New worm attacking NT based PC's on the net: firewall and patch
from
WinCustomize Forums
Just for those who may need to know. Now more than a demo exploit, it looks like an actual worm is in the wild and propagating today through the internet via vulnerable PC's. It attacks Port 135 and uses a RPC/DCOM vulnerability (buffer overflow) to get inside unprotected (unfirewalled and unpatched) NT based PC's and then propagates from there.
MS provided a patch on July 16 but there are indications that this new worm may be using another DCOM vulnerability for which MS has not yet provided a patch. This exploit effects NT 4, W2K, XP and Win Server 2003 systems. Best thing to do at the very least is to run a firewall (software or NAT router) to block Port 135 to the internet since it's suspected that the MS patch may not be effective for the current exploit.
The MS update patch can be found via this page: http://www.microsoft.com/security/security_bulletins/ms03-026.asp but again, this may not be enough and blocking port 135 to the net should be effective.
I just mention this since some people don't have any firewalling of their PC's (no router with firewalling capabilities or software firewall). Reports on this new worm as it propagates are being posted on various security news sites and forums today. So raise your shields or get one if you don't already have one. ZA Free, one choice out of several other free firewall apps is here: http://www.zonelabs.com/store/content/company/products/znalm/freeDownload.jsp
More info from SANS on this latest worm: http://isc.sans.org/diary.html?date=200-08-11
(And please, no flaming on MS. Not that I necessarily disagree, but it gets tiresome. It's like complaining about death and taxes.
It's really old news that the "most secure OS and Server OS to date" ain't.)
[Message Edited]
MS provided a patch on July 16 but there are indications that this new worm may be using another DCOM vulnerability for which MS has not yet provided a patch. This exploit effects NT 4, W2K, XP and Win Server 2003 systems. Best thing to do at the very least is to run a firewall (software or NAT router) to block Port 135 to the internet since it's suspected that the MS patch may not be effective for the current exploit.
The MS update patch can be found via this page: http://www.microsoft.com/security/security_bulletins/ms03-026.asp but again, this may not be enough and blocking port 135 to the net should be effective.
I just mention this since some people don't have any firewalling of their PC's (no router with firewalling capabilities or software firewall). Reports on this new worm as it propagates are being posted on various security news sites and forums today. So raise your shields or get one if you don't already have one. ZA Free, one choice out of several other free firewall apps is here: http://www.zonelabs.com/store/content/company/products/znalm/freeDownload.jsp
More info from SANS on this latest worm: http://isc.sans.org/diary.html?date=200-08-11
(And please, no flaming on MS. Not that I necessarily disagree, but it gets tiresome. It's like complaining about death and taxes.
It's really old news that the "most secure OS and Server OS to date" ain't.)
[Message Edited]