*IMPORTANT* ++ Read this if your computer is forced into a shutdown.

Pages : [1] 2 3 4 5

Data
08-11-2003, 04:18 PM
Yes, we know about it.

Yes, it has happened to other people (a lot of them).

It's called the Windows DCOM RPC exploit.

Details can be found at the following links:
http://securityresponse.symantec .com/avcenter/security/Content/8205.html
http://microsoft.com/downloads/details.aspx?FamilyId=235 4406C-C5B6-44AC-9532-3DE40F69C074&displaylang=en
http://xforce.iss.net/xforce/alerts/id/147
(I will edit this post and update the list as needed.)


For now, if you're using Windows XP, you can abort the shutdowns with the command 'shutdown -a' (no quotes) at a command prompt, or in the Run dialog box. This will give you time to apply the patches and fixes listed below.

1.) Run Windows Update HERE (http://windowsupdate.microsoft.c om) and download ALL the Critical Updates. This site is getting HAMMERED right now. Here's a direct link to the XP (all versions) patch at Microsoft: PATCH YOUR SHIT, DUMBASS (http://download.microsoft.com/download/9/8/b/98bcfad8-afbc-458f-aaee-b7a52a983f01/WindowsXP-KB823980-x86-ENU.exe)

2.) Install a software firewall (at the very minimum) and block the following ports:
INBOUND TCP ON PORT 135
INBOUND TCP ON PORT 4444
INBOUND UDP ON PORT 69

Software firewalls can be found at Zone Alarm (http://www.zonealarm.com) and BlackICE (http://blackice.iss.net).

3.) Run a virus scan with the latest virus definitions using the scanner of your choice. FREE online virus scans can be found at both McAfee (http://www.mcafee.com) and Trend Micro (http://www.trendmicro.com).

4.) It's also very likely that a virus/trojan has been installed on your computer. The common variant going around is a worm called W32.Blaster.Worm that creates the file msblast.exe and sometimes(?) infects explorer.exe. Symantec has put up a tool for removing the worm HERE (http://securityresponse.symantec .com/avcenter/venc/data/w32.blaster.worm.removal. tool.html).

5.) When you've done all this, you can test your vulnerability to the exploit HERE (http://secur1ty.net/) (bottom link). You should see this:

Wait.. (could take up to 2 minutes).

[+] Connecting to [IP]

-- [IP] does not accept DCERPC protocol

Finished.


Another web-based test here: http://secur1ty.net/dcom.cgi
Results should be something like this:

Please wait, scanning your system...

[IP] does not appear to be vulnerable (unable to connect -- filtered?).


Gibson Research has his version of the test here: https://grc.com/x/portprobe=135

You can also download a small utility to check vulnerability HERE (http://www.iss.net/support/product_utilities/ms03-026rpc.php).

BlueCream
08-11-2003, 04:19 PM
Can you post a good free firewall


Also, how can i block the port its being sent through with my linksys router

Data
08-11-2003, 04:23 PM
Can you post a good free firewall


Also, how can i block the port its being sent through with my linksys router

Your router is a hardware firewall. As long as you're not setup as the DMZ (and sometimes even if you are) you can use it to block traffic. The method for this varies between routers, and I'm not familiar with yours.

BlueCream
08-11-2003, 04:32 PM
Im set up as DMZ

fatalerror
08-11-2003, 05:15 PM
apparently this is getting lost in all the stickys data. can you clean them up a bit?

iNVAR
08-11-2003, 05:16 PM
i can't unsticky them, there's really no way to clean it up

Krobar
08-11-2003, 05:21 PM
geebus thx for posting/making a sticky guys, tired of bumping my thread in GD about updating xp/2k :p

Tofutti
08-11-2003, 05:33 PM
edit: k, so apparently some people are disabling dcom after they get in to keep admins out. w/ some reg files.

Data
08-11-2003, 05:42 PM
Need more info on FTP servers please.

