Slashdot Mirror


HomeSec Warns Again About Microsoft's Insecurity

cbrandtbuffalo writes "The Department of Homeland Security has posted this advisory about an impending attack on MS systems. This RPC attack has already been seen in some localized systems, but may spread as unpatched computers are exploited. Some of the national news like CNN are running stories too."

97 of 497 comments (clear)

  1. How big a threat is this? by mjmalone · · Score: 4, Interesting

    The security people at my office were talking about this vulnerability yesterday in our monthly meeting, they were saying it is likely going to be worse than slammer/code red/etc (which the article seems to back up)... Do you guys think this is that serious of a threat? A lot of what they were saying sounded like worst case scenario kind of stuff, hopefully it will not be that large of an issue. One interesting thing that the security people mentioned, that the article doesn't, is that windows 98/windows 98se is vulnerable but Microsoft has not released a patch because they no longer support the product.

    1. Re:How big a threat is this? by rde · · Score: 4, Funny

      windows 98/windows 98se is vulnerable but Microsoft has not released a patch because they no longer support the product.#

      So upgrade to Windows XP, or the 73rr0r1575 \/\/1ll win.

    2. Re:How big a threat is this? by tlovie · · Score: 5, Interesting

      I'm not sure if Windows98/se is vulnerable since microsoft's knowledge base specifically states that Windows ME is not vulnerable. The vulnerability is based on a buffer overflow of the RPC service. Does windows 95/98 even offer the RPC service?

    3. Re:How big a threat is this? by Anonymous Coward · · Score: 2, Informative

      they just suck. Windows 98/98SE doesn't enter non support phase until Jan 16 next year.

    4. Re:How big a threat is this? by diersing · · Score: 4, Informative
      It could be bad if the Windows admins out there aren't paying attention. But, most sysadmins in MS shops realize the frequency of these kind of patches and are good about applying them timely. This was released over 10 days ago (I got notified on the 19th), and have already applied it to the 350+ MS servers on our network. If the lazy admin has configured auto-update they are protected as well.

      The primary vehicle for spreading this type of exploit, are all the MS clients of broadband users, many untechy PC owners will be to blame if this things hits hard. And yes, I think it could be worst then slammer/code red because its RPC. Pretty much all the MS client out there are going to have it running (versus an IIS exploit).

    5. Re:How big a threat is this? by iabervon · · Score: 2, Interesting

      It's reasonable to expect this to be worse than some of the other worms, because it is part of a more central and common service. It seems unlikely that future worms will be less effective than past ones, for that matter, since the past ones have generally been disassembled and discussed, and someone writing a worm is unlikely to start from scratch.

      Of course, the vulnerability requires that it be possible to reach the machine with an inbound connection, so firewalled networks will be protected until someone combines this with a document-based vulnerability to attack these networks from inside.

    6. Re:How big a threat is this? by dreamchaser · · Score: 2, Insightful
      The primary vehicle for spreading this type of exploit, are all the MS clients of broadband users, many untechy PC owners will be to blame if this things hits hard. And yes, I think it could be worst then slammer/code red because its RPC. Pretty much all the MS client out there are going to have it running (versus an IIS exploit).


      Perhaps ISP's should just block RPC at their routers that feed broadband users. I can't think of any good reason most people would want it to be exposed anyways, on a residential broadband account at least.
    7. Re:How big a threat is this? by gregmac · · Score: 3, Interesting
      One interesting thing that the security people mentioned, that the article doesn't, is that windows 98/windows 98se is vulnerable but Microsoft has not released a patch because they no longer support the product.

      If this is true, Microsoft doesn't even acknowledge that it affects Windows98. It's one thing to not release a patch for an affected OS, it's quite another to not mention that it's affected.

      --
      Speak before you think
    8. Re:How big a threat is this? by Xformer · · Score: 2, Insightful

      That, or ditch Windows entirely (novel idea, I know :-)

      --
      All I want is a kind word, a warm bed and unlimited power.
    9. Re:How big a threat is this? by mark_lybarger · · Score: 4, Informative

      maybe you were going for +1 phunny, but i'll swing anyway.

      Windows XP isn't really a upgrade for Win98 machines. Win 98 was delivered on PII 266mhz, 32/64MB RAM, 2-4MB PCI Video systems. I would hate to try anything on a system like that with XP. Sure the CPU could handle it, but the memory would need to be seriously upgraded. There's also the issue regarding device drivers. There's a LOT of hardware out from that time period that doesn't have XP drivers.

    10. Re:How big a threat is this? by GrenDel+Fuego · · Score: 2, Insightful

      These days you can buy a computer for not much more than the price of Windows XP home (retail version).

      They're not great machines, but they're better than a PII 266mhz.

      Or as other people said, ditch windows entirely.

    11. Re:How big a threat is this? by saskwach · · Score: 5, Informative

      Someone did their reporting wrong. The huge gaping flaw that was announced recently pertained only to computers with the NT kernel (WinNT, Win2000, WinServ2003, WinXP). This vulnerability does NOT affect 98/98SE/ME/95/3.1/whathaveyou.

    12. Re:How big a threat is this? by los+furtive · · Score: 4, Insightful

      I agree with you. But if you have 128megs of ram (or even 64), I would strongly recommend upgrading to Windows 2000, for the stability alone. A P2 266/300/350 with Win2K is a fine machine.

      --

      I'm a writer, a poet, a genius, I know it. I don't buy software, I grow it.

    13. Re:How big a threat is this? by Lumpy · · Score: 3, Interesting

      and the fun part is that cince corperate IT is so damn slow, current IT policy is "NOTHING HIGHER THAN SP3 on W2K machines."

      so that makes all "OFFICIAL" machines in corperate will be hosed as usual when these things come through... Just like the stupid policy of no virus updates from anywher but the corperate server which is always at least 4-5 behind the software companies site. (Another policy I ignore.. I keep everything at the latest DAT)

      --
      Do not look at laser with remaining good eye.
    14. Re:How big a threat is this? by kikta · · Score: 3, Informative

      Pretty sure they don't. I believe this is something only on the NT side of the house.

