
    XP probably has some similar combinations that result in failure even
    though your system reports success.

    Microsoft's MBSA or Shavlik's HFNetChk should give a good answer about
    whether the correct files are installed, and eEye's free Retina RPC
    scanner can tell you from an external perspective whether or not your
    system is vulnerable.

    It is probably best to use multiple tools to verify the system's status.

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: Charles Hamby: "RE: MSBLASTER Infecting despite 03-026 patch?"

    Relevant Pages

    • Re: Project isnt showing project data; just a white pane. Any id
      ... "CaptainTact" wrote: ... I know that will add a lot of time to the installation ... but it would eventually tell us which patch is causing the problem. ... Windows Update and installed all the XP and Office related patches it said I ...
      (microsoft.public.project)
    • Re: Critical Update for Windows Media Player Script Commands (KB828026)
      ... See http://www.nwlink.com/~zachd/pss/pss.html for some helpful WMP info. ... (Windows Update Installation ... > History shows that the Patch has been installed 4 times). ... > Are there any know issues with the installation of this ...
      (microsoft.public.windowsmedia.player)
    • Re: Project isnt showing project data; just a white pane. Any id
      ... If you do wind up reformatting and reinstalling everything, ... I know that will add a lot of time to the installation ... but it would eventually tell us which patch is causing the problem. ... Windows Update and installed all the XP and Office related patches it said I ...
      (microsoft.public.project)
    • Security Patch without SP-1 - Problem?
      ... Windows Update program. ... The patch scan tool ... you had already installed, the previous installation ... Win Update also pulls up SP-1 as a critical update. ...
      (microsoft.public.windowsxp.security_admin)
    • Re: Files required to use Windows Update are no longer registered
      ... Windows Update was not working. ... This will ensure that required system files are present. ... then it would behoove you to do a Repair Installation. ... I clicked on 'install' and then got the usual error message "Files required ...
      (microsoft.public.windowsupdate)