Slashdot Mirror


Win32 Blaster Worm is on the Rise

EvilNight writes "You know you've got it when a 60 second shutdown timer pops up on your screen. The virus uses the RPC vulnerability. It looks like it's reaching critical mass today. Luckily, it's an easy one to stop: Download this security update. Once you've installed that patch, go here and download the removal tool." Update: 08/12 19:19 GMT by M : Security bulletin URL corrected.

72 of 1,251 comments (clear)

  1. Wrong link by JPelzer · · Score: 5, Funny

    Shouldn't the "Removal Tool" link point to a Linux ISO download site or something? I mean, this is slashdot... :-)

    1. Re:Wrong link by TopShelf · · Score: 2, Funny

      Preferably SCO's, right? Might as well burn up their servers...

      --
      Stop by my site where I write about ERP systems & more
  2. The Rise by mao+che+minh · · Score: 5, Funny
    DOOM-DOOM-DOOM-DOOM DOOM *PANG*
    DOOM-DOOM-DOOM-DOOM DOOM * PANG*

    At 10:06 AM, August 12th, 2003, Skynet launched dah Win32 Blaster Wahm. It quickly seized contrahl of ahh computers on the Net and forced a mahndatory reboot.

    OK this is getting old.....

    1. Re:The Rise by paranode · · Score: 1, Funny

      Vote for me if you want to live!

    2. Re:The Rise by Anonymous Coward · · Score: 2, Funny

      Coincidence??

      Nope. The whole world revolves around your movie watching habits.

  3. Much better removal tool.. by _14k4 · · Score: 2, Funny

    fdisk
    format
    install FreeBSD or keep your copy of Winders up to date. :)

    1. Re:Much better removal tool.. by Anonymous Coward · · Score: 3, Funny

      I tried that and nothing happened ??

      Microsoft(R) Windows DOS
      (C)Copyright Microsoft Corp 1990-2001.

      C:\>fdisk
      'FDISK' is not recognized as an internal or external command,
      operable program or batch file.

      C:\>format
      Required parameter missing -

      C:\>install FreeBSD

      C:\>WTF !!!

  4. Re:shutdown /a by Pionar · · Score: 3, Funny

    >Why he hadn't fixed it already is a mystery, especially since slashdot.org is his homepage.

    You actually believe that reading /. makes you smart? Apparently, you never read comments below 5.

  5. Virus by Anonymous Coward · · Score: 5, Funny

    If this thing wouldn't keep crashing computers, it would be spreading like greased wildfire.

  6. A sure fire method to solve this RPC exploit by Dental+Plan · · Score: 0, Funny

    not patching your Windows machine... that's a paddling!

    not using a firewall... that's a paddling!

    not using Linux as you should be... you better believe that's a paddling!

    1. Re:A sure fire method to solve this RPC exploit by caluml · · Score: 3, Funny
      I paddle my wife, but she still insists on using Windoze.

      Threaten to not paddle her - that might make her change.
      (She might be darker than you think!)

  7. Re:shutdown /a by whiteranger99x · · Score: 3, Funny

    Apparently, you never read comments below 5.

    In some cases even THAT doesn't mean you'll see smart comments

    (hell, look at MY 5 point comments sometime lol ;)

    --
    Join the TWIT army now!
  8. Slight change by Anonymous Coward · · Score: 0, Funny

    Can anyone be so kind to take this worm (since I already patched my system) and change windowsupdate.com to something more interesting like

    sco.com
    riaa.org

    Thank you

  9. This thing hit our customers yesterday... by Snarfangel · · Score: 5, Funny

    I work at an ISP, and over half of our tech support calls yesterday were because of this worm. You wouldn't believe the number of people who thought we were somehow going into their computer and not only kicking them off the internet, but rebooting their computers. (Yes, sir, the tech support staff feels horribly underworked today, so we thought we'd make things more exciting and pi** off a few customers in the process.) I hope they find the person involved and perform medical experiments on him.

    --
    This tagline is copyrighted material. Please send $10 for an affordable replacement.
    1. Re:This thing hit our customers yesterday... by brakk · · Score: 2, Funny

      pi**

      Just say it. PISS PISS PISS

      Slashdot doesn't restrict any words. If you want to protect people from your "bad" language, then change your wording.

  10. Just seen an ATM affected... by mccalli · · Score: 5, Funny
    Seriously. If you fancy a laugh, and you're working in the City of London, then go to the Halifax ATM between Canon Street and Poultry.

    Then try, really, really hard to stop laughing...