    15. Re:How big a threat is this? by timelorde · · Score: 2, Informative

      windows 98/windows 98se is vulnerable but Microsoft has not released a patch because they no longer support the product.

      No, 98 isn't in the list for this vulnerability (MS03-026). But it is in the list for a different one: MS03-030 (the one about MIDI files and DirectX and QUARTZ.DLL)...

    16. Re:How big a threat is this? by norite · · Score: 2, Informative
      What a complete load of tosh!!! I have a pentium 166Mhz machine with 64Mb RAM and it runs windows 2000 just fine. Admittedly, the pentium is overclocked to 200Mhz though....)

      Windows 2000 requires a minimum of 32Mb to run. it won't install on a machine with less than 32Mb RAM.

      --
      -- Fuck Beta
    17. Re:How big a threat is this? by toddestan · · Score: 2, Insightful

      And they also said Windows 95 would run on a 386 with 4MB of ram. Anyone ever try that? They also said Windows 98 will run on a 486-66 with 8MB of ram. I've seen that and it's not pretty.

      It is possible, and it is useable, it certainly is not too responsive.

    18. Re:How big a threat is this? by net-junk · · Score: 2, Interesting

      I really can't say this bothers me much after several people have called me to find out why their systems are down. After going thru the usual questions, one person explained to me that they ran updates on their systems, only to find that each and every one of them got disabled. Now this person has purchased a license for each system, yet this "update" has rendered his systems unusable. Last I heard he was playing phone tag with MS in getting them unlocked, but this brings a question to mind: Is this another ploy of M$ to get everyone to run the update so it can effectivly weed out pirated copies? I mean, it wouldn't really suprise me much if this wasn't another one of their tactics. That is just my thought on this - Thank God for Linux..

  2. Microsoft really did it this time.. by Tirel · · Score: 5, Interesting

    This is turning out to be a huge problem, we got the exploit a bit *cough*early*cough* and by simply joining a channel on IRC you get a handful of IPs, of which at least a few are exploitable. And then they wonder why there are a thousands of ddos zombie machines running windows!

    But there's another problem, a lot of people are starting to distrust microsoft and are turning off the automatic update / not getting service packs instead of switching to another operating system.

    1. Re:Microsoft really did it this time.. by BWJones · · Score: 4, Interesting

      But there's another problem, a lot of people are starting to distrust microsoft and are turning off the automatic update / not getting service packs instead of switching to another operating system.

      Shoot, this was a problem years ago leading me to never enable automatic updates after more than one Windows machine was completely FUBAR'ed after an update. We fought with security issues on Windows for a while, then dealt with the expense and hassle of IRIX (although IRIX is impressively stable), went back to Windows due to the cost and then simply migrated our servers to Apache on OS X. Safe, simple, stable, affordable and secure.

      --
      Visit Jonesblog and say hello.
    2. Re:Microsoft really did it this time.. by Andy+Smith · · Score: 2, Interesting
      a lot of people are starting to distrust microsoft and are turning off the automatic update
      That's exactly what I've done.

      One of their "updates" to Movie Maker (which I use solely to grab DV from an encoder) made the output files incompatible with other video programmes, in particular VirtualDub. Thankfully I was able to get the previous version back by doing a system restore but that's the last time I'll upgrade an MS app when the one I've got is working fine.
  3. How long? by Voltas · · Score: 5, Funny

    2 years / millions of dollars and the Home Land Security people tell me that people like to attack Microsoft Products.

    I'm glad I pay all those taxs!

    --
    -- Disclaimer: I can't really back up anything I post on /. --
    1. Re:How long? by rusty0101 · · Score: 4, Interesting

      And what's the OS Vendor of choice for the Department of Homeland Security? I seem to recall a story or something about it.

      Anyone want to talk to their representative or senators about that decision?

      --
      You never know...
    2. Re:How long? by Jonsey · · Score: 5, Funny

      I'm glad I pay all those taxs!

      And I'm glad our "edjacashun" budget keeps rising to make the US more smarterer.

      --
      I assert that my comment is only my opinion, not that of any employer, past, present or future.
    3. Re:How long? by sniggly · · Score: 4, Interesting

      The sad part is that the NSA itself already was far ahead developing a secure OS that would do just fine for the dept of HS. Instead tax monies go to bill gates and his dancing monkeys.

      --
      Of those to whom much is given, much is required.
  4. Now if we can get them to arrest by MECC · · Score: 2, Funny

    If ew can get them to arrest the board of MS directors, in cluding BIll Gates, and treat them as POWs, that would help things considerably.

    --
    "We are all geniuses when we dream"
    - E.M. Cioran
    1. Re:Now if we can get them to arrest by Zemran · · Score: 4, Funny

      The whole Microsoft staff end up in Gauntanamo bay without trail or legal representation :) Seems fair to me...

      --
      I love stacking my barbecues in the shed at the end of summer - you can't beat a bit of grill on grill action.
  5. Pretty Bad by the.jedi · · Score: 5, Insightful

    My friend works at MIT's network security.
    From wednesday to thursday they're compromise rate
    went from 3 computers an hour to 30.
    Right now they're just blocking the RPC port
    but the routers are starting to take some heavy
    traffic. Looks like this one is going to be pretty
    bad.

    --
    ThunderBird. Nuff said.
    1. Re:Pretty Bad by tarquin_fim_bim · · Score: 5, Funny

      "Which port is it that you need to block?"

      To make windows secure?

      All of them.

    2. Re:Pretty Bad by pascalb3 · · Score: 5, Informative

      Check out CERT, a good site for this stuff. Here's their warning (more info than DHS). A list of what they have to block:
      135/TCP
      135/UDP
      139/TCP
      139/UDP
      445/TC P
      445/UDP

      Also, it appears 4444 is being used,

      Security Focus's incidentmailing list is also enlightening. And for good measure, a posting on the ineffectiveness one of MS's patch (as of 29 Jul).

