There seems to be a massive denial of service attack going on
Guest
Posts: n/a
Posts: n/a
>-----Original Message-----with this same RPC
>I too am seeing many of my clients remote PC's going down
>and COM+ errors. The NT Authority auto shutdown thateveryone is talking
>about.experiencing this problem.
>
>
>Basically all our users behind a firewall are not
>Remote users that acces the interent and then come to ourservers by way of
>terminal connection are dropping like flies.another.
>We have lost many systems today all going down one after
>patched against
>These remote systems, since they use slow dialup were not
>this RPC exploit. We are trying to now but MS site seemsswamped and we are
>unable. Fortunately these people can stay up becausethey can RAS into our
>firewalled site and then user their browser to get theupdate. Users that
>only have internet access can not stay up long enough toget updates.
>poeple have talked
>All systems affected have the MSBlast.exe file that some
>about.from Symantec or
>
>Does any security person know whats going on?
>
>How is the DOS working? Where is it coming from? Any word
>Macafee on what msblast.exe is and what other files mayhave been affected?
>
>
>
>.
>
> I too am seeing many of my clients remote PC's going down with thissame RPC
> and COM+ errors. The NT Authority auto shutdown that everyone istalking
> about.problem.
>
>
> Basically all our users behind a firewall are not experiencing this
> Remote users that acces the interent and then come to our servers byway of
> terminal connection are dropping like flies.against
> We have lost many systems today all going down one after another.
>
> These remote systems, since they use slow dialup were not patched
> this RPC exploit. We are trying to now but MS site seems swamped andwe are
> unable. Fortunately these people can stay up because they can RASinto our
> firewalled site and then user their browser to get the update. Usersthat
> only have internet access can not stay up long enough to getupdates.
>talked
> All systems affected have the MSBlast.exe file that some poeple have
> about.Symantec or
>
> Does any security person know whats going on?
>
> How is the DOS working? Where is it coming from? Any word from
> Macafee on what msblast.exe is and what other files may have beenaffected?
>
>
>
> it seem to me that it is a virus, I don't know what ms is
> doing about this issue I just receive this patch for the
> hole the virus is getting in through. Our phones jumped
> off the hook about 10 minutes when I came into work. I
> came here to see what was going on and I saw all these
> people with the same issues... IS THERE ANYTHING i CAN DO
> TO HELP ??? i COULD I EMAIL YOU ANYTHING?
>
> -RAINIE> >-----Original Message-----> with this same RPC
> >I too am seeing many of my clients remote PC's going down> >and COM+ errors. The NT Authority auto shutdown that> everyone is talking> >about.> experiencing this problem.
> >
> >
> >Basically all our users behind a firewall are not> >Remote users that acces the interent and then come to our> servers by way of> >terminal connection are dropping like flies.> another.
> >We have lost many systems today all going down one after> >> patched against
> >These remote systems, since they use slow dialup were not> >this RPC exploit. We are trying to now but MS site seems> swamped and we are> >unable. Fortunately these people can stay up because> they can RAS into our> >firewalled site and then user their browser to get the> update. Users that> >only have internet access can not stay up long enough to> get updates.> >> poeple have talked
> >All systems affected have the MSBlast.exe file that some> >about.> from Symantec or
> >
> >Does any security person know whats going on?
> >
> >How is the DOS working? Where is it coming from? Any word> >Macafee on what msblast.exe is and what other files may> have been affected?> >
> >
> >
> >.
> >
> Mark;http://security.symantec.com/ssc/hom...ZTYMWPAZTJWUFJ
> First, IMMEDIATELY disconnect from the internet before a "friend"
> leaves a gift on your computer for you.
> DO NOT reconnect until this issue is resolved.
>
> Install or enable a firewall immediately.
> http://support.microsoft.com/?kbid=283673
>
> Run an updated virus scan.
