logo   login
right
Home Forums Downloads Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Forum Info
Forum Members: 18,642
Total Threads: 8,744
Posts: 95,512

Administrators:
DeeZire, Redemption

There are currently 20 users online.
Partner Links

Free Credit Repair

Learn the Ticket Broker Secrets
Advertisements


Generals & Zero Hour Editing Discuss any modding related issues to do with Generals and Zero Hour here.

Reply
 
LinkBack Thread Tools
Old 09-17-2003, 09:47 PM   #1 (permalink)
Senior Member
 
Join Date: Sep 2001
Posts: 1,094
Send a message via ICQ to smurfbizkit Send a message via AIM to smurfbizkit Send a message via MSN to smurfbizkit
Default Only a few days left until MSBlast 2

found this on another forum, figured I should post it...

Quote:
The source code of a working exploit for the RPCSS vulnerabilities discovered on September 12th was posted early this morning, meaning there are only a few days left before a worm using the code will be created and released. This was first reported on full-disclosure and there is now an article in The Reg about it. This exploit uses VU#254236 RPCSS Long Filename Overflow, which allows complete local system privileges to any attacker. There is also an attack tool out for VU#326746 RPC Denial of Service which can reportedly crash every vulnerable Windows machine on a subnet in under a minute.

So if you run Windows NT4/2000/XP/2003, make sure you follow the instructions to secure your system while there's still time:

http://www.cert.org/advisories/CA-2003-23.html#solution

You should also begin checking for emergency virus definition updates that will become available when the worm is released:

http://www.networkassociates.com/us/...es/default.asp
http://securityresponse.symantec.com.../download.html

Hopefully people learned from the first MSBlast worm an this one won't spread as fast, but that seems unlikely given the fact that people had four times as long to patch last time and they still didn't get around to it.
smurfbizkit is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 09-17-2003, 09:53 PM   #2 (permalink)
Senior Member
 
Join Date: May 2003
Location: South East USA
Posts: 1,247
Send a message via ICQ to Opals25 Send a message via AIM to Opals25 Send a message via MSN to Opals25 Send a message via Yahoo to Opals25
Default

Bah dumb windows. Theres been atleast one Crusial Flaw in it a WEEK. Jeez.

//head back to ms update//
Opals25 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 09-17-2003, 11:58 PM   #3 (permalink)
Senior Member
 
Join Date: Apr 2003
Location: USA
Posts: 144
Send a message via ICQ to gameboy_one
Default

just wondering can other operating systems it to? Like Linux?
gameboy_one is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 09-18-2003, 12:01 AM   #4 (permalink)
Senior Member
 
Join Date: Apr 2003
Location: USA
Posts: 144
Send a message via ICQ to gameboy_one
Default

oops I mean can other operating systems be infected
gameboy_one is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 09-18-2003, 02:41 AM   #5 (permalink)
Senior Member
 
Join Date: Jul 2003
Location: Revora Forums
Posts: 496
Send a message via MSN to Boomerang_Python
Default

what about Windows ME??? :scared:
Boomerang_Python is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 09-18-2003, 04:27 AM   #6 (permalink)
Senior Member
 
Join Date: Dec 2002
Posts: 1,031
Send a message via ICQ to Phoib Send a message via MSN to Phoib
Default

Quote:
Originally Posted by gameboy_one
oops I mean can other operating systems be infected
AFAIK, not

This versions attacks trough an exploit in filename length, and both Unix and Windows have other filename definitions (the former better then the last, I might add... )
Phoib is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 09-18-2003, 12:33 PM   #7 (permalink)
Senior Member
 
Join Date: Jan 2003
Location: uk
Posts: 186
Send a message via MSN to TylerD
Default

Quote:
Originally Posted by Boomerang_Python
what about Windows ME??? :scared:
Isnt that windows 2000? Im not sure though... Im using ME myself so if anyone knows for sure please say.
TylerD is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 09-18-2003, 02:43 PM   #8 (permalink)
Senior Member
 
Join Date: May 2003
Posts: 113
Default

ME is NOT win 2000. i dont think ME is affected (the 1st one didnt touch ME or the other win 9x OS's). are these worms exploiting something that is due to the getting rid of DOS, b/cs all the OS's it affects are windows without DOS. just wondering if that was why or if it was just a coincidence.
evilbutterfly is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 09-18-2003, 03:30 PM   #9 (permalink)
Senior Member
 
Join Date: Aug 2003
Location: Oh-HIGH-Ooh
Posts: 421
Send a message via AIM to premier89 Send a message via MSN to premier89
Default

Quote:
Originally Posted by evilbutterfly
are these worms exploiting something that is due to the getting rid of DOS, b/cs all the OS's it affects are windows without DOS. just wondering if that was why or if it was just a coincidence.
All Windows OS's have DOS, even XP (even though its renamed "command prompt" in Accessories). I know because I couldn't get RA to work on XP, so I installed it to DOS instead.
premier89 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 09-18-2003, 03:57 PM   #10 (permalink)
Senior Member
 
Join Date: Jul 2003
Location: Revora Forums
Posts: 496
Send a message via MSN to Boomerang_Python
Default

phew thats good news, now i am complete
Boomerang_Python is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
I'm back for a few days, and I've got some questions EvilViking Generals & Zero Hour Editing 8 07-01-2004 03:44 PM
I seem to be running into problems left and right Kelso Generals & Zero Hour Editing 0 06-20-2004 11:09 PM
Lower left border in the map editor stuck Pungent Map Authoring 0 11-23-2003 05:43 PM
Henford's Guide to removing the MSBlast Worm Henford_ Generals & Zero Hour Editing 13 08-14-2003 05:35 AM


All times are GMT -4. The time now is 03:43 AM.


Design By: Miner Skinz.com
Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.