Thread Tools
Old August 13, 2003, 22:08   #1
Blisterz
Chieftain
 
Blisterz's Avatar
 
Local Time: 07:21
Local Date: November 2, 2010
Join Date: Nov 2001
Posts: 52
MSBlast.exe (virus)
This virus is amazing in how easy it is to catch. Yesterday I was just finished putting together a new system, and was installing W2K. My computer kept getting an RPC error and shutting down. I tried everything to fix it. (i never once had even enough time to install a single critical-up date), so I would end up reinstalling W2K (did that 3 times). Then during the 3rd install I read about the virus on another computer that was there. I was curious, so right after the install I opened search and looked for MSBLAST. Nothing. Ok, so about 2 min into installing service pack 4 and I get RPC error. I do search on my system and sure enough, MSBLAST.

I have never seen (i have heard/read though) a virus that infects a system before you have downloaded ANYTHING.

I hate to give this guy/gal any credit but whoever is responsible for this huge pain in the arse, is one smart cookie.

http://www.computing.net/windowsxp/w...rum/73575.html
__________________
" Conceit, arrogance, and egotism are the essentials of patriotism." - Emma Goldman

William Seward Burroughs
February 5, 1914 - August 2, 1997 R.I.P. Uncle Bill, you are missed.
Blisterz is offline  
Old August 13, 2003, 22:11   #2
Asher
Apolytoners Hall of Fame
President of the OT
 
Asher's Avatar
 
Local Time: 01:21
Local Date: November 2, 2010
Join Date: Nov 1999
Location: Calgary, Alberta
Posts: 40,843
Actually it's very poor code and design.

It's just such an easy exploit.
__________________
"I'll never doubt you again when it comes to hockey, [Prince] Asher." - Guynemer
Asher is offline  
Old August 13, 2003, 22:13   #3
Elok
Scenario League / Civ2-Creation
Emperor
 
Elok's Avatar
 
Local Time: 03:21
Local Date: November 2, 2010
Join Date: Mar 2003
Location: Having tea with the Third Man...
Posts: 6,169
Clever, maybe, but I don't know that I'd call anybody who makes computer viruses "smart." What kind of degenerate schlep spends that much time designing newer and better ways of irritating people for no personal profit? Is there some sort of sexual pleasure in it for them, or are they too dumb to just do straight identity theft like their more enterprising nerd compatriots?
__________________
"May I be forgiven for the ills that I have done/Friends I have forsaken and strangers I have shunned/Sins I have committed, for which others had to pay/And I haven't met the whiskey that can wash those stains away."
-Brady's Leap, "Wash."
Elok is offline  
Old August 13, 2003, 22:14   #4
Nubclear
NationStatesCall to Power II Democracy GameInterSite Democracy Game: Apolyton TeamRise of Nations MultiplayerACDG The Human HiveNever Ending StoriesACDG The Free DronesACDG The Cybernetic ConsciousnessGalCiv Apolyton EmpireACDG3 SpartansC4DG Team Alpha CentauriansCiv4 SP Democracy GameDiplomacyAlpha Centauri PBEMCivilization IV PBEMAlpha Centauri Democracy GameACDG Peace
PolyCast Thread Necromancer
 
Nubclear's Avatar
 
Local Time: 07:21
Local Date: November 2, 2010
Join Date: Jul 2002
Location: We are all Asher now.
Posts: 1,437
Too bad theyre wasting their talents. They could be getting quite a bit of money.
Nubclear is offline  
Old August 13, 2003, 22:14   #5
Frozzy
PtWDG2 SunshineNationStatesCall To Power SuperLeague
Emperor
 
Frozzy's Avatar
 
Local Time: 19:21
Local Date: November 2, 2010
Join Date: Aug 2002
Location: Mad.
Posts: 4,142
Most computers have their NetBIOS port open by default (a MS Windows flaw). This enables anyone to access your files, and even set up your computer as a hidden webserver. As such, just going on the internet can let in the worm through the open port and into your computer.