    3. Re:Pretty Bad by Troed · · Score: 4, Informative
      Mod parent down. Bugtraq posting listing several other attack vectors:

      • ncacn_ip_tcp : TCP port 135
      • ncadg_ip_udp : UDP port 135
      • ncacn_np : \pipe\epmapper, normally accessible via SMB null session on TCP ports 139 and 445
      • ncacn_http : if active, listening on TCP port 593.

      • ... and finally, even port 80 might be used if ncacn_http is active, and COM Internet Services is
        installed and enabled.
    4. Re:Pretty Bad by technix4beos · · Score: 3, Insightful

      Speaking of routers...

      Am I correct in saying that a router can be used at home to prevent these kinds of attacks in the first place?

      With more families getting online and having multiple computers in a network, wouldn't it make sense to install a router that protects against the silly port attacks?

      I believe a router these days costs about $50 USD, so it's far cheaper to purchase one than to buy a software based "firewall" solution, that might be turned off by little johnny anyhow.

      --
      user@host$ diff /dev/urandom /dev/uspto
    5. Re:Pretty Bad by I8TheWorm · · Score: 3, Informative

      Actually, 135, 139, and 445.

      NetBEUI = Port 135 netBEUI is only required when you have non-Windows 2000 clients to support. However, NetBIOS over TCP/IP prevents any need for NetBEUI. These days NetBEUI is the usual answer for connection problems that turn out to be name resolution or NetBIOS configuration problems. The other ports listed, 139 and 445, are used for Server Message Block (which with Win2000 can run directly over TCP/IP rather than needing to run on top of NetBIOS) respectively. SMB is a file sharing protocol used in Windows. The attempt hits 445, and if it's succesful, it sends an RST to 139 (if NetBIOS is installed, otherwise 139 is never used). If there's no response from 445, it continues the SMB session over 139.

      --
      Saying Android is a family of phones is akin to saying Linux is a family of PCs.
    6. Re:Pretty Bad by Tackhead · · Score: 2, Informative
      > ncacn_ip_tcp : TCP port 135
      >ncadg_ip_udp : UDP port 135
      >ncacn_np : \pipe\epmapper, normally accessible via SMB null session on TCP ports 139 and 445

      Etc. Etc. Etc.

      The ironic part is that a Win9x box doesn't run these services. Or any other services - to use a technical term, in comparison to XP and 2K, an out-of-the-box 9x install doesn't listen to jack shit. If you do the 30-second tweak to disable/unbind the NetBIOS crap, you can safely (!) run 9x without a firewall because such a box doesn't listen to 80, 135, 137, 139, 445 etc. Unpatched. (Well, as long as you don't use Outleak Excess or Internet Exploiter, but that's just plain sanity :)

      XP? 2K? Nuh-uh. You can disable UPnP hole (SSDP/1900) from the Services panel, but I have yet to find a way (well, short of a firewall :) of stopping an XP box from listening to 135 and 445. After all, Joe Sixpack who owns just one computer obviously, always wants to be able to network it with NT 4.0 boxen over a LAN. But there's just no way of saying "Look, XP, I don't do that kind of kink. Ever. So stop listening to those ports".

      Thanks, Bill. No, really. Thanks a bunch. Other than a noble desire to take one for the team by jumping on the proverbial grenade, why the hell did HomeSec chose these twits as their vendor of choice?

    7. Re:Pretty Bad by TheViffer · · Score: 2, Informative

      Am I correct in saying that a router can be used at home to prevent these kinds of attacks in the first place?

      Actually that is not correct. A "router" in a nutshell is just used to "route" traffic from point A to point B.

      What what people need is a hardware based NAT switch with firewall firmware. It places that nice "buffer" zone between your machines and the web.

      If if the NAT switch/firewall is compromised somehow, it will not get the hacker very far without the presence of an OS. Your boxes behind should still be safe (but left without networking).

      --
      -- Knowing too much can get you killed, but knowing who knows too much can make you rich.
    8. Re:Pretty Bad by drinkypoo · · Score: 2, Informative
      A so-called home router (some of which are honestly routers, some are bridges, and some are firewalls and little else) will indeed solve this problem. More to the point, simply using NAT will solve this problem, as long as you don't forward the RPC port to something inside your organization. You might consider mangling the packet so that its destination is the originating host and resending, that might be kind of fun.

      Personally, I use a linux system with two NICs as my router/gateway. netfilter/iptables provides possibly the most powerful and configurable IP filtering suite available, and even though I use only a small portion of its features, I know that if I want to make it do all kinds of weird things, I just have to pore through volumes of crappy documentation.

      Of course with linux you must be careful to stay updated. This is true of any OS but less true with, say, openbsd which is what I used to use. I ended up using linux because it has advantages in terms of using it for other things than just a firewall box, and it's an athlon 700 so I can still get some decent use out of it.

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
  6. Ugh. by JohnGrahamCumming · · Score: 5, Funny

    Could we not go around referring to The Department of Homeland Security as HomeSec? The last thing we need is /. popularizing a cool sounding name for this behemoth.

    If we need to refer to it then use the initial letters of its name... DoHs.

    Somehow appropriate when they put out warnings like the last one.

    John.

    1. Re:Ugh. by glwtta · · Score: 4, Funny

      I just tend to call it MiniPax - is that better?

      --
      sic transit gloria mundi
    2. Re:Ugh. by chrisgeisel · · Score: 2, Funny

      I prefer "Ministry of Love". We are at war with drugs err, al queda err, iraq err, gay marriage. We have always been at war with gay marriage.

  7. The Department of Homeland Security? by Wacky_Wookie · · Score: 5, Insightful

    Sounds more like The Department of Homeland in-security :)

    Joking aside I find the US media's "fear hyping" to be outrageous.

    "It could happen to you" Is a major catch phrase for the US media, and they are not talking about winning the lottery.

  8. They should know! by jocknerd · · Score: 3, Funny

    After all, they're giving Microsoft $90 million to run their computers.

  9. I feel bad for the Poor slob(s).... by curtisk · · Score: 4, Insightful
    ....that works at Dept. of Homeland Security whose entire job will consists of keeping up to date with MS security advisories....

    wonder how they (DoHS) are feeling about their OS investment already? :)

    --

    Sehr geehrter Toilettenbenutzer!