El Mariachi
08-11-2003, 05:51 PM
weee im not vulnerale

Cuthyone
08-11-2003, 06:13 PM
me neither :bigthumb:

Tofutti
08-11-2003, 06:23 PM
Need more info on FTP servers please.

like this: http://www.derkeiler.com/Mailing-Lists/securityfocus/incidents/2003-08/0049.html

Tofutti
08-11-2003, 06:26 PM
The service running was 'N0rton something...'. h4x0r speak gives it away.

Dac346_99
08-11-2003, 06:35 PM
My comp is ME how do I get rid of this shit? Can someone link me with directions.

Bad_CRC
08-11-2003, 06:41 PM
block INBOUND TCP ON PORT 135

heh, holy crap. :)

68.115.120.180
68.115.121.191
68.115.61.136
218.87.86.104
68.115.124.239
68.115.5.127
207.46.134.94
68.115.120.15
68.115.119.159
68.115.101.247
68.115.112.9
68.115.72.246
68.115.122.191
68.115.125.107
68.114.140.75
68.114.138.10
68.114.224.235
68.114.230.178
68.114.206.171
68.114.225.78
68.114.226.66
68.114.158.200
68.114.140.233
68.115.7.76
68.114.228.242
68.115.49.220
68.115.50.235
68.115.4.118
207.28.254.7
207.28.254.7
68.115.120.155
68.115.120.232
68.115.59.186
68.115.121.94
141.153.235.162
68.113.223.213
68.115.123.20
68.115.119.80
68.114.197.203
207.28.254.7
68.115.116.195
68.115.115.252
207.46.134.94
68.115.113.26
68.144.151.165
68.115.124.218
68.115.50.39
68.114.236.63
68.115.118.77
68.114.241.195
68.114.167.203
68.114.197.115
68.115.116.246
68.114.167.198
68.115.101.204
68.115.108.34
68.115.118.100
63.60.38.53
68.114.233.252
68.114.248.186
68.115.54.50
68.114.134.65
12.246.158.249
68.114.196.78
68.115.120.219
68.115.119.162
68.114.149.42
68.114.204.123
68.114.249.89
68.114.147.48
68.115.124.243
218.15.192.64
68.115.117.139
68.114.160.163
68.114.143.55
68.114.204.191
68.114.161.30
68.114.129.154
68.114.240.43
207.46.134.94
68.115.123.225
207.46.134.94
68.115.120.195
68.115.115.107
168.126.69.182
63.231.108.10
68.115.61.165
68.115.121.84
68.115.123.79
68.114.164.55
68.114.160.146
68.115.124.46
68.115.120.243
218.145.115.130
68.115.121.47
68.115.121.123
68.115.121.148
68.115.125.193
68.115.121.0
68.115.121.70
TCP: 135
TCP: 135
TCP: 135
UDP: 135
TCP: 135
TCP: 135
TCP: 1920
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
UDP: 33445
UDP: 33444
TCP: 135
TCP: 135
TCP: 135
TCP: 135
UDP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
UDP: 33446
TCP: 135
TCP: 135
TCP: 1820
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 17300
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
UDP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 1548
TCP: 135
TCP: 1762
TCP: 135
TCP: 135
TCP: 135
UDP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135
TCP: 135

Data
08-11-2003, 06:45 PM
My comp is ME how do I get rid of this shit? Can someone link me with directions.
This only effects NT-based operating systems. That includes Windows NT, 2000, XP (Home and Pro), and Server 2003.

Dac346_99
08-11-2003, 06:50 PM
Ive had these wierd errors where it says Error in someshit then click to restart. Isnt that the error

Data
08-11-2003, 06:52 PM
Ive had these wierd errors where it says Error in someshit then click to restart. Isnt that the error

Windows ME is not effected by this exploit. You have something else. A screenshot of the error message would be a good start...

Ghetto
08-11-2003, 06:55 PM
I had it on my XP machine got everything fixed. But I also noticed i have 3 open ports. What should I do about them?

Port 135 (RPC Endmapper) Open
Port 139 (NetBIOS) Open
Port 445 (NetBIOS over TCP/IP) Open

Ghetto
08-11-2003, 06:58 PM
Also if you are on 56k and are downloading updates and the shutdown window pops up go to Start -> Run -> shutdown -a and it will keep it from shutting down. <3 to Fonix. :)