It's just as easy to close the port. Why MS doesn't do this by default...
Frozzy is offline  
Old August 13, 2003, 22:17   #6
Blisterz
Chieftain
 
Blisterz's Avatar
 
Local Time: 07:21
Local Date: November 2, 2010
Join Date: Nov 2001
Posts: 52
Quote:
Originally posted by Elok
Clever, maybe, but I don't know that I'd call anybody who makes computer viruses "smart." What kind of degenerate schlep spends that much time designing newer and better ways of irritating people for no personal profit? Is there some sort of sexual pleasure in it for them, or are they too dumb to just do straight identity theft like their more enterprising nerd compatriots?

For some of them, I think it's a kind of "stick it to MS thing" this one more so 'cause it is set up to start a DOS attack on Microsoftupdate.com (on aug 16th I think..? )
__________________
" Conceit, arrogance, and egotism are the essentials of patriotism." - Emma Goldman

William Seward Burroughs
February 5, 1914 - August 2, 1997 R.I.P. Uncle Bill, you are missed.
Blisterz is offline  
Old August 13, 2003, 22:21   #7
mrmitchell
Civilization III Democracy GamePtWDG RoleplayCall to Power Democracy GameInterSite Democracy Game: Apolyton TeamNationStatesPtWDG2 Tabemono
King
 
mrmitchell's Avatar
 
Local Time: 01:21
Local Date: November 2, 2010
Join Date: Sep 2002
Posts: 2,394
It's good that the worm only reboots your machine and DoS's a website. Imagine if it was truly destructive so that you could not recover from it...
__________________
meet the new boss, same as the old boss
mrmitchell is offline  
Old August 13, 2003, 22:28   #8
Sprayber
Apolyton Storywriters' Guild
Emperor
 
Sprayber's Avatar
 
Local Time: 02:21
Local Date: November 2, 2010
Join Date: Oct 2000
Location: In Exile
Posts: 4,140
I think people who **** with other people's computers should be taken out by a bunch of illiterate rednecks and beaten twice a day.
__________________
Which side are we on? We're on the side of the demons, Chief. We are evil men in the gardens of paradise, sent by the forces of death to spread devastation and destruction wherever we go. I'm surprised you didn't know that. --Saul Tigh
Sprayber is offline  
Old August 13, 2003, 22:29   #9
mrmitchell
Civilization III Democracy GamePtWDG RoleplayCall to Power Democracy GameInterSite Democracy Game: Apolyton TeamNationStatesPtWDG2 Tabemono
King
 
mrmitchell's Avatar
 
Local Time: 01:21
Local Date: November 2, 2010
Join Date: Sep 2002
Posts: 2,394
Well, viruses are both good and bad.

If there were no viruses, people wouldn't give a **** about virus security. (They wouldn't need to if there were no viruses, though, right? Although there's no shortage of 14 year olds looking for holes in MS products.)

On the other hand, malicious virus writers should be taken out and shot.
__________________
meet the new boss, same as the old boss
mrmitchell is offline  
Old August 13, 2003, 22:33   #10
Elok
Scenario League / Civ2-Creation
Emperor
 
Elok's Avatar
 
Local Time: 03:21
Local Date: November 2, 2010
Join Date: Mar 2003
Location: Having tea with the Third Man...
Posts: 6,169
Quote:
Originally posted by Blisterz
For some of them, I think it's a kind of "stick it to MS thing" this one more so 'cause it is set up to start a DOS attack on Microsoftupdate.com (on aug 16th I think..? )
Maybe, but with their collective skills you'd think they'd be able to just design some sort of assassin robot, sic it on Gates, and leave the rest of us alone. Or just sublimate their rage through porno and Starcraft like good little nerds. Whatever. Anything's better than making MS software harder and more contrary to use than it already is, right? You'd think...
__________________
"May I be forgiven for the ills that I have done/Friends I have forsaken and strangers I have shunned/Sins I have committed, for which others had to pay/And I haven't met the whiskey that can wash those stains away."
-Brady's Leap, "Wash."
Elok is offline  
Old August 13, 2003, 23:57   #11
alva
Civilization III PBEMPtWDG2 Cake or Death?PtWDG Gathering StormInterSite Democracy Game: Apolyton TeamC3C IDG: Apolyton TeamC4DG Gathering Storm
Deity
 
alva's Avatar
 
Local Time: 09:21
Local Date: November 2, 2010
Join Date: Sep 2001
Location: Republic of Flanders
Posts: 10,747
Who's to say, Norton and affiliates don't write them themselves...
__________________
#There’s a city in my mind
Come along and take that ride
And it’s all right, baby, it’s all right #
alva is offline  
Old August 14, 2003, 00:10   #12
Harovan
staff
PtWDG Gathering StormPtWDG2 Monty PythonC4DG Gathering Storm
Civ4: Colonization Content Editor
 
