This site is no longer active and is available for archival purposes only. Registration and login is disabled.

RPC DCOM Worm


RPC DCOM Worm

Postby sponge » Aug 11, 2003 @ 11:08pm

I probably should've said something a couple weeks back when I heard that some people were developing worms, but I forgot to mention it here. The first worms that exploit this hole are out, so if your running anything on the NT kernel, I highly suggest you find the patch. When hit, RPC is killed, and thus SYSTEM user shuts down. The patch is somewhere on MS, don't have the URL off hand.

BTW, if you happen to get hit, send me an IM or something, I've got the tool used to exploit it, working out a way to fix it remotely. I think if you can get the patch installed quick enough it'll work, once you are infected.

[edit] Apparently, if you can get the patch installed in 60 seconds, your good.

http://download.microsoft.com/download/ ... 86-ENU.exe
For XP Home. Find the page for other OSes

[edit2] Got any enemies? Send their IPs to me :P
Last edited by sponge on Aug 11, 2003 @ 11:55pm, edited 1 time in total.
holy internets batman.
User avatar
sponge
Not sponge
 
Posts: 12779
Joined: Jan 13, 2002 @ 8:04am
Location: New Hampshire


Postby METROID » Aug 11, 2003 @ 11:47pm

Thanks for the info and help Sponge I have been crashing all morning. I have to add if your comp is shutting down every 60 seconds quickly move to the control panel and go to system and administrater and then services and change the config of the service so it will not Shut down your comp if it runs into an error, this way you can have time to download and instal the patch without shut down (NOTE: DO NOT DISABLE THE RCP SERVICE!).
<img src="http://www.452rtracing.com/images/small/burn3.jpg"> 500HP 440 Magnum 1968 Charger R/T clone.
User avatar
METROID
pm Member
 
Posts: 766
Joined: May 22, 2003 @ 2:20am
Location: CA


Postby TroGdoR the BuRNiNatOR » Aug 12, 2003 @ 5:39am

I dont know if this is a action of the worm or jus a hacker, but my content advisor has just suddenly been turned on and set with a password i dont know. I am using my other computer to write this message and to seek help. !newb in crisis!

can anyone help me reset the password?
TroGdoR the BuRNiNatOR
pm Member
 
Posts: 22
Joined: Aug 10, 2003 @ 9:26am


Postby sponge » Aug 12, 2003 @ 5:46am

Definitely not the worm. Can't really help either, don't know anything about that offhand. Try searching http://neworder.box.sk I guess
holy internets batman.
User avatar
sponge
Not sponge
 
Posts: 12779
Joined: Jan 13, 2002 @ 8:04am
Location: New Hampshire


Postby ktemkin » Aug 12, 2003 @ 5:51am

User avatar
ktemkin
pm Member
 
Posts: 1209
Joined: May 21, 2002 @ 9:51pm
Location: Smithtown, NY


Postby sponge » Aug 12, 2003 @ 6:50am

holy internets batman.
User avatar
sponge
Not sponge
 
Posts: 12779
Joined: Jan 13, 2002 @ 8:04am
Location: New Hampshire


Postby Jaybot » Aug 13, 2003 @ 4:10pm

blaster worm.. cute.

i was wondering what that mblast.exe task was .. combined with that fact that all copy/paste functions and open in a new window (shift-click) were not working :)
-------
|\\ //|
-- ^ --
|||
User avatar
Jaybot
pm Insider
 
Posts: 3208
Joined: Mar 22, 2001 @ 10:04pm
Location: Desk.


Return to Anything Discussion


Sort


Forum Description

Post all off-topic messages here, almost anything goes.

Moderators:

Dan East, sponge, David Horn, Kevin Gelso, RICoder

Forum permissions

You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

cron