Re: There seems to be a massive denial of service attack going on

From: Jupiter Jones [MVP] (jones_jupiter_at_hotnomail.com)
Date: 08/12/03


Date: Mon, 11 Aug 2003 16:27:57 -0600


Rainie;
Microsoft is not really doing much right now.
However Microsoft did release the patch a few weeks ago to protect
against this very issue.

First, IMMEDIATELY disconnect from the internet before a "friend"
leaves a gift on your computer for you.
DO NOT reconnect until this issue is resolved.

Install or enable a firewall immediately.
http://support.microsoft.com/?kbid=283673

Run an updated virus scan.
Or Scan for Viruses online:
http://security.symantec.com/ssc/home.asp?j=1&langid=ie&venid=sym&plfid=23&pkj=IRLFIZTYMWPAZTJWUFJ

Also be sure to update immediately to prevent this in the future:
http://windowsupdate.microsoft.com/

This will tell you more:
http://www.microsoft.com/security/security_bulletins/ms03-026.asp

-- 
Jupiter Jones  [MVP]
An easier way to read newsgroup messages:
http://www.microsoft.com/windowsxp/pro/using/newsgroups/setup.asp
http://dts-l.org/index.html
"rainie klein" <rainieklein@msn.com> wrote in message
news:04cc01c36054$3d58e060$a401280a@phx.gbl...
> it seem to me that it is a virus,  I don't know what ms is
> doing about this issue I just receive this patch for the
> hole the virus is getting in through.  Our phones jumped
> off the hook about 10 minutes when I came into work.  I
> came here to see what was going on and I saw all these
> people with the same issues... IS THERE ANYTHING i CAN DO
> TO HELP ???  i COULD I EMAIL YOU ANYTHING?
>
> -RAINIE
> >-----Original Message-----
> >I too am seeing many of my clients remote PC's going down
> with this same RPC
> >and COM+  errors. The NT Authority auto shutdown that
> everyone is talking
> >about.
> >
> >
> >Basically all our users behind a firewall are not
> experiencing this problem.
> >Remote users that acces the interent and then come to our
> servers by way of
> >terminal connection are dropping like flies.
> >We have lost many systems today all going down one after
> another.
> >
> >These remote systems, since they use slow dialup were not
> patched against
> >this RPC exploit. We are trying to now but MS site seems
> swamped and we are
> >unable.  Fortunately these people can stay up because
> they can RAS into our
> >firewalled site and then user their browser to get the
> update. Users that
> >only have internet access can not stay up long enough to
> get updates.
> >
> >All systems affected have the MSBlast.exe file that some
> poeple have talked
> >about.
> >
> >Does any security person know whats going on?
> >
> >How is the DOS working? Where is it coming from? Any word
> from Symantec or
> >Macafee on what msblast.exe is and what other files may
> have been affected?
> >
> >
> >
> >.
> >


Relevant Pages

  • Re: [Full-disclosure] Security Alert: Unofficial IE patches appear on internet
    ... created by a vulnerability is as serious as this case and the available ... Microsoft will be inclined strongly against holding on to this patch. ... Microsoft often have patches ready but wait for the corporate known ...
    (Full-Disclosure)
  • Re: Worm in Patch
    ... a naive and trusting nature in your personality believing that you would ... "receive a patch" instead of getting it from a trusted source..? ... Essentially - Microsoft never emails you a patch. ... using Windows XP "prettifications". ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Why do i keep on receiving shutdown system ?
    ... the Microsoft provided information on the matter can be ... The Symantec Repair utility and manual removal instructions can be found ... The patch that would have prevented this whole fiasco for you: ... If you have Sasser, the Microsoft provided information on the matter can be ...
    (microsoft.public.windowsxp.security_admin)
  • Re: NT Authority..
    ... You could have Blaster or you could have Sasser. ... the Microsoft provided information on the matter can be ... The patch that would have prevented this whole fiasco for you: ... After enabling the Internet Connection Firewall or creating the read-only ...
    (microsoft.public.windowsxp.help_and_support)
  • So Windows Update is a dog, now what?
    ... extension, that means that the soon-to-be-released Windows Update, ... How about someone getting serious about patch management over at ... In their explanation of the severity rating scheme, the Microsoft ... incredibly reliable mechanism for getting patches onto systems, ...
    (NT-Bugtraq)