Sasser ganna be the next sobig\blaster?

Pyro Pilots Lounge. For all topics *not* covered in other DBB forums.

Moderators: fliptw, roid

Post Reply
User avatar
Warlock
DBB 3D Artist
DBB 3D Artist
Posts: 3370
Joined: Wed May 12, 1999 2:01 am
Location: Midland, Tx, U.S.
Contact:

Sasser ganna be the next sobig\blaster?

Post by Warlock »

aney one got hit by this sucker yet?
it got me befor it was even a day old

http://securityresponse.symantec.com/av ... .worm.html

bothersome little worm but to easy to kill off
User avatar
Testiculese
DBB Material Defender
DBB Material Defender
Posts: 4689
Joined: Sun Nov 11, 2001 3:01 am

Post by Testiculese »

5-10 people on this floor got it..took all of 10 minutes to remove.

Anyone with a router won't even notice. For some reason, those ports weren't closed at the Aramark building. I'm guessing they are now!
User avatar
STRESSTEST
DBB DemiGod
DBB DemiGod
Posts: 6574
Joined: Sun Nov 21, 1999 3:01 am

Post by STRESSTEST »

spent this morning at a clients house taking care of 4 machines.....

No router (Buying two now)
User avatar
Tetrad
DBB Alumni
DBB Alumni
Posts: 7585
Joined: Thu Nov 05, 1998 12:01 pm
Location: Dallas, TX

Post by Tetrad »

Yea, if you have a firewall of some sort that doesn't let in the RPC ports you'll be fine.

But if you are infected, it's a pain to remove. Very smart worm from all accounts I've heard.

You can check to see if you have it here: http://www.microsoft.com/security/incident/sasser.asp
User avatar
Warlock
DBB 3D Artist
DBB 3D Artist
Posts: 3370
Joined: Wed May 12, 1999 2:01 am
Location: Midland, Tx, U.S.
Contact:

Post by Warlock »

i had my xp fire wall up but had to kill it so my bro can send files and i forgot to turn it back on :| oh well no damage

but that worm done some thang els thats not on there page.
when it took over i couldent go to norton..com and all the other AV pages well i saw it goes in and edits the host file and blocks u from the pages
User avatar
Topher
DBB Alumni
DBB Alumni
Posts: 3545
Joined: Thu Nov 05, 1998 12:01 pm
Location: New York
Contact:

Post by Topher »

....automatic update....
User avatar
Grendel
3d Pro Master
3d Pro Master
Posts: 4390
Joined: Mon Oct 28, 2002 3:01 am
Location: Corvallis OR, USA

Post by Grendel »

MAYOR company network got blasted by Sasser.C.. My coworker catched it from them immediately, fortunately I'd taken care of our LAN before he returned. Killed our Linksys BEFSR41 V.2 (nothing a reset couln't fix tho).
User avatar
Mobius
DBB_Master
DBB_Master
Posts: 7940
Joined: Sun Jun 03, 2001 2:01 am
Location: Christchurch, New Zealand
Contact:

Post by Mobius »

past tense of "catch" = "caught"

I will catch you.
You will catch cold.
I'm catching up to you.
I [have] caught Herpes from Sasser.
Tomorrow, I will have caught the train to Pookagee = same as ---> Tomorrow I will catch the train...

English is a stupid language, I know.
User avatar
Lothar
DBB Ghost Admin
DBB Ghost Admin
Posts: 12133
Joined: Thu Nov 05, 1998 12:01 pm
Location: I'm so glad to be home
Contact:

Post by Lothar »

English is a stupid language, and Pookagee is a stupid place name ;)
User avatar
Nitrofox125
DBB Admiral
DBB Admiral
Posts: 1848
Joined: Sun Jul 07, 2002 2:01 am
Location: Colorado Springs, CO, USA
Contact:

Post by Nitrofox125 »

And Mobius isn't even English! ;)

My friend got hit with this. Does autoupdate and a quick virus scan get rid of this?
User avatar
Avder
DBB Material Defender
DBB Material Defender
Posts: 4926
Joined: Sat Oct 09, 1999 2:01 am
Location: Moorhead, MN

Post by Avder »

Mobius is STUPID! :P
User avatar
Warlock
DBB 3D Artist
DBB 3D Artist
Posts: 3370
Joined: Wed May 12, 1999 2:01 am
Location: Midland, Tx, U.S.
Contact:

Post by Warlock »

Topher wrote:....automatic update....
i know
i kept putting it off and putting it off so its my fault i got infected
Vertigo
DBB Fleet Admiral
DBB Fleet Admiral
Posts: 2641
Joined: Mon Jun 04, 2001 2:01 am
Location: Belgium

Post by Vertigo »

ugh.... this one's making life utter misery at the HellDesk ...


