PDA

View Full Version : Awas kepada pengguna WinDO$ Why2K keatas.


root
12-08-03, 11:13 AM
Cecacing/ulat MSBLATER dikatakan sedang mula menyerang sistem anda. Patch cepat-cepat sistem anda.... Kalau anda ada pendinding-api, DROP kan port 135.

http://isc.sans.org/diary.html?date=2003-08-11

farking
12-08-03, 11:31 PM
Kat sini ada gak posting ni? So aku isi benda yg sama le..

Sedikit tambahan dan pembetulan. Worm ini tidak terbatas kepada sistem operasi Win2K sahaja:

Microsoft Windows NT 4.0
Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Server 2003

Worm/cecacing ini mengambil kesempatan di atas vulnerability DCOM RPC yang diumumkan baru-baru ini.

Maklumat lanjut sila rapat umum ke:

http://www.cert.org/advisories/CA-2003-20.html (CERTŪ Advisory CA-2003-20 W32/Blaster worm)
http://www.securityfocus.com/news/6689 (RPC DCOM Worm Hits the Net)
http://www.cert.org/advisories/CA-2003-19.html (Exploitation of Vulnerabilities in Microsoft RPC Interface)
http://microsoft.com/technet/security/bulletin/MS03-026.asp (Microsoft Security Bulletin)

farking
13-08-03, 09:39 AM
HEhehe freehill. Kawan aku dah kena, pc dia asik reboot ke. Dia call aku ckp RPC tu error le so aku suh dia dload patch tu le..nasib baik line dia laju.

Tatau lak ada cara abort sequence tu. Thanks for your tips..

minhaj
13-08-03, 10:46 AM
thanx for the info....

tengah update patch.....
setakat ni....
biler tekan tiga2 button tu...takde la proses msblast.exe tu.....

chadtce
13-08-03, 10:46 AM
Slackware box aku tak pernah bukak port 135 tu... :) :D Ehee..he..he.. :)

farking
13-08-03, 10:49 AM
Slackware tu menggunakan sistem operasi windows ke. Hehehe.. ;)

ebx
13-08-03, 11:13 AM
ni mendeha? worm ka?

FWIN,2003/08/13,14:14:48 +8:00 GMT,134.159.116.x:3036,192.168.0.11:135,TCP (flags:S)
FWIN,2003/08/13,14:18:48 +8:00 GMT,82.64.101.x:3466,192.168.0.11:135,TCP (flags:S)
FWIN,2003/08/13,14:30:48 +8:00 GMT,219.95.184.x:3307,192.168.0.11:135,TCP (flags:S)
FWIN,2003/08/13,11:24:22 +8:00 GMT,12.215.69.x:4172,192.168.0.11:135,TCP (flags:S)
FWIN,2003/08/13,11:24:28 +8:00 GMT,12.216.178.x:1222,192.168.0.11:135,TCP (flags:S)
FWIN,2003/08/13,11:26:52 +8:00 GMT,219.95.8.x:4044,192.168.0.11:135,TCP (flags:S)
FWIN,2003/08/13,11:30:26 +8:00 GMT,219.95.167.x:1688,192.168.0.11:135,TCP (flags:S)
FWIN,2003/08/13,11:30:36 +8:00 GMT,219.93.205.x:2120,192.168.0.11:135,TCP (flags:S)
FWIN,2003/08/13,11:30:56 +8:00 GMT,219.95.160.x:3326,192.168.0.11:135,TCP (flags:S)
FWIN,2003/08/13,11:33:08 +8:00 GMT,219.95.161.X:3078,192.168.0.11:135,TCP (flags:S)
FWIN,2003/08/13,11:33:14 +8:00 GMT,219.93.15.x:4119,192.168.0.11:135,TCP (flags:S)
FWIN,2003/08/13,11:33:16 +8:00 GMT,219.95.162.x:4200,192.168.0.11:135,TCP (flags:S)
FWIN,2003/08/13,11:33:34 +8:00 GMT,219.95.17.X:2344,192.168.0.11:135,TCP (flags:S)

chadtce
13-08-03, 01:06 PM
Slackware tu menggunakan sistem operasi windows ke. Hehehe..
Agak-agak ngko..? :D Thee..he..hee...he :)


The propaganda is everywhere and it'll continues till The Day Of Resurrection...

lembumankambin
13-08-03, 01:40 PM
Kenapa bila ada topik yg kena mengena dengan Windows, ramai yang buat posting yang ntah ape-ape pasal Lin$ux.

ebx
13-08-03, 06:19 PM
The alert states: "TruSecure does not expect LANs to suffer from denial of service conditions due to this infection, even if it becomes infected. This is because internal infections will only propagate if outbound TFTP requests are allowed. If a source is found it can be blocked at either the firewall or router."