  10. windows at the office?? by chef_raekwon · · Score: 5, Interesting

    i could have sworn that 2 weeks ago, here on this very same slashdot....there was a story about HomeLand Security securing a very large purchase from Microsoft....aka 100 million, or some outrageous number like that..

    isn't this a bit irresponsible of them, now that they are declaring Windows a vulnerability?

    --
    We're like rats, in some experiment! -- George Costanza
  11. Hilarious! by Wilersh · · Score: 5, Funny

    Microsoft is now officially a threat to Homeland Security. Maybe George should drop some bombs on Redmond! We know where they are and they keep putting out a product that threatens our security. Oh wait, the government saw fit to give them a slap on the wrist and turn around and contracted even more unsafe software from them. They'll undoubtedly be mentioned in future hindsight publications from congress but on blanked out pages for national security reasons. That's what we do for "friends".

    Ugh.

    Wilersh

    1. Re:Hilarious! by kinnell · · Score: 2, Funny
      Maybe George should drop some bombs on Redmond

      ...or maybe he should summon the giant penguin of the apocalypse.

      --
      If I seem short sighted, it is because I stand on the shoulders of midgets
  12. Color scale? by Elendil · · Score: 5, Funny

    On the DHS alert color code, blue means "guarded", just one notch lower than the alert level the USA have been living in for the last few months (with occasional orange flares). Should this color be reconsidered in sight of the well known Blue Screen of Death?

  13. Switch campaign kick-off by SgtChaireBourne · · Score: 5, Insightful
    One interesting thing that the security people mentioned, that the article doesn't, is that windows 98/windows 98se is vulnerable but Microsoft has not released a patch because they no longer support the product.
    A second interesting thing is why just this particular bug is getting the publicity. There's been no shortage of remote exploits for that product line, old or new, this year. Is it part of the new marketing campaign that's just kicking in?

    Along those lines, since most of the design flaws are downplayed for weeks/months/years after exploits are found. Apple, RedHat and SuSe have a good lead time to prepare switch campaigns.

    I'm sure a dollar value can be put on the peace of mind and increase productivity that goes with moving to a better workstation platform.

    --
    Beta is broken and the link to classic doesn't work. Stop wasting our time or there won't be anybody left here.
    1. Re:Switch campaign kick-off by Cromac · · Score: 2, Insightful
      A second interesting thing is why just this particular bug is getting the publicity. There's been no shortage of remote exploits for that product line, old or new, this year. Is it part of the new marketing campaign that's just kicking in?

      It's possible that the reason this bug is getting publicity by the Dept of Homeland Security and others didn't is simply because they know about this one. Yes, other security problems are out there and "known" but maybe not by the people at HS. Remember even though it's a large government agency the bottem line is it's still run by people who may not have all the facts.

    2. Re:Switch campaign kick-off by platypus · · Score: 2, Interesting

      Maybe I'm ignoring the severity of this new Microsoft flaw, but why the Dept. of Homeland Security issuing ANY statement about security flaws in any operating system?

      Maybe because their PR department was scheduled to prodce some proof for their right to exists,but they didn't have any terrorists handy ATM.

      Seriously, this shouldn't be their job, in the end they will be just echoing CERT or bugtraq, while wasting a lot of money into "network security research".

  14. Again.. by NetJunkie · · Score: 4, Insightful

    Patch your stuff and for goodness sake put up a firewall! RPC port open to the word? Why?!

    1. Re:Again.. by White+Roses · · Score: 5, Funny
      RPC port open to the word? Why?!

      So it can be saved and get into heaven. Oh, you mean world.

      --
      Do not touch -Willie
  15. Govt should use its own OS. by sniggly · · Score: 5, Insightful

    It's time the government started to realize its own linux version has been developed to preclude vulnerabilities such as these that are caused mostly by sloppy programming.

    --
    Of those to whom much is given, much is required.
  16. Well engineered worms by Catskul · · Score: 5, Insightful
    I think it is going to be worse if someone actually has an objective (ie terrorists) because all of the worms I have heard of have been fairly poorly engineered.

    A well engineered worm would:

    Work on many different system.

    Use more than one security flaw. (spread by email, + kazaa, + IE hole, + sendmail hole)

    Patch that flaw once compromised, and open a separate hole

    Have at least different attack modes (slow and quiet and local sub nets, fast and hard and whole internet)

    Build up to critical mass before initiating fast attack mode.

    Attempt to hide itself from scans. (maybe randomly stop functioning for a while to offer false sense of security)

    Adjust its fingerprint so that it isn't simple to find computers which have the worm (use different ports, different protocols, send some different data when filling buffers etc)

    Offer a payload that makes patching difficult, goes after security websites that often offer patches, targets financial institutions, etc.

    Patch other programs on the system, back to previous insecure versions.

    And that's just off the top of my head. If someone really is sitting down and thinking about this, Im sure they could come up with much more dangerous specifications.

    I think someone should be writing a competing worm that patches all vulnerable systems, just in case this breaks out in to a chrisis.

    --

    Im not here now... Im out KILLING pepperoni
    1. Re:Well engineered worms by digitalunity · · Score: 4, Insightful

      In case you hadn't noticed, few virus writers are developing malicious code. It would appear that most of the internet worms of late are fairly innocuous, and their only design feature is the ability to replicate itself. However, there are others that send random files by e-mail to random people. That was kind of funny. No, if someone wanted to write some really mean code, they'd set up a worm that would find and infect at least a few hosts, and then destroy it's host OS. It wouldn't spread as fast as non-destructive worms, but it'd cause a lot of trouble for a lot of people.

      Personally, this RPC bug doesn't really get me thinking much. Anyone stupid enough to allow incoming RPC packets from the internet deserves what they've got coming. Now, on the otherhand, if a live exploit for BGP4 was ever discovered and published, we'd be in a world of hurt for quite a while.