Well, for the ones getting hit by this, i guess you had it coming, and i hope in the future you might consider updating windos a bit more, and/or running a firewall ;)
Jagger
DBB Admiral
DBB Admiral
Posts: 1615
Joined: Wed Nov 17, 1999 3:01 am
Location: Santa Rosa, CA

Post by Jagger »

It's been kinda quiet here. Haven't heard of anyone getting in my neck of the woods.

That was pretty funny, Mobius.
User avatar
Ferno
DBB Commie Anarchist Thug
DBB Commie Anarchist Thug
Posts: 15163
Joined: Fri Nov 20, 1998 3:01 am

Post by Ferno »

Never got hit by it.

i love my firewall. :D
User avatar
Tyranny
DBB Defender
DBB Defender
Posts: 3399
Joined: Sun Nov 10, 2002 3:01 am
Location: Phoenix, Arizona

Post by Tyranny »

Looks good on my end. Two firewalls and A/V software. Also have A/V on my ISP's end before stuff gets through :)
MD-2389
Defender of the Night
Defender of the Night
Posts: 13477
Joined: Thu Nov 05, 1998 12:01 pm
Location: Olathe, KS
Contact:

Post by MD-2389 »

You know, someone needs to write a worm that does nothing but shut off your internet access, bombard you with messenger prompts every 5 seconds saying "You are an idiot because you can't even bother to get off your lazy ass and update your damn OS and Anti-Virus software!" and dump the infamous "Your are an Idiot!" flash in their startup....

Maybe then people will get a damn clue.

The patch has been out for two weeks people. If you get bit, its your own damn fault.

Patch is available here for those too lazy to run Windows Update.

Removal tool (McAffe) Removal tool (symantec) for those that got bit.
User avatar
BUBBALOU
DBB Benefactor
DBB Benefactor
Posts: 4198
Joined: Tue Aug 24, 1999 2:01 am
Location: Dallas Texas USA
Contact:

Post by BUBBALOU »

Anyone who frequents this board and gets a virus because they were too lazy to check for updates on O/S and AV needs to box up their computer and send it back to whence it came. Especially if you are running a Network of computers.... enable auto update if your lazy.

Norton used to only update their Virus Def's once a week, now it is almost on a daily basis..... come on folks
User avatar
roid
DBB Master
DBB Master
Posts: 9996
Joined: Sun Dec 09, 2001 3:01 am
Location: Brisbane, Australia
Contact:

Post by roid »

i never got it. i havn't updated windows for at least a few months, but reading this thread made me do it. ^_^

i also used the scaners and i didn't have it.
but i'm talking a customer through howto get rid of it on the phone right now.
User avatar
Tricord
DBB Alumni
DBB Alumni
Posts: 3394
Joined: Thu Nov 05, 1998 12:01 pm

Post by Tricord »

Heh. I never update, I'm still running the first release of Win2000 :)

*Pats router and norton AV.
User avatar
Krom
DBB Database Master
DBB Database Master
Posts: 16138
Joined: Sun Nov 29, 1998 3:01 am
Location: Camping the energy center. BTW, did you know you can have up to 100 characters in this location box?
Contact:

Post by Krom »

So far the only computers I have seen that have had viruses on them, also had norton auto-protect on them and it was kept up to date, cant say the same for windowsupdate tho.
User avatar
Topher
DBB Alumni
DBB Alumni
Posts: 3545
Joined: Thu Nov 05, 1998 12:01 pm
Location: New York
Contact:

Post by Topher »

Tricord wrote:Heh. I never update, I'm still running the first release of Win2000 :)

*Pats router and norton AV.
*notes Tricord's IP...

Seriously, how can you justify not applying security patches? I mean really, it's the retarded people that don't patch that let viruses like this spread. :(
User avatar
Tricord
DBB Alumni
DBB Alumni
Posts: 3394
Joined: Thu Nov 05, 1998 12:01 pm

Post by Tricord »

Well, for one thing, I am not a retarded user and I know what exposes me and what doesn't. I don't browse dubious sites and I'm sitting behind a Linux router with NAT. My ISP blocks all ports under 1024, scans emails for viruses on the mailserver, and if you can still root my router you won't get very far. Only 13k of RAM left ;)