For these reasons, TruSecure "does not expect this to be as bad as Code Red, Nimda or SQL Slammer".

However, the company notes that there has been "numerous problems with Windows Update and St. Bernard's Update Expert - both of which showed that MS patch was installed when it wasn't". It is expecting more trouble ahead.

more from http://www.zone-h.org/en/news/read/id=3220/

farking
13-08-03, 09:29 PM
Kiriman asal oleh lembumankambin
Kenapa bila ada topik yg kena mengena dengan Windows, ramai yang buat posting yang ntah ape-ape pasal Lin$ux.


mungkin dia tgh period kot..so emosi tak menentu..ahaha :)

SebenEleben
14-08-03, 02:29 AM
hehehehehe nasib baik aku pakai ninux takde kena kutuk tehehe

chadtce
14-08-03, 10:40 AM
mungkin dia tgh period kot..so emosi tak menentu..ahaha
Period? What's that? Dot? Red Dot? Thee.. hee.. hee... hee.. Alaa.. itu pun nak makan ati... Kalau korang suka WinDO$, pakai je... pedulik hapa org nak kata.. :D

revomatrix
14-08-03, 02:09 PM
Kenapa bila ada topik yg kena mengena dengan Windows, ramai yang buat posting yang ntah ape-ape pasal Lin$ux.


sebab ko kenal komputer melalui games ..bukan melalui apa yang selalu ko gunakan daripada komputer ...harap ko akan dapat iktibar ...kenapa aku promote Linux ...malah di fakulti aku ...

farking
14-08-03, 02:55 PM
Ok drop that topic ok... here is

3 Comprehensive links in combat with MSBlaster Worm:

DCOM ISS Scanner:
http://www.iss.net/support/product_utilities/ms03-026rpc.php
Microsoft Patches:
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-026.asp
DCOM Cleaner for Infected Boxen:
http://securityresponse.symantec.com/avcenter/venc/data/w32.blaster.worm.removal.tool.html

lembumankambin
14-08-03, 04:26 PM
sebab ko kenal komputer melalui games ..bukan melalui apa yang selalu ko gunakan daripada komputer ...harap ko akan dapat iktibar ...kenapa aku promote Linux ...malah di fakulti aku ...

Mana ko tau aku kenal komputer melalui games? lol. Fakulti ape, who cares.

revomatrix
14-08-03, 06:02 PM
Mana ko tau aku kenal komputer melalui games? lol. Fakulti ape, who cares.

hehehehehe....sebab ko kan budak gamers ....suka games ...entertainment

chadtce
14-08-03, 08:22 PM
Dah aaa... woi... jangan gaduh lak... :D Itu pun nak marah ke? Rileks aa.. ada banyak benda lain lagi yang buleh gaduh...

lembumankambin
14-08-03, 08:48 PM
hehehehehe....sebab ko kan budak gamers ....suka games ...entertainment

Hehehe lawaknyer. :Z:

revomatrix
15-08-03, 05:12 PM
maafkan aku lembumankambin ....aku bukannya saja saja nak bagi posting macam tuh ....mungkin suka suka jer ....hehe

yang pasal OpenSource tuh ...lagi laa aku nak mintak maaf pada sesapa yg terasa ...aku cuma bagi tau apa apa yang aku rasa betul ...kalau salah ...berikan tunjuk ajar ekk

p/s kena turun kan graf ego aku sikit ...nanti kena benci :D

lembumankambin
15-08-03, 10:58 PM
Weh ape nih sorry sorry hehe, aku tak main la terasa-terasa nih. Aku tau la aku tak pandai, guna Windows jer tau, eh silap Window$ jerk.

Kalo ko terasa, aku pun minta maaf le. :D