832894 phish fix -- TCP broken

From: Clyde (b26440510_at_DELETEyahoo.com)
Date: 02/04/04


Date: Wed, 04 Feb 2004 15:49:39 -0500

System: Win2K Pro on 2.4P4 1GB RAM. Used as server for internet apps
(email, web, ftp, etc). Been running good for many years. No new
software installed for many months.

I installed Windows Update 832894 on my Win2K SP4 box yesterday. When
it asked if I wanted to restart, I said no. After I restarted later
that evening, when I opened my email client it could not connect to my
email server which runs on this machine (machine A). I opened up a
terminal window and tried to connect to port 25 -- connection refused.
I tried to connect to port 80 (running a webserver on this machine
also) -- connection refused.

I tried to telnet from machine B to machine A to port 25 -- connection
accepted, same with port 80 from B to A.

I opened up my FTP client on machine A and tried to connect to the FTP
server running on machine A -- can't connect. Telnet to port 21
showed connection refused.

Connections to the outside world from box A worked fine -- I can go to
google, etc.. The problem only happens when trying to access a port
on machine A from machine A.

I checked my Ghost image files and the latest one I had was from
10/2003 so I tried fixing the current install.

Patch 832894 shows no information for rolling the patch back. It does
not show up in Add/Remove.

Made a ghost image of my current Win2K partition. Tried uninstalling
SP4 -- connection refused. Reinstalled SP4 -- connection refused.
Tried repairing IE6 -- connection refused. Tried uninstalling and
installing IE6 -- connection refused. Tried repairing Win2K from CD
-- connection refused.

Finally restored my Ghost image from 10/03 and everything works.

I called MS' virus and security number 800-PCSECURITY. Unfortunately
the lady on the other end didn't seem to understand at all. She kept
telling me to contact my ISP and they could issue me a new IP number,
blah, blah. After a few more minutes, she said that it sounded like
an ISP issue and I told her that 127 addresses don't get outside the
local network so the ISP didnt have anything to do with it. Then she
said if I ever got the virus removed, and I informed her that the
patch was to fix vulnerabilities, it had nothing to do with viruses.

She eventually gave me a ticket number (146276720) and said it would
be sent to escalation and they'd call back. Then I called MS support
and eventually got to Win2K support. Told them the symptoms. They
said they could check if the patch could cause it but if not they'd
charge me for support. I told them I was simply trying to let MS know
that there could be an issue with the patch.



Relevant Pages

  • Re: Event ID 6161 for HP 6840
    ... patch related to an exposure via the print spooler service. ... download which offers the option of a local port. ... >> There were no problems with the install and the printer works find so long ... >> 3) All machines on the network can connect to the printer via Internet ...
    (microsoft.public.windowsxp.print_fax)
  • Re: Shame on Microsoft
    ... I'm not even going to waste my time rereading the original advisory. ... All I remember is the port numbers and patch install. ...
    (microsoft.public.security)
  • Re: Shame on Microsoft
    ... They specifically mentioned using the firewall on XP till the ... the port till the patch was installed. ... >> don't use a firewall or couldn't install the patch. ...
    (microsoft.public.security)
  • Win2k disabled after loading sasser patch
    ... my win2k machine. ... On rebooting after the install on my pc though, ... I have no idea if it has the sasser patch or not, ... I did have sp4 prior to this event. ...
    (microsoft.public.win2000.setup)
  • Win2k disabled after loading sasser patch
    ... my win2k machine. ... On rebooting after the install on my pc though, ... I have no idea if it has the sasser patch or not, ... I did have sp4 prior to this event. ...
    (microsoft.public.win2000.security)