There seems to be a massive denial of service attack going on

Posted: 08-11-2003, 09:47 PM
I too am seeing many of my clients remote PC's going down with this same RPC
and COM+ errors. The NT Authority auto shutdown that everyone is talking
about.


Basically all our users behind a firewall are not experiencing this problem.
Remote users that acces the interent and then come to our servers by way of
terminal connection are dropping like flies.
We have lost many systems today all going down one after another.

These remote systems, since they use slow dialup were not patched against
this RPC exploit. We are trying to now but MS site seems swamped and we are
unable. Fortunately these people can stay up because they can RAS into our
firewalled site and then user their browser to get the update. Users that
only have internet access can not stay up long enough to get updates.

All systems affected have the MSBlast.exe file that some poeple have talked
about.

Does any security person know whats going on?

How is the DOS working? Where is it coming from? Any word from Symantec or
Macafee on what msblast.exe is and what other files may have been affected?



Reply With Quote

Responses to "There seems to be a massive denial of service attack going on"

rainie klein
Guest
Posts: n/a
 
There seems to be a massive denial of service attack going on
Posted: 08-11-2003, 11:02 PM
it seem to me that it is a virus, I don't know what ms is
doing about this issue I just receive this patch for the
hole the virus is getting in through. Our phones jumped
off the hook about 10 minutes when I came into work. I
came here to see what was going on and I saw all these
people with the same issues... IS THERE ANYTHING i CAN DO
TO HELP ??? i COULD I EMAIL YOU ANYTHING?

-RAINIE
>-----Original Message-----
>I too am seeing many of my clients remote PC's going down
with this same RPC
>and COM+ errors. The NT Authority auto shutdown that
everyone is talking
>about.
>
>
>Basically all our users behind a firewall are not
experiencing this problem.
>Remote users that acces the interent and then come to our
servers by way of
>terminal connection are dropping like flies.
>We have lost many systems today all going down one after
another.
>
>These remote systems, since they use slow dialup were not
patched against
>this RPC exploit. We are trying to now but MS site seems
swamped and we are
>unable. Fortunately these people can stay up because
they can RAS into our
>firewalled site and then user their browser to get the
update. Users that
>only have internet access can not stay up long enough to
get updates.
>
>All systems affected have the MSBlast.exe file that some
poeple have talked
>about.
>
>Does any security person know whats going on?
>
>How is the DOS working? Where is it coming from? Any word
from Symantec or
>Macafee on what msblast.exe is and what other files may
have been affected?
>
>
>
>.
>
Reply With Quote
Jupiter Jones [MVP]
Guest
Posts: n/a
 
Re: There seems to be a massive denial of service attack going on
Posted: 08-11-2003, 11:26 PM
Mark;
First, IMMEDIATELY disconnect from the internet before a "friend"
leaves a gift on your computer for you.
DO NOT reconnect until this issue is resolved.

Install or enable a firewall immediately.
http://support.microsoft.com/?kbid=283673

Run an updated virus scan.
Or Scan for Viruses online:
http://security.symantec.com/ssc/hom...ZTYMWPAZTJWUFJ

Also be sure to update immediately to prevent this in the future:
http://windowsupdate.microsoft.com/

This will tell you more:
http://www.microsoft.com/security/se...s/ms03-026.asp

--
Jupiter Jones [MVP]
An easier way to read newsgroup messages:
http://www.microsoft.com/windowsxp/p...oups/setup.asp
http://dts-l.org/index.html


"Mark Jerome" <mdjerome@hotmail.com> wrote in message
news:eavdZnEYDHA.2548@TK2MSFTNGP09.phx.gbl...
> I too am seeing many of my clients remote PC's going down with this
same RPC
> and COM+ errors. The NT Authority auto shutdown that everyone is
talking
> about.
>
>
> Basically all our users behind a firewall are not experiencing this
problem.
> Remote users that acces the interent and then come to our servers by
way of
> terminal connection are dropping like flies.
> We have lost many systems today all going down one after another.
>
> These remote systems, since they use slow dialup were not patched
against
> this RPC exploit. We are trying to now but MS site seems swamped and
we are
> unable. Fortunately these people can stay up because they can RAS
into our
> firewalled site and then user their browser to get the update. Users
that
> only have internet access can not stay up long enough to get
updates.
>
> All systems affected have the MSBlast.exe file that some poeple have
talked
> about.
>
> Does any security person know whats going on?
>
> How is the DOS working? Where is it coming from? Any word from
Symantec or
> Macafee on what msblast.exe is and what other files may have been
affected?
>
>
>

Reply With Quote
Jupiter Jones [MVP]
Guest
Posts: n/a
 
Re: There seems to be a massive denial of service attack going on
Posted: 08-11-2003, 11:27 PM
Rainie;
Microsoft is not really doing much right now.
However Microsoft did release the patch a few weeks ago to protect
against this very issue.