    Cheers,
    Ian

  11. Surprised? Not me by Anonymous Coward · · Score: 1, Funny

    Have fun patching, windows lusers. Maybe linux isn't ready for the desktop, but this goes to show that windows isn't ready for the Internet.

  12. Virus, not starring Jamie Lee Curtis. by Channard · · Score: 3, Funny

    Man, it's almost as bad as that Teddy Bear virus *cough*

  13. Re:Windows Update slashdotted? by javatips · · Score: 4, Funny

    or maybe the machine reboots every 60s

  14. Shoot The messenger... by decepetion · · Score: 2, Funny

    My wife calls me upstairs last night.."The machine keeps shutting down".. Me: "what" *looks at task manager* Task Manager: msblast.exe Me: "Why isn't the firewall turned on?" Wife: "I Hate having to answer all of its questions, so I turned it off." Me: AAAARRRGGGHHH

  15. Re:Good timing... by irc.goatse.cx+troll · · Score: 4, Funny

    Something similer happened to me yesterday. A friend of mine immed me saying his computer kept saying it had 60 seconds to reboot, and something about rpc crashing. So I responded with a screenshot of dir c:\ running on his machine.
    Moral of the story: I'm an asshole.
    (For the record, I then told him where to get the patch, and how to cancle a running shutdown.)

    --
    Pain lasts, kid. Its how you know you're alive. Sometimes I think this growing up thing is just pain management-TheMaxx
  16. I might not be speaking for everyone, but I say: by burgburgburg · · Score: 5, Funny

    I welcome our new Skynet Overlords.

  17. Re:Fscking Windows. by Anonymous Coward · · Score: 2, Funny

    Oh, come on, people. He threw you a bone for fuck's sake. Linux 7.2? Sheesh!

  18. Re:60 second timer by razberry636 · · Score: 4, Funny
    Of course, if you're getting hammered this isn't going to help much.

    A nasty work is quickly spreading across the internet forcing about 90 percent of the connected computers to become inoperable. Thousands of phones are ringing at IT desks all over the world. On the other ends of those phones are screaming, panicky users crying because their computers won't work. Management is calling because now you're the bottleneck causing inefficiency in the team, and you might need to start looking for a new job if this isn't taken care of. And then you trip over a network cable.

    I think getting hammered is the best thing to do right now.

  19. Re:Echoes by fishbert42 · · Score: 5, Funny

    'You'd think every hotmail account would get a message saying "Plug that hole" from whoever it is that runs hotmail.'

    Actually, in my hotmail spam repository account I already do get tons of messages saying things like that. But, I don't think they're talking about computer security. =)

  20. Re:Sad really by harrkev · · Score: 2, Funny
    It's really that simple. Check daily for patches on your software, patch it, reboot, get back to work.

    Yup. Until Micro$oft issues a patch which breaks something else. Then some part of your server dies.

    Wait... This is Micro$oft we are talking about. They would NEVER release a patch with bad side-effects. The test all of their stuff extensively before releasing.
    --
    "-1 Troll" is the apparently the same as "-1 I disagree with you."
  21. Re:shutdown /a by MmmmJoel · · Score: 3, Funny
    "Thought it was just Windows XP being retarded"

    It is Windows XP being retarded. Don't second-guess yourself!

  22. Re:shutdown /a by ChiefArcher · · Score: 5, Funny

    Supposively, if they don't fix it by this weekend, all the infected boxes are going to attack microsoft's website all at once.

    So in my opinion.... Don't patch it :)

    ChiefArcher

  23. Re:In addition... by Anonymous Coward · · Score: 1, Funny
    I think that it would be sensible to have it enabled by default
    Ah, but that would be an illegal evil anti-competitive measure to ensure Microsoft world dominance over third-party firewall-making companies, and would be rightly flamed to oblivion on Slashdot. Leaving it off by default is, of course, a stupid evil security hole in Windows that is rightly flamed to oblivion on Slashdot.
  24. Re:Precisely by Anonymous Coward · · Score: 1, Funny

    The half dozen smart windows users aren't the problem, it's the rest of 'em.

  25. Re:There are several reasons... by Surreal_Streaker · · Score: 4, Funny
    How many of those Linux holes where in the core operating system (IE, kernel + GNU tools)?

    IE is not a core part of the core Linux operating system no matter what you've heard.

  26. Re:shutdown /a by Zak3056 · · Score: 3, Funny

    You actually believe that reading /. makes you smart?

    Yeah, what do you think this is, a Holiday Inn Express or something?

