Re: "Messenger Service screens

From: Bruce Chambers (bchambers_at_nospamcableone.net)
Date: 04/24/04


Date: Sat, 24 Apr 2004 11:50:13 -0600

Greetings --

    It's a scam, plain and simple. It's from a very unscrupulous
"business." They're trying to sell you patches that Microsoft
provides free-of-charge. It's also demonstrating that your PC is very
unsecure.

    This type of spam has become quite common over the past year or
so, and unintentionally serves as a valid security "alert." It
demonstrates that you haven't been taking sufficient precautions while
connected to the Internet. Your data probably hasn't been compromised
by these specific advertisements, but if you're open to this exploit,
you most definitely open to other threats, such as the Blaster Worm
that still haunts the Internet. Install and use a decent, properly
configured firewall. (Merely disabling the messenger service, as some
people recommend, only hides the symptom, and does little or nothing
to truly secure your machine.) And ignoring or just "putting up with"
the security gap represented by these messages is particularly
foolish.

Messenger Service of Windows
http://support.microsoft.com/default.aspx?scid=KB;en-us;168893

Messenger Service Window That Contains an Internet Advertisement
Appears
http://support.microsoft.com/?id=330904

Stopping Advertisements with Messenger Service Titles
http://www.microsoft.com/windowsxp/pro/using/howto/communicate/stopspam.asp

Blocking Ads, Parasites, and Hijackers with a Hosts File
http://www.mvps.org/winhelp2002/hosts.htm

  Whichever firewall you decide upon, be sure to ensure UDP ports 135,
137, and 138 and TCP ports 135, 139, and 445 are _all_ blocked. You
may also disable Inbound NetBIOS (NetBIOS over TCP/IP). You'll have
to follow the instructions from firewall's manufacturer for the
specific steps.

    You can test your firewall at:

Symantec Security Check
http://security.symantec.com/ssc/vr_main.asp?langid=ie&venid=sym&plfid=23&pkj=GPVHGBYNCJEIMXQKCDT

Security Scan - Sygate Online Services
http://www.sygatetech.com/

    Oh, and be especially wary of people who advise you to do nothing
more than disable the messenger service. Disabling the messenger
service, by itself, is a "head in the sand" approach to computer
security. The real problem is _not_ the messenger service pop-ups;
they're actually providing a useful, if annoying, service by acting as
a security alert. The true problem is the unsecured computer, and
you've been advised to merely turn off the warnings. How is this
helpful?

Bruce Chambers

--
Help us help you:
http://dts-l.org/goodpost.htm
http://www.catb.org/~esr/faqs/smart-questions.html
You can have peace.  Or you can have freedom.  Don't ever count on 
having both at once. -- RAH
"MikeS" <michael@careof.me.uk> wrote in message 
news:O223OYhKEHA.3216@tk2msftngp13.phx.gbl...
> Hi,
>
> Newly connected to ADSL/broadband. For the 1st time I'm receiving 
> messages
> on my desktop screen. Some are obviously fake, but this one below 
> makes me
> nervous.......
>
> So, my security query is, is this kosher?
>
> On the desk top screen I'm receiving messages on a panel headed 
> Messenger
> Service.
>
> Reads:
> " Message from Microsoft Networks to Windows users.
> Microsoft Security bulletin  MS03-043.
> Buffer overun in Messenger Service. Could allow Code Execution 
> (828035)
> Affected Software:  Win NT, 2000, XP.....etc
>
> Your system is affected - download patch from address below. Type 
> address
> below in browser  .....www.windows-patch.info  "
>
>
> many thanks MikeS
>
> Humour on PC desktop:
>  Error message # 1... Universe.confg   corrupt.
>  Reboot big-bang.exe  (y/n)
>
> 


Relevant Pages

  • Re: Annoying Messenger Pop_ups
    ... (Disabling the messenger service, as ... Messenger Service of Windows ... service is a "head in the sand" approach to computer security. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Messenger Service
    ... >> What is unwise from a security standpoint is to run any services that ... If you don't need the Messenger Service, ... >> firewall is down is bad. ... >While it is true that firewall plus disabling services is more secure ...
    (microsoft.public.win2000.security)
  • Re: POPUPS
    ... (Merely disabling the messenger ... "putting up with" the security gap represented by these messages is ... Messenger Service Window That Contains an Internet Advertisement ... a security alert. ...
    (microsoft.public.windowsxp.general)
  • Re: contacting Microsot
    ... sell you patches and information that Microsoft already provides, ... the security gap represented by these messages is particularly ... Messenger Service of Windows ... > some website for updates or patches. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Popups
    ... Microsoft sent, you've been installing viruses. ... rely upon this PC for your business needs, ... something about computer security. ... Messenger Service Window That Contains an Internet Advertisement ...
    (microsoft.public.windowsxp.security_admin)

Loading