I'm just applying the "don't fix what isn't broken" rule of thumb. In this way I'm still using ICQ2000a, MSN 5.0, IE 5.0 and more of that software that got upgraded at least four years ago...
Vertigo
DBB Fleet Admiral
DBB Fleet Admiral
Posts: 2641
Joined: Mon Jun 04, 2001 2:01 am
Location: Belgium

Post by Vertigo »

Tricord wrote:Well, for one thing, I am not a retarded user and I know what exposes me and what doesn't. I don't browse dubious sites and I'm sitting behind a Linux router with NAT. My ISP blocks all ports under 1024, scans emails for viruses on the mailserver, and if you can still root my router you won't get very far. Only 13k of RAM left ;)

I'm just applying the "don't fix what isn't broken" rule of thumb. In this way I'm still using ICQ2000a, MSN 5.0, IE 5.0 and more of that software that got upgraded at least four years ago...
Whatever... next time i see you at a lanparty your pc'll be owned by both msblast and sasser :P

(last OCC i saw an entire row of pc's getting shut down by blaster at the same time, heh)
User avatar
Tricord
DBB Alumni
DBB Alumni
Posts: 3394
Joined: Thu Nov 05, 1998 12:01 pm

Post by Tricord »

Vertigo wrote:Whatever... next time i see you at a lanparty your pc'll be owned by both msblast and sasser :P
That might be a problem ;)
User avatar
Topher
DBB Alumni
DBB Alumni
Posts: 3545
Joined: Thu Nov 05, 1998 12:01 pm
Location: New York
Contact:

Post by Topher »

Tricord wrote: I'm just applying the "don't fix what isn't broken" rule of thumb. In this way I'm still using ICQ2000a, MSN 5.0, IE 5.0 and more of that software that got upgraded at least four years ago...
But...it is broken, that's why there's a fix for it! :-P
That's like saying "I won't get the vaccine until I know I have the disease" or "I won't buckle up unless I see a car coming".

Or am I just being ornery? (Quite possible)
Birdseye
DBB DemiGod
DBB DemiGod
Posts: 3655
Joined: Thu Nov 05, 1998 12:01 pm
Location: Oakland, CA

Post by Birdseye »

"Anyone who frequents this board and gets a virus because they were too lazy to check for updates on O/S and AV needs to box up their computer and send it back to whence it came. Especially if you are running a Network of computers.... enable auto update if your lazy. "

COUNT ME IN!!!!!
I got it. I had JUST reformatted and installed XP fresh. There must have been a matter of 1 hour where I hadn't installed windows XP updates and virus definitions.

For some reason the Dlink wireless router i have isn't doing NAT. Also, I can't contact it at all using 192.168.1.
User avatar
Warlock
DBB 3D Artist
DBB 3D Artist
Posts: 3370
Joined: Wed May 12, 1999 2:01 am
Location: Midland, Tx, U.S.
Contact:

Post by Warlock »

yeah i connected to the net in the morning and went to the store and came back and computer was acting all funney

thank god for system restore went back 2 weeks and sick AVG on it.

this worm was to easy to kill :( i like the hard ones like Monkey where you half to really work to kill it
User avatar
Top Wop
DBB Master
DBB Master
Posts: 5104
Joined: Wed Mar 01, 2000 3:01 am
Location: Far from you.
Contact:

Post by Top Wop »

Nothing here.

I taught everyone here in the office how to use windowsupdate. :D
User avatar
fliptw
DBB DemiGod
DBB DemiGod
Posts: 6459
Joined: Sat Oct 24, 1998 2:01 am
Location: Calgary Alberta Canada

Post by fliptw »

nothing says loving like a good firewall.

should the first thing people install on a new copy of NT/2K/XP.
MD-2389
Defender of the Night
Defender of the Night
Posts: 13477
Joined: Thu Nov 05, 1998 12:01 pm
Location: Olathe, KS
Contact:

Post by MD-2389 »

Warlock wrote:yeah i connected to the net in the morning and went to the store and came back and computer was acting all funney

thank god for system restore went back 2 weeks and sick AVG on it.

this worm was to easy to kill :( i like the hard ones like Monkey where you half to really work to kill it
No offense, but if you get infected with a virus or worm, using system restore is the worst thing you can do since they tend to go after restore points first thing. All you're doing by running SR is making things worse.
User avatar
Warlock
DBB 3D Artist
DBB 3D Artist
Posts: 3370
Joined: Wed May 12, 1999 2:01 am
Location: Midland, Tx, U.S.
Contact:

Post by Warlock »

well at that point i didnt care but it did good though it got my net back up and running so i can get the new virus def

but if it didnt work i would have just blown my C drive cause nothing is on there but the OS
Post Reply