JREF Homepage Swift Blog Events Calendar $1 Million Paranormal Challenge The Amaz!ng Meeting Useful Links Support Us
James Randi Educational Foundation JREF Forum
Forum Index Register Members List Events Mark Forums Read Help

Go Back   JREF Forum » General Topics » Computers and the Internet
Click Here To Donate

Notices


Welcome to the JREF Forum, where we discuss skepticism, critical thinking, the paranormal and science in a friendly but lively way. You are currently viewing the forum as a guest, which means you are missing out on discussing matters that are of interest to you. Please consider registering so you can gain full use of the forum features and interact with other Members. Registration is simple, fast and free! Click here to register today.

Tags hack , mass

Reply
Old 11th August 2003, 02:56 PM   #1
mummymonkey
Did you spill my pint?
 
mummymonkey's Avatar
 
Join Date: Dec 2002
Location: Scotland
Posts: 1,915
Mass Hack

Looks like someone is trying a mass hack tonight via the the RPC service vulnerability. Make sure you're all patched up!

The patch is here
__________________
Knees bent, arms stretched, Ra! Ra! Ra!
mummymonkey is offline   Quote this post in a PM   Nominate this post for this month's language award Copy a direct link to this post Reply With Quote Back to Top
Old 11th August 2003, 04:34 PM   #2
bignickel
Mad Mod Poet God
 
bignickel's Avatar
 
Join Date: Aug 2002
Location: St. Louis, MO
Posts: 2,724
My machine just got attacked.

You'd think I would have d/led that patch already, wouldn't you? But no...
__________________
"You can find that book everywhere and the risk is that many people who read it believe that those fairy tales are real. I think I have the responsibility to clear things up to unmask the cheap lies contained in books like that."
- Cardinal Tarcisio Bertone
bignickel is offline   Quote this post in a PM   Nominate this post for this month's language award Copy a direct link to this post Reply With Quote Back to Top
Old 11th August 2003, 08:41 PM   #3
Torment
Scholar
 
Join Date: Apr 2003
Posts: 77
I got hit it a week ago. The amount of people getting hit seems to have drastically increased since then. In one forum I go to over 20 people have gotten it, and we have maybe 60 active members.

The stuff you get infected with are easy enough to get rid of though, at least once you know the basics of virus removal and have a good AV.
__________________
Why do the people who know the least know it the loudest?
Torment is offline   Quote this post in a PM   Nominate this post for this month's language award Copy a direct link to this post Reply With Quote Back to Top
Old 11th August 2003, 09:31 PM   #4
Wolverine
Grumpy Stinky Mustelid
 
Wolverine's Avatar
 
Join Date: Jun 2002
Location: Austin, TX
Posts: 1,690
More info.
Wolverine is offline   Quote this post in a PM   Nominate this post for this month's language award Copy a direct link to this post Reply With Quote Back to Top
Old 11th August 2003, 09:35 PM   #5
Wolverine
Grumpy Stinky Mustelid
 
Wolverine's Avatar
 
Join Date: Jun 2002
Location: Austin, TX
Posts: 1,690
... and more...
Wolverine is offline   Quote this post in a PM   Nominate this post for this month's language award Copy a direct link to this post Reply With Quote Back to Top
Old 11th August 2003, 11:30 PM   #6
Luke T.
Guest
 
Join Date: May 2003
Posts: 14,759
Do not download this patch. It has totally screwed up my computer.
Luke T. is offline   Quote this post in a PM   Nominate this post for this month's language award Copy a direct link to this post Reply With Quote Back to Top
Old 11th August 2003, 11:35 PM   #7
Luke T.
Guest
 
Join Date: May 2003
Posts: 14,759
I hop ethis gets through. I have two accounts on my computer. The account I used to download and run th epatch is no longer allowing me access to the outside world in any way. And on the other account I am using right now, it has a system shutdown message which only allows me to use the ocmputer for one minute. I am typing fast as I can.

This sytem is shutton down,. Please save ll work in progress and log off. This shutdown was initiated by NT autority/system
Luke T. is offline   Quote this post in a PM   Nominate this post for this month's language award Copy a direct link to this post Reply With Quote Back to Top
Old 11th August 2003, 11:39 PM   #8
Luke T.
Guest
 
Join Date: May 2003
Posts: 14,759
Computer reboots all by itself. I log back on, and I get a one minute warning it is going to reboot again.

And yes, I have restored my computer to a point prior to patch. I tried three restore points, all the way back to two weeks ago.

Windows XP.

