Forum Home
Press F1
 
Thread ID: 36509 2003-08-12 04:00:00 Careful - the msblast.exe worm is on the loose!! PressF1 User (1065) Press F1
Post ID Timestamp Content User
167032 2003-08-12 04:00:00 A new worm that exploits the Remote Procedure Call (PRC) vulnerability is doing the rounds at the moment and attacked my machine this afternoon (I'm running Windows XP Pro). I was notified by ZoneAlarm as it tried to access the internet.

Its only 6 Kb in size so is not noticed as it's being downloaded (even on 56 k), and it will reside in your windows system folder.

Watch the firewalls and make sure that your virus scanners are up to date with the latest updates.

The worm scans random ranges of IP addresses on port 135 for the security flaw. You can read more here:

www.crn.com


Cheers PF1 :-)
PressF1 User (1065)
167033 2003-08-12 04:09:00 There is a patch available to fix this exploit(You can get it throw windows update)& you can test your computer to see if port 135 is open at http://grc.com stu140103 (137)
167034 2003-08-12 04:09:00 If the other link doesn't work try this instead:

www.informationweek.com

Cheers PF1 :-)
PressF1 User (1065)
167035 2003-08-12 04:18:00 This will test your port 135 to see if you are vulnurable to attack:

grc.com

Cheers PF1 :-)
PressF1 User (1065)
167036 2003-08-12 04:50:00 McAfee has a patch too!!! KiwiTT (4082)
167037 2003-08-12 06:03:00 using nod32 yang11 (170)
167038 2003-08-12 06:30:00 Well, I'm sure this is all nice talk, but there's just one thing...

As with many cases of Microsoft flaws, the official patch for this has already been released by Microsoft.

The official security bulletin from Microsoft is available here (www.microsoft.com).

It was also released to many technology news sites, many of which advised to block port 135 with a firewall.

Over two weeks ago, I installed the patch, and blocked port 135 with Kerio.

It just so happens many users don't often listen to these security bulletins, as was the case with the Slammer and Code Red worms.
agent (30)
167039 2003-08-12 06:36:00 I am presuming you mean the patch that came out in/on about 16-18 July 03 through "windows update": KB 823980 for Microsoft Security Bulletin MS03-026 ?

Here (www.microsoft.com)

Or is there some revision to that update or something? as I am showing as up to date through "windows update"?
J ZEP (336)
167040 2003-08-12 06:40:00 Thanks Agent ;-), I thought that was the case/update - boy i am getting slow at typing, your post didn't appear till i posted mine :-) J ZEP (336)
1