> Or Scan for Viruses online:
>
>
> Also be sure to update immediately to prevent this in the future:
> http://windowsupdate.microsoft.com/
>
> This will tell you more:
> http://www.microsoft.com/security/se...s/ms03-026.asp
>
> --
> Jupiter Jones [MVP]
> An easier way to read newsgroup messages:
> http://www.microsoft.com/windowsxp/p...oups/setup.asp
> http://dts-l.org/index.html
>
>
> "Mark Jerome" <mdjerome@hotmail.com> wrote in message
> news:eavdZnEYDHA.2548@TK2MSFTNGP09.phx.gbl...> > I too am seeing many of my clients remote PC's going down with this> same RPC> > and COM+ errors. The NT Authority auto shutdown that everyone is> talking> > about.> problem.
> >
> >
> > Basically all our users behind a firewall are not experiencing this> > Remote users that acces the interent and then come to our servers by> way of> > terminal connection are dropping like flies.> against
> > We have lost many systems today all going down one after another.
> >
> > These remote systems, since they use slow dialup were not patched> > this RPC exploit. We are trying to now but MS site seems swamped and> we are> > unable. Fortunately these people can stay up because they can RAS> into our> > firewalled site and then user their browser to get the update. Users> that> > only have internet access can not stay up long enough to get> updates.> >> talked
> > All systems affected have the MSBlast.exe file that some poeple have> > about.> Symantec or
> >
> > Does any security person know whats going on?
> >
> > How is the DOS working? Where is it coming from? Any word from> > Macafee on what msblast.exe is and what other files may have been> affected?> >>
> >
> >
>
> Mark;http://security.symantec.com/ssc/hom...ZTYMWPAZTJWUFJ
> First, IMMEDIATELY disconnect from the internet before a "friend"
> leaves a gift on your computer for you.
> DO NOT reconnect until this issue is resolved.
>
> Install or enable a firewall immediately.
> http://support.microsoft.com/?kbid=283673
>
> Run an updated virus scan.
> Or Scan for Viruses online:
>
>
> Also be sure to update immediately to prevent this in the future:
> http://windowsupdate.microsoft.com/
>
> This will tell you more:
> http://www.microsoft.com/security/se...s/ms03-026.asp
>
> --
> Jupiter Jones [MVP]
> An easier way to read newsgroup messages:
> http://www.microsoft.com/windowsxp/p...oups/setup.asp
> http://dts-l.org/index.html
>
>
> "Mark Jerome" <mdjerome@hotmail.com> wrote in message
> news:eavdZnEYDHA.2548@TK2MSFTNGP09.phx.gbl...> > I too am seeing many of my clients remote PC's going down with this> same RPC> > and COM+ errors. The NT Authority auto shutdown that everyone is> talking> > about.> problem.
> >
> >
> > Basically all our users behind a firewall are not experiencing this> > Remote users that acces the interent and then come to our servers by> way of> > terminal connection are dropping like flies.> against
> > We have lost many systems today all going down one after another.
> >
> > These remote systems, since they use slow dialup were not patched> > this RPC exploit. We are trying to now but MS site seems swamped and> we are> > unable. Fortunately these people can stay up because they can RAS> into our> > firewalled site and then user their browser to get the update. Users> that> > only have internet access can not stay up long enough to get> updates.> >> talked
> > All systems affected have the MSBlast.exe file that some poeple have> > about.> Symantec or
> >
> > Does any security person know whats going on?
> >
> > How is the DOS working? Where is it coming from? Any word from> > Macafee on what msblast.exe is and what other files may have been> affected?> >>
> >
> >
>
> Well advise is sound but flawed. TO fix the computers we need the patchand
> we need acces to get the NAV updates. Problems right now is how STUPID MSis
> doing this and how unpapared they are. I can only find the patch throughMS
> update and NOT as a single file download. THis has immense consequencesthat
>
> Also for sites where we have lots of users on broadband our problem is
> MS has not provided this patch as a file which is utterly stupid!!! Whatfrom
> we all want to do is download ONE FILE. Then disconnect the entire site
> the internet. Then apply the patch to all the computers.get
>
> The way it is now we have to have each and every PC hit the internet to
> this patch. MS site is so bogged down it takes for ever. Before any patchviciuos
> can be complete the PC's are getting nailed with this BUG. this is a
> cycle we can't seem to get out of. Does anyone know where this stupidpatch
> can be downloaded as a file???http://security.symantec.com/ssc/hom...ZTYMWPAZTJWUFJ
>
>
>
> "Jupiter Jones [MVP]" <jones_jupiter@hotnomail.com> wrote in message
> news:%23PsBqeFYDHA.1620@TK2MSFTNGP12.phx.gbl...> > Mark;>
> > First, IMMEDIATELY disconnect from the internet before a "friend"
> > leaves a gift on your computer for you.