Here I go, rebooting itself again. MOTHERF***ER!!!!!
Luke T. is offline   Quote this post in a PM   Nominate this post for this month's language award Copy a direct link to this post Reply With Quote Back to Top
Old 12th August 2003, 12:46 AM   #9
mummymonkey
Did you spill my pint?
 
mummymonkey's Avatar
 
Join Date: Dec 2002
Location: Scotland
Posts: 1,915
Luke T.
See Wolverines info. Looks like you got blasted.
__________________
Knees bent, arms stretched, Ra! Ra! Ra!
mummymonkey is offline   Quote this post in a PM   Nominate this post for this month's language award Copy a direct link to this post Reply With Quote Back to Top
Old 12th August 2003, 12:54 AM   #10
Wolverine
Grumpy Stinky Mustelid
 
Wolverine's Avatar
 
Join Date: Jun 2002
Location: Austin, TX
Posts: 1,690
Quote:
Originally posted by Luke T.
This sytem is shutton down,. Please save ll work in progress and log off. This shutdown was initiated by NT autority/system
This sounds like the worm, not any problem caused by installing the patch.

Go to start/run and type in msconfig then click ok

Click the Startup tab

If you see anything that says msblast.exe (there are possibly other alaises also), chances are you're infected with this critter.
Wolverine is offline   Quote this post in a PM   Nominate this post for this month's language award Copy a direct link to this post Reply With Quote Back to Top
Old 12th August 2003, 12:59 AM   #11
Wolverine
Grumpy Stinky Mustelid
 
Wolverine's Avatar
 
Join Date: Jun 2002
Location: Austin, TX
Posts: 1,690
Symantec has additional info and a removal tool (and additional removal instructions) now posted on this page.
Wolverine is offline   Quote this post in a PM   Nominate this post for this month's language award Copy a direct link to this post Reply With Quote Back to Top
Old 12th August 2003, 01:56 AM   #12
davidhorman
Muse
 
Join Date: Oct 2001
Posts: 984
I read once that it's very difficult to block your RPC port unless you have firewall software, but I found an easy way (if you know enough to do it). If you have Internet Connection Sharing on the computer that's connected to the Internet (you can enable it just to do this if you want), you can use the Advanced settings to forward port 113 to a non-existant address.

David
davidhorman is offline   Quote this post in a PM   Nominate this post for this month's language award Copy a direct link to this post Reply With Quote Back to Top
Old 12th August 2003, 06:56 AM   #13
Jon_in_london
Illuminator
 
Jon_in_london's Avatar
 
Join Date: Aug 2002
Posts: 4,994
Quote:
Originally posted by Luke T.
Computer reboots all by itself. I log back on, and I get a one minute warning it is going to reboot again.

And yes, I have restored my computer to a point prior to patch. I tried three restore points, all the way back to two weeks ago.

Windows XP.

Here I go, rebooting itself again. MOTHERF*CKER!!!!!
Luke, Sounds like you have the patch but the msblast is still on your system.

Delete/stop running msblast then install patch.
__________________
Radicals and Racists Don't point your finger at me I'm a small town white boy Just tryin' to make ends meet
Don't need your religion Don't watch that much T.V.
Just makin' my livin', baby Well that's enough for me

Jon_in_london is offline   Quote this post in a PM   Nominate this post for this month's language award Copy a direct link to this post Reply With Quote Back to Top
Old 12th August 2003, 09:08 AM   #14
peptoabysmal
Illuminator
 
peptoabysmal's Avatar
 
Join Date: Sep 2002
Posts: 3,467
Quote:
Originally posted by Luke T.
Computer reboots all by itself. I log back on, and I get a one minute warning it is going to reboot again.

And yes, I have restored my computer to a point prior to patch. I tried three restore points, all the way back to two weeks ago.

Windows XP.

Here I go, rebooting itself again. MOTHERFU*KER!!!!!
I had the same thing happen on Win XP. I went into the network control panel and enabled the firewall protection from the Advanced tab, that seemed to stop it. Either I just got lucky, or this hack relies on a remote proc call sent from outside and the firewall blocks it.
__________________
OBAMA: It's not that I want to punish your success; I just want to make sure that everybody who is behind you that they've got a chance to success, too. I think when you spread the wealth around, it's good for everybody.
peptoabysmal is offline   Quote this post in a PM   Nominate this post for this month's language award Copy a direct link to this post Reply With Quote Back to Top
Old 12th August 2003, 12:07 PM   #15
Bluegill
Graduate Poster
 
Bluegill's Avatar
 
Join Date: Oct 2002
Location: Louisville
Posts: 1,188
Quote:
Originally posted by Luke T.
I hop ethis gets through. I have two accounts on my computer. The account I used to download and run th epatch is no longer allowing me access to the outside world in any way. And on the other account I am using right now, it has a system shutdown message which only allows me to use the ocmputer for one minute. I am typing fast as I can.

This sytem is shutton down,. Please save ll work in progress and log off. This shutdown was initiated by NT autority/system

My wife was on the computer last night when she suddenly started getting this warning and getting kicked off. I guess now I know why. I guess I know what I'll be messing around with when I get home from work today. Bastards.
Bluegill is online now   Quote this post in a PM   Nominate this post for this month's language award Copy a direct link to this post Reply With Quote Back to Top
Old 12th August 2003, 12:18 PM   #16
bignickel
Mad Mod Poet God
 
bignickel's Avatar
 
Join Date: Aug 2002
Location: St. Louis, MO
Posts: 2,724
Hey Bluegill! I caught Heide Howe last night here in St. Louis coffeehaus. Louisville's own.