First, IMMEDIATELY disconnect from the internet before a "friend"
leaves a gift on your computer for you.
DO NOT reconnect until this issue is resolved.

Install or enable a firewall immediately.
http://support.microsoft.com/?kbid=283673

Run an updated virus scan.
Or Scan for Viruses online:
http://security.symantec.com/ssc/hom...ZTYMWPAZTJWUFJ

Also be sure to update immediately to prevent this in the future:
http://windowsupdate.microsoft.com/

This will tell you more:
http://www.microsoft.com/security/se...s/ms03-026.asp

--
Jupiter Jones [MVP]
An easier way to read newsgroup messages:
http://www.microsoft.com/windowsxp/p...oups/setup.asp
http://dts-l.org/index.html


"rainie klein" <rainieklein@msn.com> wrote in message
news:04cc01c36054$3d58e060$a401280a@phx.gbl...
> it seem to me that it is a virus, I don't know what ms is
> doing about this issue I just receive this patch for the
> hole the virus is getting in through. Our phones jumped
> off the hook about 10 minutes when I came into work. I
> came here to see what was going on and I saw all these
> people with the same issues... IS THERE ANYTHING i CAN DO
> TO HELP ??? i COULD I EMAIL YOU ANYTHING?
>
> -RAINIE
> >-----Original Message-----
> >I too am seeing many of my clients remote PC's going down
> with this same RPC
> >and COM+ errors. The NT Authority auto shutdown that
> everyone is talking
> >about.
> >
> >
> >Basically all our users behind a firewall are not
> experiencing this problem.
> >Remote users that acces the interent and then come to our
> servers by way of
> >terminal connection are dropping like flies.
> >We have lost many systems today all going down one after
> another.
> >
> >These remote systems, since they use slow dialup were not
> patched against
> >this RPC exploit. We are trying to now but MS site seems
> swamped and we are
> >unable. Fortunately these people can stay up because
> they can RAS into our
> >firewalled site and then user their browser to get the
> update. Users that
> >only have internet access can not stay up long enough to
> get updates.
> >
> >All systems affected have the MSBlast.exe file that some
> poeple have talked
> >about.
> >
> >Does any security person know whats going on?
> >
> >How is the DOS working? Where is it coming from? Any word
> from Symantec or
> >Macafee on what msblast.exe is and what other files may
> have been affected?
> >
> >
> >
> >.
> >

Reply With Quote
Mark Jerome
Guest
Posts: n/a
 
Re: There seems to be a massive denial of service attack going on
Posted: 08-12-2003, 02:45 PM
Well advise is sound but flawed. TO fix the computers we need the patch and
we need acces to get the NAV updates. Problems right now is how STUPID MS is
doing this and how unpapared they are. I can only find the patch through MS
update and NOT as a single file download. THis has immense consequences

Also for sites where we have lots of users on broadband our problem is that
MS has not provided this patch as a file which is utterly stupid!!! What
we all want to do is download ONE FILE. Then disconnect the entire site from
the internet. Then apply the patch to all the computers.

The way it is now we have to have each and every PC hit the internet to get
this patch. MS site is so bogged down it takes for ever. Before any patch
can be complete the PC's are getting nailed with this BUG. this is a viciuos
cycle we can't seem to get out of. Does anyone know where this stupid patch
can be downloaded as a file???



"Jupiter Jones [MVP]" <jones_jupiter@hotnomail.com> wrote in message
news:%23PsBqeFYDHA.1620@TK2MSFTNGP12.phx.gbl...
> Mark;
> First, IMMEDIATELY disconnect from the internet before a "friend"
> leaves a gift on your computer for you.
> DO NOT reconnect until this issue is resolved.
>
> Install or enable a firewall immediately.
> http://support.microsoft.com/?kbid=283673
>
> Run an updated virus scan.
> Or Scan for Viruses online:
>
http://security.symantec.com/ssc/hom...ZTYMWPAZTJWUFJ
>
> Also be sure to update immediately to prevent this in the future:
> http://windowsupdate.microsoft.com/
>
> This will tell you more:
> http://www.microsoft.com/security/se...s/ms03-026.asp
>
> --
> Jupiter Jones [MVP]
> An easier way to read newsgroup messages:
> http://www.microsoft.com/windowsxp/p...oups/setup.asp
> http://dts-l.org/index.html
>
>
> "Mark Jerome" <mdjerome@hotmail.com> wrote in message
> news:eavdZnEYDHA.2548@TK2MSFTNGP09.phx.gbl...
> > I too am seeing many of my clients remote PC's going down with this
> same RPC
> > and COM+ errors. The NT Authority auto shutdown that everyone is
> talking
> > about.
> >
> >
> > Basically all our users behind a firewall are not experiencing this
> problem.
> > Remote users that acces the interent and then come to our servers by
> way of
> > terminal connection are dropping like flies.
> > We have lost many systems today all going down one after another.
> >
> > These remote systems, since they use slow dialup were not patched
> against
> > this RPC exploit. We are trying to now but MS site seems swamped and
> we are
> > unable. Fortunately these people can stay up because they can RAS
> into our
> > firewalled site and then user their browser to get the update. Users
> that
> > only have internet access can not stay up long enough to get
> updates.
> >
> > All systems affected have the MSBlast.exe file that some poeple have
> talked
> > about.
> >
> > Does any security person know whats going on?
> >
> > How is the DOS working? Where is it coming from? Any word from
> Symantec or
> > Macafee on what msblast.exe is and what other files may have been
> affected?
> >
> >
> >
>
>