> > DO NOT reconnect until this issue is resolved.
> >
> > Install or enable a firewall immediately.
> > http://support.microsoft.com/?kbid=283673
> >
> > Run an updated virus scan.
> > Or Scan for Viruses online:
> >
> >>
> > Also be sure to update immediately to prevent this in the future:
> > http://windowsupdate.microsoft.com/
> >
> > This will tell you more:
> > http://www.microsoft.com/security/se...s/ms03-026.asp
> >
> > --
> > Jupiter Jones [MVP]
> > An easier way to read newsgroup messages:
> > http://www.microsoft.com/windowsxp/p...oups/setup.asp
> > http://dts-l.org/index.html
> >
> >
> > "Mark Jerome" <mdjerome@hotmail.com> wrote in message
> > news:eavdZnEYDHA.2548@TK2MSFTNGP09.phx.gbl...> > > I too am seeing many of my clients remote PC's going down with this> > same RPC> > > and COM+ errors. The NT Authority auto shutdown that everyone is> > talking> > > about.> > problem.
> > >
> > >
> > > Basically all our users behind a firewall are not experiencing this> > > Remote users that acces the interent and then come to our servers by> > way of> > > terminal connection are dropping like flies.> > against
> > > We have lost many systems today all going down one after another.
> > >
> > > These remote systems, since they use slow dialup were not patched> > > this RPC exploit. We are trying to now but MS site seems swamped and> > we are> > > unable. Fortunately these people can stay up because they can RAS> > into our> > > firewalled site and then user their browser to get the update. Users> > that> > > only have internet access can not stay up long enough to get> > updates.> > >> > talked
> > > All systems affected have the MSBlast.exe file that some poeple have> > > about.> > Symantec or
> > >
> > > Does any security person know whats going on?
> > >
> > > How is the DOS working? Where is it coming from? Any word from> > > Macafee on what msblast.exe is and what other files may have been> > affected?> > >> >
> > >
> > >
> >
>
> Well advise is sound but flawed. TO fix the computers we need thepatch and
> we need acces to get the NAV updates. Problems right now is howSTUPID MS is
> doing this and how unpapared they are. I can only find the patchthrough MS
> update and NOT as a single file download. THis has immenseconsequences
>is that
> Also for sites where we have lots of users on broadband our problem
> MS has not provided this patch as a file which is utterly stupid!!!What
> we all want to do is download ONE FILE. Then disconnect the entiresite from
> the internet. Then apply the patch to all the computers.to get
>
> The way it is now we have to have each and every PC hit the internet
> this patch. MS site is so bogged down it takes for ever. Before anypatch
> can be complete the PC's are getting nailed with this BUG. this is aviciuos
> cycle we can't seem to get out of. Does anyone know where thisstupid patch
> can be downloaded as a file???
| | LinkBack | Thread Tools | Display Modes |
![]() |
| Thread Tools | |
| Display Modes | |
| |
Similar Threads | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| ZoneAlarm Advertising Blocking Denial of Service Vulnerability | JM Tella Llop [MVP Windows] | Windows XP Configuration & Management | 0 | 11-21-2004 06:10 PM |
| IBM HTTP Server Denial of Service Vulnerabilities | JM Tella Llop [MVP Windows] | Windows XP Configuration & Management | 0 | 11-21-2004 06:09 PM |
| Massive slow downs in Win XP | Kyle Szklenski | Windows XP Performance & Maintenance | 0 | 07-31-2003 09:42 PM |
| is it me or is there a massive increase in XP problems? | q | Windows XP Performance & Maintenance | 1 | 07-17-2003 02:57 PM |
| Massive problems...please help. | Chris | Windows XP Network & Web | 0 | 07-08-2003 03:34 PM |
| LinkBack |
LinkBack URL |
About LinkBacks |


Linear Mode


Posts: n/a