      --
      You can't legislate goodness. Let each to his own destiny, by will of his freely made choices.
    2. Re:Well engineered worms by Finni · · Score: 4, Insightful
      Anyone stupid enough to allow incoming RPC packets from the internet deserves what they've got coming.

      True, but that doesn't cover any/all cases at all. Businesses with Windows servers can't turn off RPC (and sometimes can't turn off DCOM) on their users' laptops, right? So a laptop user goes home and uses dialup, or he has broadband and no router and gets infected. No he comes back into work the next day. The MS-supplied patch doesn't work in all cases, so even if they have a good patching system and a great firewall, they've still got a compromised, infectious system on their LAN. Mobile-user VPN has the same risks.

    3. Re:Well engineered worms by hey · · Score: 3, Interesting
      Thanks for the tips ;-)

      Yeah, I like the idea of changing DLLs on a system back to insecure versions and (of course) keeping the Add/Remove Programs list saying they patches have been applied. Needless to say this would be other worms/viruses would get in further making diagnosing more difficult.

      If we want to see what nasty viruses do we need only look at nature. For example, AIDS (or the HIV virus if you want to be exact) attacks the immune system -- the part of the body that fights viruses. People with AIDS then die with opportunistic viruses, like pneumonia, take advantage of the situation. If you wrote a computer virus that only attacked the immune system of the net it would be quite a sight to see.

      • Launch DDOS attached against Windows Update, Symantec, Norton, CERT websites
      • Make the Windows update agent think all is well but to the user appear to functioning properly
      • Likewise neuter virus checking programs by say altering their .EXE's to check for a different .DAT file. If the user can manage to get a current .DAT file he replace one that the program isn't looking at :-)
    4. Re:Well engineered worms by WhiteWolf666 · · Score: 5, Insightful

      Or, maybe, create a set of worms

      IANAWC (I am not a worm creator), but, you could have all kinds of worms running around. One that attacked on a large scale, seeking to infect as many systems as possible. Then it would download extra components as needed, but otherwise sit dormant, awaiting the final component. One that sought out unpatched, vulernable, Windows 2000/XP boxes, to use as a permanent base of operations (This one could be BIG). One that sought out infected systems, and modified the worm continuously, to confuse scanners. Any maybe, you could even have the dang things self-destruct? I don't know much about this, but you can setup applications on a Windows 2000/XP box that won't run until the next realmode boot, right? If it installs itself as a system file, scanners won't be able to remove it unless they run before the system is fully booted up. But if your worm runs the next time pre-bootup system maintenance is scheduled, and runs before any other task, you could have it eat the harddrive.

      If one were to prepare this sort of thing ahead of time, and released the worms one by one, most of the security community wouldn't anticipate the attack. Especially if they were all encrypted, and you released them in a quick enough period such that it would not be obviously that they were working together until after the fact.

      The other thing I wonder is why worms haven't targeted the infrastructure of weak networks. Like that worm that was discovered on the comcast dns servers. If somewhere were to create something that attacked the Windows 2000/XP (or any other operating system, but Windows seems like it would be the most vulnerable) TCP/IP stack, and only attacked systems behind vulnerable routers, and then utilized the hacked TCP/IP stack and hacked routers to hide all of the traffic, it would be extremely hard for anyone to tell what had happened, right?

      Of course, all of the things I have just said won't work, as I've described them. My knowledge of this topic is just too limited to really make much sense, but my point is I don't think we have seen a coordinated effort to run multiple, smaller worms in concert. This way you can spread a rapid, smaller infection, and use it to pave the way for a much more deadly, and harder to remove infection.

      --
      WhiteWolf666 an exBush supporter. All you new-school,compassionate,save the children Republicans can rot in hell
    5. Re:Well engineered worms by Anonymous Coward · · Score: 2, Funny

      ...Or, maybe, create a set of worms...

      if a set of geese is a gaggle,
      a set of whales is a pod,
      a set of cows is a hurd,
      is a set of worms a can ?

      ...Or, maybe, open a can of worms...

      HA! I Crack my self UP!

    6. Re:Well engineered worms by Finni · · Score: 3, Interesting
      No. This has nothing to do with forced upgrades, because

      1. They made patches for this covering all the way back to NT 4.0

      2. They don't charge for these patches.

      3. The bloody patch doesn't work.

    7. Re:Well engineered worms by nat5an · · Score: 3, Insightful

      Well, admins can turn off RPC on their users' laptops. The average user probably has no need for this service to be running. Of course, you never know what Microsoft is using it for. You turn off the RPC service, and suddenly 10 unrelated things stop working. Such is the fun of being a Windows Admin (and I would know).

      --
      Head down, go to sleep to the rhythm of the war drums...
    8. Re:Well engineered worms by tsa · · Score: 2, Insightful

      And since most users are completely incompetent in configuring and securing their PC, if I had a business I would forbid them to use their own computers for work.

      --

      -- Cheers!

    9. Re:Well engineered worms by johnnyb · · Score: 3, Interesting

      Actually, destroying the whole OS isn't as bad as you can get. Imagine if there were a worm packed with a payload like CPUburn! Or if it had drivers which hosed hardware. Especially if it was set to go off in the middle of the night, you could actually have a virus which inflicted hardware damage.

    10. Re:Well engineered worms by Vainglorious+Coward · · Score: 2, Insightful
      In case you hadn't noticed, few virus writers are developing malicious code.

      While it's generally true that historically, most viruses have had feeble or non-existent payloads, the evidence is strong that some of the waves of infection this year have been created by spam gangs, using viral infections to install proxy software.

      --
      My next sig will be ready soon, but subscribers can beat the rush
  17. HomeSec. Ingsoc. MiniPax. Double-plus good. by thelandp · · Score: 5, Funny
    The name "HomeSec" reminds me of a few similar terms from George Orwell's important (and never more appropriate) book, 1984.

    Most government departments actually are designed to achieve the opposite of their names. For example, the "Department of Homeland Security" is in fact designed to control the level of insecurity that people feel. Likewise, the ministry of defence is really about offence, and in 1984 the Ministry of Information is about disinformation and so on.

    In the book, the language was controlled to the point of creating new terms like IngSoc, MiniPax (ministry of peace, really designed to perpetuate war), and Double-plus good.