Reply With Quote
Mark Jerome
Guest
Posts: n/a
 
Re: There seems to be a massive denial of service attack going on
Posted: 08-12-2003, 02:48 PM
Disregard last Post

Here is the file as a single download

http://microsoft.com/downloads/detai...displaylang=en


"Jupiter Jones [MVP]" <jones_jupiter@hotnomail.com> wrote in message
news:%23PsBqeFYDHA.1620@TK2MSFTNGP12.phx.gbl...
> Mark;
> First, IMMEDIATELY disconnect from the internet before a "friend"
> leaves a gift on your computer for you.
> DO NOT reconnect until this issue is resolved.
>
> Install or enable a firewall immediately.
> http://support.microsoft.com/?kbid=283673
>
> Run an updated virus scan.
> Or Scan for Viruses online:
>
http://security.symantec.com/ssc/hom...ZTYMWPAZTJWUFJ
>
> Also be sure to update immediately to prevent this in the future:
> http://windowsupdate.microsoft.com/
>
> This will tell you more:
> http://www.microsoft.com/security/se...s/ms03-026.asp
>
> --
> Jupiter Jones [MVP]
> An easier way to read newsgroup messages:
> http://www.microsoft.com/windowsxp/p...oups/setup.asp
> http://dts-l.org/index.html
>
>
> "Mark Jerome" <mdjerome@hotmail.com> wrote in message
> news:eavdZnEYDHA.2548@TK2MSFTNGP09.phx.gbl...
> > I too am seeing many of my clients remote PC's going down with this
> same RPC
> > and COM+ errors. The NT Authority auto shutdown that everyone is
> talking
> > about.
> >
> >
> > Basically all our users behind a firewall are not experiencing this
> problem.
> > Remote users that acces the interent and then come to our servers by
> way of
> > terminal connection are dropping like flies.
> > We have lost many systems today all going down one after another.
> >
> > These remote systems, since they use slow dialup were not patched
> against
> > this RPC exploit. We are trying to now but MS site seems swamped and
> we are
> > unable. Fortunately these people can stay up because they can RAS
> into our
> > firewalled site and then user their browser to get the update. Users
> that
> > only have internet access can not stay up long enough to get
> updates.
> >
> > All systems affected have the MSBlast.exe file that some poeple have
> talked
> > about.
> >
> > Does any security person know whats going on?
> >
> > How is the DOS working? Where is it coming from? Any word from
> Symantec or
> > Macafee on what msblast.exe is and what other files may have been
> affected?
> >
> >
> >
>
>

Reply With Quote
Testy
Guest
Posts: n/a
 
Re: There seems to be a massive denial of service attack going on
Posted: 08-12-2003, 04:08 PM
Maybe you should have properly secured your computers and installed the
patch a month ago when it was available.