    --
    What part of "shall not be infringed" is so hard to understand?
  27. Re:Honest question by killmenow · · Score: 2, Funny

    My Grandma is definitely a keeper. She wouldn't touch a computer. She just found out there's this thing called "cable" for your TV...although she's not very fond of it.

  28. Ha! by Bedevere · · Score: 2, Funny

    For once using Windows ME pays off!

  29. All you do is complain by ShieldW0lf · · Score: 2, Funny

    Do you like BSODs?!? Don't you wish you could leave the server room for 5 minutes?!? Aren't you sick of data corruption??!

    I wrote Win32 Blaster, and since installing it on our server, we haven't had any of these problems that plague Windows boxes around the world.

    Being the nice guy that I am, I wrote some "Automatic Update" code, and fixed all your machines. And you call it a virus and complain about it.

    I'm not helping you anymore... fix your own damned problems.

    --
    -1 Uncomfortable Truth
  30. Update by Etyenne · · Score: 2, Funny

    Download this security update.

    Where's the Linux version ?

    --
    :wq
  31. Why are Brit Geeks all named... by Anonymous Coward · · Score: 1, Funny

    ... Ian?

    I swear, even here in Dallas TX, I've met four different British techno geeks recently and all four of them are all named Ian.

    I guess I should be thankful, they aren't all named Bruce instead.

    1. Re:Why are Brit Geeks all named... by kiwimate · · Score: 2, Funny

      Well, I'm in Philadelphia and I'm named Ian, but I'm from New Zealand.

      However, my parents are originally from England, which means I have a distinct British tinge to my accent. Oh, and most of my family still lives over there...close enough?

      (By the way, of course they're not all named Bruce -- that'll be the Australians.)

    2. Re:Why are Brit Geeks all named... by DataCannibal · · Score: 1, Funny

      They're not all named Ian (or Iain) the rest of them are all named Steve,

      --
      No but, yeah but, no but...
  32. Re:shutdown /a by RoLi · · Score: 5, Funny
    I mean that's how you're supposed to setup any operating system. No net connection until you've got all the necessary patches installed and firewalls set up.

    Exactly! It's pretty easy, actually:

    • Unplug Internet connection
    • Download patches from the Internet
    • Set up firewall
    • Plug in Internet connection

    If that doesn't work, just send an email to support@microsoft.com

  33. Re:shutdown /a by Anonymous Coward · · Score: 4, Funny

    your_girlfriend.exe

  34. Re:Sad really by RoLi · · Score: 4, Funny
    Check daily for patches on your software, patch it, reboot, get back to work.

    Too bad that this "check daily, patch, reboot" procedures never get mentioned in any MS-paid TCO-analysis.

  35. Re:Laptops by Havokmon · · Score: 2, Funny
    Think about this scenario: a perfectly competent administrator has a properly configured firewall which blocks the problem. The "road warrior" brings his laptop from from 3 weeks on the road and had used a bunch of hotel access points where he got the worm. He connects it to his docking station in the office effectively bringing the problem behind the firewall.

    Yeppers. I was waiting for a 'Road Warrior' to return (I consult on Friday afternoons only) so I could update his laptop. Upon seeing the news this morning, I sent him an email with instructions (crossing fingers!) on how to use Windows Update.

    He called me about his system strangely rebooting before he even read my email. :(

    --
    "I can't give you a brain, so I'll give you a diploma" - The Great Oz (blatently stolen sig)
  36. All computers are Taco Bell. by Anonymous Coward · · Score: 1, Funny

    Don't get overexcited. To most normal people, computer==windows and vice versa

    That is correct. Just like in that movie Demolition Man where , in the future the only restauraunts that exist are all Taco Bells, all computers are already now Windows.

  37. Re:Honest question by wfrp01 · · Score: 4, Funny

    What's a port?
    Do I have any?
    How can I check?


    A place where ships are safe from storms. See also 'port of entry'.
    You have an output port on your behind.
    Do yoga.

    --

    --Lawrence Lessig for Congress!
  38. Re:it hit me this morning! by Theatetus · · Score: 2, Funny
    i have never seen a worm spread so fast!

    Somebody wasn't administering Windows-based networks back in 1999-2000. Ah, the heady days of damaging Office macros...

    Microsoft Developer 1: Hey, Fred, let's include in our Office suite a macro development environment that can access the entire OS's API!
    Microsoft Developer 2: Good idea, Jim, I'll get working on it. This should ensure that even the ditzy office manager can easily create executables that will take down the entire network!