She rocks! Well, she folks anyway...
__________________
"You can find that book everywhere and the risk is that many people who read it believe that those fairy tales are real. I think I have the responsibility to clear things up to unmask the cheap lies contained in books like that."
- Cardinal Tarcisio Bertone
bignickel is offline   Quote this post in a PM   Nominate this post for this month's language award Copy a direct link to this post Reply With Quote Back to Top
Old 12th August 2003, 02:20 PM   #17
Bluegill
Graduate Poster
 
Bluegill's Avatar
 
Join Date: Oct 2002
Location: Louisville
Posts: 1,188
Quote:
Originally posted by bignickel
Hey Bluegill! I caught Heide Howe last night here in St. Louis coffeehaus. Louisville's own.

She rocks! Well, she folks anyway...
Howdy! Heidi Howe (heh heh) hired my sister-in-law (I ran out of H-words, darn it) to film some of her concerts, but I've never seen her. She gets pretty good press. I suppose I should try to see one of her shows.

So I guess you and I practically know one another [waves]
Bluegill is online now   Quote this post in a PM   Nominate this post for this month's language award Copy a direct link to this post Reply With Quote Back to Top
Old 12th August 2003, 11:16 PM   #18
Luke T.
Guest
 
Join Date: May 2003
Posts: 14,759
Getting rid of the virus has proven more difficult than I thought. I also think it is too strange a coincidence that it didn't kick in until the moment I tried to get the patch from Microsoft to work.

I still can't get the patch to work. But I got the virus remover that Wolverine linked from Symantec to work.

But that didn't work right away. I had files on my computer that were unrelated to the virus which were corrupted and would not delete. This caused the virus remover to halt and quit when it came across them.

I finally had to go into DOS and manually delete them, then I got the virus remover to finally work.

The Microsoft patch still won't run.

If I were to get my hands on the hacker who wrote this virus, I would turn Islamic for a few minutes and break his face, pull off his ears, cut out his tongue, break his knees, and cut off his hands one finger at a time. With a dull, rusty butter knife and no anethesia.

Let him try and write code as a deaf, dumb, fingerless cripple.
Luke T. is offline   Quote this post in a PM   Nominate this post for this month's language award Copy a direct link to this post Reply With Quote Back to Top
Old 13th August 2003, 12:22 AM   #19
mummymonkey
Did you spill my pint?
 
mummymonkey's Avatar
 
Join Date: Dec 2002
Location: Scotland
Posts: 1,915
Luke T.
Rename the catroot2 file in windows\system32 then try again.
__________________
Knees bent, arms stretched, Ra! Ra! Ra!
mummymonkey is offline   Quote this post in a PM   Nominate this post for this month's language award Copy a direct link to this post Reply With Quote Back to Top
Old 13th August 2003, 08:55 PM   #20
Luke T.
Guest
 
Join Date: May 2003
Posts: 14,759
Quote:
Originally posted by mummymonkey
Luke T.
Rename the catroot2 file in windows\system32 then try again.
huh?
Luke T. is offline   Quote this post in a PM   Nominate this post for this month's language award Copy a direct link to this post Reply With Quote Back to Top
Old 17th August 2003, 07:13 AM   #21
De_Bunk
Scourge of the Believer
 
De_Bunk's Avatar
 
Join Date: Feb 2002
Posts: 5,508
And before you do anything...

Turn off system restore....(Thats if you got it on in the first place)


DB
__________________
I've made nearly 20,000 posts on the JREF...

Trouble is..over 14,000 have been deleted...

And you think you're 'Hardcore'.. (DB)
De_Bunk is offline   Quote this post in a PM   Nominate this post for this month's language award Copy a direct link to this post Reply With Quote Back to Top
Old 20th August 2003, 05:05 AM   #22
max
That old codger
 
Join Date: Feb 2002
Location: uk
Posts: 988
Go to Desktop and click on F3 if infected there will be two files one a jvs the other exe, to get rid go to www.bigblackglasses.com they have a script to download to clean up the desktop. Then go to www.microsoft.com and download the patch. Use the one referring to RPC. Run the patch then shutdown and restart the computer
max is offline   Quote this post in a PM   Nominate this post for this month's language award Copy a direct link to this post Reply With Quote Back to Top
Reply

JREF Forum » General Topics » Computers and the Internet

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -7. The time now is 10:52 AM.
Powered by vBulletin. Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
© 2001-2012, James Randi Educational Foundation. All Rights Reserved.

Disclaimer: Messages posted in the Forum are solely the opinion of their authors.