Local Time: 08:21
Local Date: November 2, 2010
Join Date: Dec 2001
Posts: 11,117
An operating is **** if it can be knocked out with such an amazing ease. But still Asher is right, it's crappy coded. It was designed to DoS the Windows update website, but in the most cases it fails its purpose and just makes the computer crash. Probably the product of some geek who should better care about his acne.
Harovan is offline  
Old August 14, 2003, 00:10   #13
Asher
Apolytoners Hall of Fame
President of the OT
 
Asher's Avatar
 
Local Time: 01:21
Local Date: November 2, 2010
Join Date: Nov 1999
Location: Calgary, Alberta
Posts: 40,843
Sir Ralph: Tell everyone where the RPC code comes from...
__________________
"I'll never doubt you again when it comes to hockey, [Prince] Asher." - Guynemer
Asher is offline  
Old August 14, 2003, 00:12   #14
Asher
Apolytoners Hall of Fame
President of the OT
 
Asher's Avatar
 
Local Time: 01:21
Local Date: November 2, 2010
Join Date: Nov 1999
Location: Calgary, Alberta
Posts: 40,843
People overestimate how hard it is to make worms like this...and somehow that equates to the guy doing it being intelligent or something.

If somebody went in and shot up a bank, the guy isn't exactly that smart, regardless of how well planned out it was.
__________________
"I'll never doubt you again when it comes to hockey, [Prince] Asher." - Guynemer
Asher is offline  
Old August 14, 2003, 00:18   #15
Harovan
staff
PtWDG Gathering StormPtWDG2 Monty PythonC4DG Gathering Storm
Civ4: Colonization Content Editor
 
Local Time: 08:21
Local Date: November 2, 2010
Join Date: Dec 2001
Posts: 11,117
Quote:
Originally posted by Asher
Sir Ralph: Tell everyone where the RPC code comes from...
Ummm, that was Solaris, wasn't it? Not sure, though. Makes me wonder why Solaris apparently doesn't have any problems (and never had). Ah well, some people can't even properly steal . Perhaps it's so, because next to nobody runs Solaris and no cracker could be arsed to write a worm to attack some 52 or 53 computers.
Harovan is offline  
Old August 14, 2003, 00:23   #16
Asher
Apolytoners Hall of Fame
President of the OT
 
Asher's Avatar
 
Local Time: 01:21
Local Date: November 2, 2010
Join Date: Nov 1999
Location: Calgary, Alberta
Posts: 40,843
No, it was an open source OS...think on it.

Hint: It wasn't a GNU-licensed OS.
__________________
"I'll never doubt you again when it comes to hockey, [Prince] Asher." - Guynemer
Asher is offline  
Old August 14, 2003, 00:39   #17
Sarxis
Rise of Nations MultiplayerAlpha Centauri PBEMCivilization III MultiplayerCivilization III PBEMCTP2 Source Code ProjectCall to Power II MultiplayerCall to Power MultiplayerCivilization IV: MultiplayerCivilization IV CreatorsGalCiv Apolyton Empire
Emperor
 
Sarxis's Avatar
 
Local Time: 03:21
Local Date: November 2, 2010
Join Date: Sep 1999
Posts: 3,361
Honestly, the worm wasn't a big deal, but I am sorta glad for msblast: it made MS get off their butts and come up with a fix before some SERIOUSLY malicious software abused this security hole.