    The whole point here is to justify the actions of the government. Because it becomes alot easier to justify removing civil rights when there is the perceived threat of some common enemy.

    --

    -- the only thing we have to fear is really scary things
  18. the patch is really a trojan (funny) by number6x · · Score: 2, Funny

    The patch from MS is really a trojan!

    Go to this link to learn more!

  19. security through obscurity by BigBir3d · · Score: 2, Funny

    I guess that is why our IT Department doesn't want to update the desktops beyond Windows 98. "Hackers target the newest OS" is what he said. Apparently system stability is not a high concern :(

  20. Re:Why are they even working on this? by admbws · · Score: 2, Funny

    Can't you see??? If they don't tell anyone about these vulnerabilities, "terrorists" will take advantage of them and kill hundreds of thousands of people! What if "terrorists" hacked into the Win98 computer controlling one of the many Nuclear Reactors based in the United States? Can you imagine the havoc that could cause?!?!

  21. No patch for Win98/SE? by shunnicutt · · Score: 5, Funny

    This suggests a new marketing slogan:

    "If you don't upgrade to Windows XP, then the terrorists have already won!"

    1. Re:No patch for Win98/SE? by akiaki007 · · Score: 2, Informative

      I believe this only effects the NT based computers, since it is a RPC hack and 98 and below aren't NT based computers, thus don't run an RPC server!

      --
      "Time is long and life is short, so begin to live while you still can." -EV
  22. That's not true by TheConfusedOne · · Score: 4, Funny

    "Which port is it that you need to block?"

    To make windows secure?

    All of them.


    You only have to block the port where the power cord goes into the computer. :-D

    --
    --- I wish I could hear the soundtrack to my life. That way I'd know when to duck.
  23. Can I suggest some newspeak by Rogerborg · · Score: 2, Funny

    Instead of saying open source versus closed source, how about we just start saying open source versus untrustable? That might help to chivvy things along.

    --
    If you were blocking sigs, you wouldn't have to read this.
  24. Linux Users? by Chibi+Merrow · · Score: 5, Informative

    I'm a tech on a Windows network for the local government here and we immediately disable Automatic updates on machines now. Lord knows it's not because we're Linux users (I'm the only one) but because the updates all too often BREAK things that were already working.

    --
    Maxim: People cannot follow directions.
    Increases in truth directly with the length of time spent explaining them
  25. google is fun by sniggly · · Score: 3, Interesting

    Concidence or not? google news' primary link to this story points to the register's article about this vulnerability. In their best sour Brit register tradition theyre none too congratulatory about "free patches". Does bandwidth cost money?

    --
    Of those to whom much is given, much is required.
  26. WoMD? by vgaphil · · Score: 3, Funny

    Windows of Mass Destruction?

    --
    A clever person solves a problem. A wise person avoids it. -- Einstein
  27. Homeland INSecurity Spinning a Bad Decision by FreeUser · · Score: 2, Insightful

    Think of it as "Homeland Security eats its own dog food..." In other words, they are using the same operating system that the vast majority of people use, so they will experience the same vulnerabilities. They'll be able to advise people about computer security from first-hand experience, not just from a few pristine 'test lab' machines.

    That's a good spin on an incredibly incompetent IT decision, but at the end of the day, spin is all it is.

    You want a testbed for vulerability? Fine. Set up a windows lab with its own dedicated internet connection and absolutely no way to talk to the rest of your internal network. Catalog, experience, and enjoy the chaos that ensues.

    Do not, I repeat, do not deploy it as your platform for collecting, collating, analyzing, and addressing security threats. What good is Homeland INSecurity going to be when they need to address a real, meatspace threat and a Microsoft worm has taken down most of their IT infrastructure?

    Some perhaps, but they certainly will be operating at a severely degraded effeciency level.

    --
    The Future of Human Evolution: Autonomy
  28. Re:how long has the patch been available? by Rogerborg · · Score: 4, Funny

    Jeez, you Microserf zealots are getting irrational and touchy. Back off man, that's our shtick. ;-P

    --
    If you were blocking sigs, you wouldn't have to read this.
  29. Unfair to public servants by laetus · · Score: 2, Interesting

    You know guys, not everybody in the government is fawking off and trying to screw you out of your legitimate right to freely download copyrighted music.

    There are thousands of hardworking men and women serving in Coast Guard ships off our coasts, monitoring land border crossings, inspecting imported cargo containers, and serving as airport security inspectors and skymarshals, all to keep your bloody arses safe behind your monitors as you make fun of them.

    Sorry for the rant, but reality check, there ARE bad people in the world that are intent upon harming the United States and a good number of Americans working at the Department of Homeland Security are intent upon preventing that from happening.

    Instead of easily making fun of these institutions, how about sitting down and thinking about better ways to reduce risks cost effectively. Propose it, then make your criticisms.

    --

    "We're sorry, but the website you're trying to reach has been disconnected."
  30. Security by atcurtis · · Score: 5, Funny

    To make your computer truely secure, follow these simple steps:

    1. Get a decent firewall
    2. Configure it to deny everything except the ports you really need.
    3. Unplug any conputer with really sensitive data from the network
    4. In fact, unplug it from the wall power socket
    5. Heck with it, it's still vulnerable from someone at the console - encase it in concrete
    6. Cover the concrete block with copper sheeting to prevent against Echelon
    7. Cover it with lead plate just to be safe from X-Rays.
    8. Put it on a back of a trailer and tow it into a deep mine shaft. Salt mines go pretty deep.
    9. More concrete please!
    10. Use a tactical device to ensure that access to the bottom of the mine is difficult.

    Should be truely secure... But for the overtly paranoid, concider dropping the planet into your local black hole. Please note that there may be information leakage as any entropy is represented on the black hole's event horizon.

    Not practical... But fun.

    --
    -- The universe began. Life started on a billion worlds...
    -- Except on one where stupidity was there first.
  31. It's all right by Rogerborg · · Score: 4, Funny

    "Based on this notification, no change to the Homeland Security Advisory System (HSAS) is anticipated; the current HSAS level is YELLOW."