Testy

"Mark Jerome" <mdjerome@hotmail.com> wrote in message
news:OcEi2fNYDHA.2548@TK2MSFTNGP09.phx.gbl...
> Well advise is sound but flawed. TO fix the computers we need the patch
and
> we need acces to get the NAV updates. Problems right now is how STUPID MS
is
> doing this and how unpapared they are. I can only find the patch through
MS
> update and NOT as a single file download. THis has immense consequences
>
> Also for sites where we have lots of users on broadband our problem is
that
> MS has not provided this patch as a file which is utterly stupid!!! What
> we all want to do is download ONE FILE. Then disconnect the entire site
from
> the internet. Then apply the patch to all the computers.
>
> The way it is now we have to have each and every PC hit the internet to
get
> this patch. MS site is so bogged down it takes for ever. Before any patch
> can be complete the PC's are getting nailed with this BUG. this is a
viciuos
> cycle we can't seem to get out of. Does anyone know where this stupid
patch
> can be downloaded as a file???
>
>
>
> "Jupiter Jones [MVP]" <jones_jupiter@hotnomail.com> wrote in message
> news:%23PsBqeFYDHA.1620@TK2MSFTNGP12.phx.gbl...
> > Mark;
> > First, IMMEDIATELY disconnect from the internet before a "friend"
> > leaves a gift on your computer for you.
> > DO NOT reconnect until this issue is resolved.
> >
> > Install or enable a firewall immediately.
> > http://support.microsoft.com/?kbid=283673
> >
> > Run an updated virus scan.
> > Or Scan for Viruses online:
> >
>
http://security.symantec.com/ssc/hom...ZTYMWPAZTJWUFJ
> >
> > Also be sure to update immediately to prevent this in the future:
> > http://windowsupdate.microsoft.com/
> >
> > This will tell you more:
> > http://www.microsoft.com/security/se...s/ms03-026.asp
> >
> > --
> > Jupiter Jones [MVP]
> > An easier way to read newsgroup messages:
> > http://www.microsoft.com/windowsxp/p...oups/setup.asp
> > http://dts-l.org/index.html
> >
> >
> > "Mark Jerome" <mdjerome@hotmail.com> wrote in message
> > news:eavdZnEYDHA.2548@TK2MSFTNGP09.phx.gbl...
> > > I too am seeing many of my clients remote PC's going down with this
> > same RPC
> > > and COM+ errors. The NT Authority auto shutdown that everyone is
> > talking
> > > about.
> > >
> > >
> > > Basically all our users behind a firewall are not experiencing this
> > problem.
> > > Remote users that acces the interent and then come to our servers by
> > way of
> > > terminal connection are dropping like flies.
> > > We have lost many systems today all going down one after another.
> > >
> > > These remote systems, since they use slow dialup were not patched
> > against
> > > this RPC exploit. We are trying to now but MS site seems swamped and
> > we are
> > > unable. Fortunately these people can stay up because they can RAS
> > into our
> > > firewalled site and then user their browser to get the update. Users
> > that
> > > only have internet access can not stay up long enough to get
> > updates.
> > >
> > > All systems affected have the MSBlast.exe file that some poeple have
> > talked
> > > about.
> > >
> > > Does any security person know whats going on?
> > >
> > > How is the DOS working? Where is it coming from? Any word from
> > Symantec or
> > > Macafee on what msblast.exe is and what other files may have been
> > affected?
> > >
> > >
> > >
> >
> >
>
>

---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.507 / Virus Database: 304 - Release Date: 8/4/2003


Reply With Quote
Jupiter Jones [MVP]
Guest
Posts: n/a
 
Re: There seems to be a massive denial of service attack going on
Posted: 08-12-2003, 08:26 PM
Mark;
Microsoft prepared for this.
This vulnerability has been on the news lately.
1. The patch was available weeks ago both by direct download and
Windows Update.
2. Windows XP has a built in firewall, why was no firewall in place
on your network?.
3. Your computer system should have an up to date reliable antivirus
application.
At least two of these did not happen.
You need to question the competency of your IT department and perhaps
train them in basic computer security and maintenance.
Until then expect the same thing next time.

--
Jupiter Jones [MVP]
An easier way to read newsgroup messages:
http://www.microsoft.com/windowsxp/p...oups/setup.asp
http://dts-l.org/index.html


"Mark Jerome" <mdjerome@hotmail.com> wrote in message
news:OcEi2fNYDHA.2548@TK2MSFTNGP09.phx.gbl...
> Well advise is sound but flawed. TO fix the computers we need the
patch and
> we need acces to get the NAV updates. Problems right now is how
STUPID MS is
> doing this and how unpapared they are. I can only find the patch
through MS
> update and NOT as a single file download. THis has immense
consequences
>
> Also for sites where we have lots of users on broadband our problem
is that
> MS has not provided this patch as a file which is utterly stupid!!!
What
> we all want to do is download ONE FILE. Then disconnect the entire
site from
> the internet. Then apply the patch to all the computers.
>
> The way it is now we have to have each and every PC hit the internet
to get
> this patch. MS site is so bogged down it takes for ever. Before any
patch
> can be complete the PC's are getting nailed with this BUG. this is a
viciuos
> cycle we can't seem to get out of. Does anyone know where this
stupid patch
> can be downloaded as a file???

Reply With Quote
 
LinkBack Thread Tools Display Modes
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
ZoneAlarm Advertising Blocking Denial of Service Vulnerability JM Tella Llop [MVP Windows] Windows XP Configuration & Management 0 11-21-2004 06:10 PM
IBM HTTP Server Denial of Service Vulnerabilities JM Tella Llop [MVP Windows] Windows XP Configuration & Management 0 11-21-2004 06:09 PM
Massive slow downs in Win XP Kyle Szklenski Windows XP Performance & Maintenance 0 07-31-2003 09:42 PM
is it me or is there a massive increase in XP problems? q Windows XP Performance & Maintenance 1 07-17-2003 02:57 PM
Massive problems...please help. Chris Windows XP Network & Web 0 07-08-2003 03:34 PM


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90