I think that was the point of it anyway.
Sarxis is offline  
Old August 14, 2003, 00:42   #18
Asher
Apolytoners Hall of Fame
President of the OT
 
Asher's Avatar
 
Local Time: 01:21
Local Date: November 2, 2010
Join Date: Nov 1999
Location: Calgary, Alberta
Posts: 40,843
Um. The fix for the hole MSBlast exploits was out almost a month before MSblast...
__________________
"I'll never doubt you again when it comes to hockey, [Prince] Asher." - Guynemer
Asher is offline  
Old August 14, 2003, 00:44   #19
Sarxis
Rise of Nations MultiplayerAlpha Centauri PBEMCivilization III MultiplayerCivilization III PBEMCTP2 Source Code ProjectCall to Power II MultiplayerCall to Power MultiplayerCivilization IV: MultiplayerCivilization IV CreatorsGalCiv Apolyton Empire
Emperor
 
Sarxis's Avatar
 
Local Time: 03:21
Local Date: November 2, 2010
Join Date: Sep 1999
Posts: 3,361
Was it really? oh well, must have missed it. Was a pretty stupid worm, and it didn't even work like it was supposed to on my system.
Sarxis is offline  
Old August 14, 2003, 00:47   #20
Asher
Apolytoners Hall of Fame
President of the OT
 
Asher's Avatar
 
Local Time: 01:21
Local Date: November 2, 2010
Join Date: Nov 1999
Location: Calgary, Alberta
Posts: 40,843
I told people to patch immediately as a worm was inevitable, last month: http://apolyton.net/forums/showthrea...threadid=93099
__________________
"I'll never doubt you again when it comes to hockey, [Prince] Asher." - Guynemer
Asher is offline  
Old August 14, 2003, 00:57   #21
Sarxis
Rise of Nations MultiplayerAlpha Centauri PBEMCivilization III MultiplayerCivilization III PBEMCTP2 Source Code ProjectCall to Power II MultiplayerCall to Power MultiplayerCivilization IV: MultiplayerCivilization IV CreatorsGalCiv Apolyton Empire
Emperor
 
Sarxis's Avatar
 
Local Time: 03:21
Local Date: November 2, 2010
Join Date: Sep 1999
Posts: 3,361
Ahh! See, I was getting ready to move, and I didn't have internet in the new place till recently. Just wasn't paying attention.
Sarxis is offline  
Old August 14, 2003, 01:41   #22
JohnT
lifer
Apolytoners Hall of Fame
Emperor
 
JohnT's Avatar
 
Local Time: 03:21
Local Date: November 2, 2010
Join Date: Mar 1999
Location: San Antonio, TX
Posts: 4,264
That Asher... always looking after our asses.

...uhhhh...

JohnT is offline  
Old August 14, 2003, 03:46   #23
Harovan
staff
PtWDG Gathering StormPtWDG2 Monty PythonC4DG Gathering Storm
Civ4: Colonization Content Editor
 
Local Time: 08:21
Local Date: November 2, 2010
Join Date: Dec 2001
Posts: 11,117
Quote:
Originally posted by Asher
No, it was an open source OS...think on it.

Hint: It wasn't a GNU-licensed OS.
Must have been a BSD then. On Linux I've heard them called SunRPC, that's why I thought they came from Solaris. I don't use RPCs at all, they are a security risk on either OS. By the way, my router gets bombed with 135 requests. Just drops them of course.

A friend of my wife caught the worm already. She was shocked and helpless when she called me. Made me think... 3 months ago I set her up that computer. It came shipped with XP Home, but I seriously considered to install a Debian+Gnome on it, since she is a bloody newbie. I should have done so, even more since she lives 700 km away, and these service calls every 2 weeks drive me nuts.
Harovan is offline  
Old August 14, 2003, 04:04   #24
Urban Ranger
NationStatesApolyton Storywriters' GuildNever Ending Stories
Deity
 
Urban Ranger's Avatar
 
Local Time: 15:21
Local Date: November 2, 2010
Join Date: May 1999
Location: The City State of Noosphere, CPA special envoy
Posts: 14,606
Quote:
Originally posted by Asher
Actually it's very poor code and design.