    Hasn't it been yellow for like ever? I think they just can't figure out how to change the bulb.

    Slightly more seriously, are we all comfortable with the idea that the Vaterland Security Advisory System is now here to stay, and that it's now featured in contexts where the words "external" or "terrorists" don't appear? That Homeland Security bulletins, much like the "troops killed in Iraq" daily scorecard, are now routine routine occurances?

    I've just had a kid. When he starts asking what the HSAS is, what do I tell him? "We're at War, junior. We've always been at War. Terrorists, drug barons, organized criminals, religious extremists, crackers, hackers, commies, arabs, they're all out to get us, and it's important to know just how scared the government wants us to be that we're going to die today."

    Nice world he's going to grow up in.

    --
    If you were blocking sigs, you wouldn't have to read this.
    1. Re:It's all right by pmz · · Score: 2, Interesting

      I've just had a kid. When he starts asking what the HSAS is, what do I tell him? "We're at War, junior. We've always been at War. Terrorists, drug barons, organized criminals, religious extremists, crackers, hackers, commies, arabs, they're all out to get us, and it's important to know just how scared the government wants us to be that we're going to die today."

      Nice world he's going to grow up in.


      I don't know why this is modded "Funny". Yeah, the world turning into shit is so funny I'm in pain from laughing.

  32. Port blocking by Gothmolly · · Score: 5, Insightful

    Is it me (insert tinfoil hat joke), or is anyone else disturbed by the increasing tendency of ISPs and vendors to say 'just block port xxx' on your network connection, as a response to problems? Is this one more step on the road of converting the Internet to simply an MSN-ified WWW? Where does the small, independent content creator turn as more and more barriers to market entry are enacted, either by FUDding ISPs, lobbying Congress, and blatant stupidity?

    --
    I want to delete my account but Slashdot doesn't allow it.
  33. Fixes by DanV · · Score: 3, Informative

    If I understand right, 4444 is the port the exploit for the DCOM bug connects to.
    I updated all my systems,and firewalled 135/139/445(UDP and TCP) and 4444(TCP).
    I know I am gonna get modded down for this,but if you dont have already, I suggest you fix this ASAP.
    You can get the fix from here for windows 2000, and here for windows xp.

    The exploit has it in the code:

    target_ip.sin_port = htons(4444);

    Also, notice the comment about the shell code:
    /* port 4444 bindshell */

    Dan
    Security consultant
    ClickNews

  34. Already hearing it as an excuse... by Satan's+Librarian · · Score: 3, Insightful
    For boxen being broken at ISP's. Interland trashed a rather important co-located server for us over the weekend, and blamed it on a "Worm" referencing this bug. AFAIK, no worm has yet been released, and certainly none was out then - anyone else been fed this kind of b.s.? Anyone heard of any truth to it at all?

    As far as DoHs getting in on the action - I think they'll cry wolf at anything to keep interest. The more afraid the public is on a daily basis, the more they are legitimized. I was appalled the other day to see this article on the front page a few days ago - no shit guys, thanks for the press release. Ya know what else? .COM stocks might not be the best investment if the company hasn't produced a product.

    Obviously this hole is a major one, but we've kinda known that unfirewalled Windows boxen on the net are a Bad Thing (tm). This hasn't changed, and it's not much more likely now for a worm to run rampant through everything that it was in the past - it'll happen, it'll suck, and everyone will do the same fire drill as every other time it happened. And a few, bright IT departments will switch to FreeBSD or similar for their external machines or put up a bloody firewall.

  35. Who or what can you trust? by dollar70 · · Score: 2, Interesting
    Look, this is not meant as a flame or troll, but new updates/patches are coming out every 10 minutes, and conspiracy theories keep flying around like its a tin-foil hat party. The only patch I've ever decided I had to install was the one for Win95 back in '98 because I kept getting "nuked" whenever I went into an IRC chat room. Win98 was that patch. Then one day I discovered GRC.com and realized I was leaking crap all over the web. So I put ZoneAlarm on my PC and felt relatively secure. Yes, I was one of the poor suckers that actually got the free rubber collectors' watch with my purchase of Windows ME. After much hesitation I finally decided to plunge into broadband, and felt the need for a NAT router, but still kept ZoneAlarm turned on for good measure. With the introduction of XP and the EULA I couldn't abide, I started seriously looking into the option of Linux. By this time, MS was crankin' out the updates every time a new weblog started.

    Now why should I trust MicroSoft? They led me down the primrose path to endless updates that either show no noticeable effect, or cause my computer to act flakey.

    Why should I trust HomeSec? I'm never going to feel secure so long as they keep throwing terror alerts in my face as an excuse to keep whittling away what's left of my civil rights.

    And why should I trust the Linux community who's mainstay advice is "RTFM". I'm stuck using Lycoris until I can figure out how to get Wine to work under a better distro. (I'm sorry but some programs designed to run under MS Windows are just too cool to ignore.)

    As far as I can tell, these so called updates could be trojans to give backdoor access to HomeSec so they can determine the efficacy of their scare tactics, and Linux is a twisted plot to make borderline-geeks like myself waste their time reading endless man pages trying to figure out how the damn thing works.

    OK, so maybe I'm sounding a little frustrated, but all I really want is a nice little computer that does only what I tell it to do. Is that too much to ask?

    --

    Next stop: Insanity

  36. Port/Process utility for Windows? by simetra · · Score: 2, Informative

    Is there a utility/app/shareware thing that will tell you what process on WinNT/2K/XP is associated with whatever ports are active? Thanks. Really, I mean that.

    --

    "Would it kill you to put down the toilet seat?" -- Maya Angelou
    1. Re:Port/Process utility for Windows? by gregarican · · Score: 4, Informative
      Search for a utility called FPort. It will map out all of the active PID's with the TCP/UDP port and associated process. Some processes can hide themselves through rundll32.exe (Win9x) or svchost.exe (WinNT/2K/XP), however.

      But you can get an idea about what ports are sitting out there either listening or actively transferring.