    --
    All's true that is mistrusted
  39. Famous last words by dtfinch · · Score: 3, Funny

    From the Microsoft security bulletin on the vulnerability:

    "This vulnerability only permits a denial of service attack and does not provide an attacker with the ability to modify or retrieve data on the remote machine."

  40. Re:Honest question by jafuser · · Score: 2, Funny

    That said, none of my machines have been infucted

    Was that a deliberate misspelling? =)

    --
    Please consider making an automatic monthly recurring donation to the EFF
  41. Re:shutdown /a by Geek+of+Tech · · Score: 5, Funny
    That almost makes me want to infect my box. Oh well.

    --
    Stop the Slashdot effect! Don't read the articles!
  42. Re:shutdown /a by Anonymous Coward · · Score: 2, Funny
    Supposively, you passed your University's language competency test.

    I may be wrong.

  43. Re:Sad really by TCM · · Score: 2, Funny

    Where's the "test, test, test" part?

    --
    Of course it runs NetBSD. BTC: 1NT7QvbetmANwaMzhpVL6
  44. Re:Automatic updates by PeteyG · · Score: 2, Funny

    It pops up, partially covering part of the system tray and a bit of the desktop.

    It has a fucking annoying 'pooaaAAHP!' sound.

    It takes up an icon in the system tray. I hate icons in the system tray. Makes me look like a loser who has too many 'Banzai Buddy' programs installed.

    And after getting hit by this worm, I am now going to turn it back on on my home XP install. : )

    --
    no thanks
  45. Re:shutdown /a by TwistedGreen · · Score: 2, Funny

    What do you mean? They obviously did it to protect their customers from getting the virus!

    Yeah, that's the ticket...

  46. Re:Honest answer by allism · · Score: 3, Funny

    Monitoring slashdot...I need to remember that phrase if I ever get reprimanded for excessive internet activity...

    seriously, though, I, for one, thank you on the behalf of all us little peon users for testing before patching. I swear, the next time the sysadmin comes around an installs something on my computer that means I have to spend hours fixing my computer before I can do any more of my real work, I'm gonna kick him in the shins...

  47. Re:shutdown /a by rworne · · Score: 4, Funny
    (Score:2, Insightful) for a post recommending you download patches with your network cable unplugged. Wow, Slashdot is a haven for those with technical know-how, isn't it.

    Perhaps he was meaning to suggest using a wireless access point. That way there is no physical medium for the virus to travel over.
    --
    I tried every decent and legal way I could think of to resolve the issue w/the business before I rented the chicken suit
  48. Re:shutdown /a by Samari711 · · Score: 2, Funny

    i'd like to see you download the patch in under 60 seconds, and without a tinfoil beanie

    --

    I never said I was smart, I just said I was smarter than you

  49. Re:shutdown /a by grazzy · · Score: 1, Funny

    Unplug Internet connection
    Download patches from the Internet
    Set up firewall
    Plug in Internet connection

    Is it only my seeing a problem here? Exactly HOW do you download anything when you're unplugged?

  50. Re:shutdown /a by Anonymous Coward · · Score: 1, Funny

    How do I uninstall the security patch?

  51. Re:shutdown /a by Anonymous Coward · · Score: 3, Funny

    Unless the virus becomes airborne, in which case I'm covering my box with surgical masks and insulating blankets.

    Looks like my computer is suffering from a high fever now. I'll give it plenty of fluids and some bedrest.

  52. Re:Gimme A Chance!! by dirtydiaper · · Score: 4, Funny

    Don't worry I know your problem.. You put the wrong boot disk in.. The one you want is the CD that says LINUX not Microsoft Windows XP. If that doesnt work.. Open up you case and find the worm.. They are a brownish colour some are a couple inches long.. good luck!

  53. Re:Gimme A Chance!! by devphaeton · · Score: 2, Funny

    Don't worry I know your problem.. You put the wrong boot disk in.. The one you want is the CD that says LINUX not Microsoft Windows XP. If that doesnt work.. Open up you case and find the worm.. They are a brownish colour some are a couple inches long.. good luck!

    Hell no. All over /. all you hear is LINUX LINUX LINUX. All over CNET and TechTV all you hear is LINUX LINUX LINUX. Screw you guys and your Monopoly. I'm switching to Windows, The Alternative OS.

    --


    do() || do_not(); // try();
  54. Re:shutdown /a by Nucleon500 · · Score: 5, Funny

    Does the worm work with Wine?