It's just such an easy exploit.
Thanks to MS, of course.
__________________
(\__/) 07/07/1937 - Never forget
(='.'=) "Claims demand evidence; extraordinary claims demand extraordinary evidence." -- Carl Sagan
(")_(") "Starting the fire from within."
Urban Ranger is offline  
Old August 14, 2003, 05:01   #25
Makeo
Civilization II MultiplayerDiploGames
King
 
Makeo's Avatar
 
Local Time: 00:21
Local Date: November 2, 2010
Join Date: Dec 1969
Location: Melbourne
Posts: 2,963
Quote:
Originally posted by Asher
I told people to patch immediately as a worm was inevitable, last month: http://apolyton.net/forums/showthrea...threadid=93099
I probably should have done something about it last month rather than yesterday.
__________________
Hold my girlfriend while I kiss your skis.
Makeo is offline  
Old August 14, 2003, 06:52   #26
SpencerH
Civilization III PBEMCivilization III MultiplayerBtS Tri-League
Emperor
 
SpencerH's Avatar
 
Local Time: 02:21
Local Date: November 2, 2010
Join Date: Feb 2002
Location: Back in BAMA full time.
Posts: 4,502
I cant be sure its MSBlast but a worm has brought down bagfulls of PC's at my work. They just try to boot up and get into some kinda loop.
__________________
We need seperate human-only games for MP/PBEM that dont include the over-simplifications required to have a good AI
If any man be thirsty, let him come unto me and drink. Vampire 7:37
Just one old soldiers opinion. E Tenebris Lux. Pax quaeritur bello.
SpencerH is offline  
Old August 14, 2003, 07:07   #27
laurentius
Civilization II MultiplayerApolyton Storywriters' GuildACDG The Cybernetic ConsciousnessDiplomacyAlpha Centauri PBEMAlpha Centauri Democracy GameACDG Planet University of TechnologyNever Ending StoriesACDG PeaceACDG3 GaiansMacC4DG Team Alpha Centaurians
King
 
laurentius's Avatar
 
Local Time: 09:21
Local Date: November 2, 2010
Join Date: Jun 2001
Location: of genial epicuri
Posts: 1,570
I blame MicroSoft, it's their fault, their shitty software, that is causing all this pain in my ass
__________________
Que l’Univers n’est qu’un défaut dans la pureté de Non-être.

- Paul Valery
laurentius is offline  
Old August 14, 2003, 10:18   #28
Solver
lifer
Civilization IV CreatorsAge of Nations TeamApolytoners Hall of FamePolyCast TeamBtS Tri-LeagueThe Courts of Candle'BreC4WDG Team Apolyton
Deity
 
Solver's Avatar
 
Local Time: 10:21
Local Date: November 2, 2010
Join Date: Sep 2000
Location: Latvia, Riga
Posts: 18,355
ILOVEYOU was excellent code .

They don't cause any harm, people. OK, this one restarts your data. But it's very easy to make it erase all data on harddrive after 3 days. I think, if ILOVEYOU did that, how bad would it have been?
__________________
Solver, WePlayCiv Co-Administrator
Contact: solver-at-weplayciv-dot-com
I can kill you whenever I please... but not today. - The Cigarette Smoking Man
Solver is offline  
Old August 14, 2003, 10:23   #29
JohnT
lifer
Apolytoners Hall of Fame
Emperor
 
JohnT's Avatar
 
Local Time: 03:21
Local Date: November 2, 2010
Join Date: Mar 1999
Location: San Antonio, TX
Posts: 4,264
Quote:
Originally posted by laurentius
I blame MicroSoft, it's their fault, their shitty software, that is causing all this pain in my ass
So, if somebody pours sugar in your gas tank, that is the fault of the manufacturer?

JohnT is offline  
Old August 14, 2003, 10:30   #30
Harry Seldon
GalCiv Apolyton EmpireNationStates
King
 
Harry Seldon's Avatar
 
Local Time: 07:21
Local Date: November 2, 2010
Join Date: Oct 2002
Location: Birmingham, AL
Posts: 1,595
Quote:
It's just as easy to close the port. Why MS doesn't do this by default...
But this virus attacks through port 135 instead of 137, 138, or 139, which I don't think can be closed on a Microsoft machine.
Harry Seldon is offline  
 

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On

Forum Jump


All times are GMT -4. The time now is 03:21.


Design by Vjacheslav Trushkin, color scheme by ColorizeIt!.
Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Apolyton Civilization Site | Copyright © The Apolyton Team