  37. Microsoft's Insecurity? by Captain+Large+Face · · Score: 2, Funny

    Perhaps all it needs is a big hug? I know we all call Microsoft a massive anti-competative tool of the Devil, but these comments do HURT.

  38. How much more secure would we be with Linux? by Eric+Damron · · Score: 2, Insightful

    I'm very much pro-Linux. I switched from Microsoft to Linux years ago. It was kind of hard because so many "fun" programs could only be had in Windows. So I ran a dual boot for quite some time.

    I finally removed Windows altogether. After a few months of running only Linux it struck me. My system had NEVER crashed after doing so. Programs would sometimes hang but the system stayed up, not requiring a reboot. It was like an epiphany. I just started laughing!

    I was also relieved that I no longer had to worry so much about viruses. Or do I?

    My question is: If Linux becomes the dominate desktop and virus writers switch their main focus onto my OS of choice, would we be in as bad a shape as Microsoft's XP, 2000, etc?

    --
    The race isn't always to the swift... but that's the way to bet!
  39. DHS warns about windows. by Mr_Icon · · Score: 2, Funny

    DHS warns about Windows.
    I see.
    Did their solution involve duck tape and plastic sheeting?

    (Though I must admit, after about 20 minutes the computers protected this way will be VERY secure. :))

    --
    If you open yourself to the foo, You and foo become one.
  40. Security alerts and bad economy by just+fiddling+around · · Score: 2, Insightful
    Slightly offtopic, but here goes:

    As there is a permanent terrorist alert going on, could it be possible that everybody is scared from going about and conducting their business? Can this explain USA's shitty economy while Canada's is better than ever and the CA$ is constantly going up?

    [tasteless joke]
    Go MiniHomeSec! Let us commie canadians get on top!
    [/tasteless joke]

    --
    You're not old until regret takes the place of your dreams.
  41. The Net is safe from my computer by frovingslosh · · Score: 2, Funny
    I have right here a computer that is much more powerful that the million dollar plus CDC computer that provided services to my entire University when I went to school. It's more powerful than the 90 user time sharing system I was in charge of for another university. But the Internet is safe from having all of this potential computing power unleashed against it. Why? Because I hobble that dangerous computing power with Microsoft(R) brand software! Yes friends, that's right. No matter how powerful your computer is, you can rest assured that it can do little harm on the 'Net when it's running Microsoft(R) brand software, the software that not only opens security vulnerabilities but makes your system so slow that it just can't do much harm to the rest of the 'Net. And , as an added bonus, my Microsoft(R) software crashes frequently, so I reboot it often and just maybe that might eliminate or at least confuse some exploits. And when a world full of computers are crashing several times a day, it's just that much harder for exploits to find ones that are up long enough to exploit. And any exploit is likely to be minimally more inconvenient that running the Microsoft(R) software in the first place.

    Don't unleash your powerful computer on the Internet. Tame it with Microsoft(R) brand software today.

    --
    I'm an American. I love this country and the freedoms that we used to have.
  42. Re:How to distribute patch to hundreds of machines by gregarican · · Score: 2, Informative
    Personally I still use logon scripting. There's a third-party addon called KixTart that allows more sophisticated scripting. Most of the time I take this route with desktop clients.

    If your desktop clients aren't Win2k and higher (therefore not vulnerable to the RPC hit) and don't have publicly exposed IP address (i.e. - inside a Internet firewall or proxy) then you are just talking about servers.

    In that case don't have you any remote control software (e.g. - VNC, SMS, PC Anywhere, etc.)? If so just put the patches on a common network share and remote into the boxes to install. If you aren't talking about more than 10-20 boxes it shouldn't take too long. If you are talking about more than that perhaps script out AT jobs to the boxes to execute KixTart scripts or something.

  43. Scanning != virus by intermodal · · Score: 2, Insightful

    Did anyone else notice that they equated scanning to cracking? While I know that's certainly one of the possible preludes to attacks, it's certainly not a definite. I've used scanners quite legitimately more than once (checking what was visible from outside a firewall for my father in law, and testing to see if a non-responding server that I myself was responsible for even had its services running, despite it not being at my present locality). The internet was built to be open initially, and while it's understandable that it now needs security, people need to realize there's more to the internet than ports 80 and 6667, (plus those ones that most users don't ever see, like their port 25 services or port , ). There is far more to networking than HTTP, and the internet is a network.

    It's getting to where knowledge is a crime, and while I feel it would be prudent to learn more and more about computer security, I fear that merely knowing it might make me liable to be wrongly prosecuted. There's just come to be so many legal barriers or poltergeists that it just carries too great of risks for the curious to enter the field.

    --
    In SOVIET RUSSIA... erm...NSA AMERICA, the Internet logs onto YOU!
  44. Conputer??? by Evil-G · · Score: 2, Funny

    Unplug any conputer with really sensitive data from the network

    is a conputer one which is running windows?

  45. Re:Don't know. by colenski · · Score: 2, Informative

    http://www.eeye.com/html/Research/Tools/Download.a sp?file=RetinaRPCDCOM

  46. HomeSec should stay out of this by gad_zuki! · · Score: 2, Insightful

    Wow, a malicious worm. I'm completely bewildered by the fact that melissa, code red, etc didn't have a seriously nasty payload. It seems like the virus authors just wanted propagation for bragging rights. It wouldn't be so tough to write a function that will corrupt the registry or start formatting important parts of the disk after x amount of hours.

    Windows has yet to see a serious threat by a popular worm and when it does there will be a lot of heat on Microsoft, whether they deserve it or not. "Wintel everywhere" is a classic eggs in one basket gambit and heads are going to roll if 1/3rd of all computers on the internet suddenly refuse to boot up again. Something like 40% (?) of all computers on the net are not behind a firewall and who knows how many are patched.

    What I'm afraid of is that if something this bad and on this scale happens then DRM will go from controversial content protection to a Tom Ridge mandated upgrade. Your computer WILL download the newest patch and you will not rip MP3s from the newest Shania Twain CD or face the consequences (ISP banning you, fines, etc).