  55. Luckily, it's an easy one to stop: by mmu_man · · Score: 2, Funny

    http://www.linuxiso.com/
    http://www.bebits.com/ap p/2680
    http://www.qnx.com/ :-)

  56. Why stop it? by Nasheer · · Score: 2, Funny
    From F-Secure Virus Information:
    Starting from 16 of August machines infected with Lovsan will send massive amount of packets to windowsupdate.com. 40 byte packets are sent in 20 millisecond intervals to port 80. This might cause a Distributed Denial-of-Service attack on that website.
    Let it spread freely! On August 16 I'll be trying to run it under Wine to see if I can be of some help.
    --
    - Please, ignore everything written above.
  57. Re:shutdown /a by sharkey · · Score: 2, Funny
    In some cases even THAT doesn't mean you'll see smart comments

    Right. You still see the "editor's" comments in the article itself.

    --

    --
    "Outlook not so good." That magic 8-ball knows everything! I'll ask about Exchange Server next.
  58. Re:Coincidence by Politburo · · Score: 2, Funny

    Anyone who says that "Linux isn't ready for your Grandma" or whatever, should be forced to do community service for a week fixing this crap.

    Fine with me, so long as you're ready to help my grandparents (and parents, and uncles, and..) install and setup Linux!

    If you're one of the people that uses Linux as an excuse to not help people with Windows, guess what, you *don't* want normal people moving to Linux! You will suddenly be the tech support go-to guy again. Except this time you'll have to explain how to setup IPTables. Good luck!

    This bug doesn't change the fact that Linux isn't ready for our grandparents.

  59. Re:shutdown /a by sharkey · · Score: 2, Funny
    Does anyone know of any common Windows software that turns off XP's firewall?

    Give Win32 Blaster a try. It shuts down the firewall, and more. Or so I've been led to believe.

    --

    --
    "Outlook not so good." That magic 8-ball knows everything! I'll ask about Exchange Server next.
  60. Strange Brew by Fastball · · Score: 2, Funny

    Bob McKenzie: Fleshy headed mutant, are you friendly?
    Doug McKenzie (As the fleshy headed mutant): No way, eh! Ra-radiation has made me an enemy of civilization!

  61. Re:shutdown /a by inKubus · · Score: 5, Funny

    Sorry to whore this out here, but has anyone actually looked at the patch? I mean, this affects a rather important part of the Windows operating system. RPC is used for interprocess communication, named pipes, etc. Couldn't the CIA or something put a bug in it that will forward everything you cut and paste, type, send, etc. to some other entity? And what better way to get the masses to install it than a little worm to exploit a hole they purposely left open?

    Furthermore, Microsoft paid out $520M only yesterday due to patent infringement with a component in MSIE.

    I mean, I'm all patched up, so I know I'm safe but.. oh shit.. the shutdown timer just popped up! Microsoft must be reading what I'm typing. If only I can do this thing quick enough. OH FUCK I have to wait 20 seconds from the time I hit the reply button til when I press submit and it's getting down near 1 nowwwww

    --
    Cool! Amazing Toys.
  62. Understanding Win2K Security Rating (mildly OT) by Embedded+Geek · · Score: 3, Funny
    Jonathan Shapiro of the Johns Hopkins University Information Security Institute recently posted a commentary on the fact that Windows 2000 (with service pack 3) has been assigned a Common Criteria certification Evaluation Assurance Level (EAL) level of 4. In response to the question "What does this mean?", he replies:

    Security experts have been saying for years that the security of the Windows family of products is hopelessly inadequate. Now there is a rigorous government certification confirming this.

    (Originally taken from rec.humor.funny).

    --

    "Prepare for the worst - hope for the best."

  63. Re:shutdown /a by 1davo · · Score: 3, Funny
    In a knee-jerk reaction, I quickly downloaded the patch from Redmond and fired it up...

    Once I saw the messages saying "Pardon me while I inspect your system...

    Then some dialog box popped up with some message about third party blah blah blah.

    I came to my senses. Wait just a darn minute. I have not seen the effects of this worm/virus.

    So I killed the process. Bring on the RPC crap - it has to be alot better than Bill drilling any deeper into my vanilla laptop used only for browsing the web.

    Whew - dodged another one...

    Windows & security - the double bind theory of computing.

  64. Re:Does it work with wine? by daemon1010011010 · · Score: 2, Funny

    Yes, it does work quite well with wine, as confirmed by tcpdump. I will be sure to have it running this weekend just in case the rumors are true. I mean, sure I could just reverser engineer it, but that's just not as fun as running it an entire weekend and watching all the ip's of recently infected users go by in my tcpdump output. BTW, Anyone in the 85.221.22.* ip block running an unpatched NT derivative, sorry, but I had to test it.