READ ME!: Microsoft Security Hole.
Aug 1, 2003 at 12:06 AM Thread Starter Post #1 of 35

vwap

Padawan.
Joined
Dec 4, 2002
Posts
2,919
Likes
10
Hey all.. Another hellish day in IT support.

For all you home users currently unaware of the new security hole (that, as most IT support personnel already know,) it's currently being heavily exploited by bored teenagers around the world.

Read this.. Then go to Windows Update and get patched. Do this now. This is only applicable to NT-based Windows systems (NT 4.0, 2000, XP, Server 2003). Who knows, you may have already been infected.. Some variants of the exploit have a ftp server listening on port 48522, so if you're saavy enough to do a netstat -a, and see port 48522 in use (among others, probably), you've been hit. I can send you step by step instructions to clean this, if you need them.

Again.. patch your computers [size=small]NOW[/size]. I've just spent an entire freaking week troubleshooting the aftermath of this ****. Don't get yourself needlessly screwed if you don't have to.
 
Aug 1, 2003 at 12:20 AM Post #3 of 35
Quote:

Originally posted by asdfghjkl
I update Windows every couple of days and I'm not sure if I have already installed it. What would the patch look like in the installation history?


The one in my Windows XP history is: "Security Update for Windows XP (823980)"

823980 is the name of the Knowledge Base Article.
 
Aug 1, 2003 at 12:45 AM Post #5 of 35
Andy,

This update doesn't show up for Win2K. Is this only for Win XP? If not, please give some help.
 
Aug 1, 2003 at 12:46 AM Post #6 of 35
Quote:

Originally posted by ServinginEcuador
Andy,

This update doesn't show up for Win2K. Is this only for Win XP? If not, please give some help.


It should be one of the "Critical Updates" in Windows Update. I'm not currently looking at a Windows 2000 computer, so I can't say what the line sayd.. However, the reference number should be the same. (823980).
 
Aug 1, 2003 at 12:51 AM Post #7 of 35
Andy,

It wasn't there, but I followed the first link you gave and am downloading the patch now. Weird, but it doesn't showup under the Windows update page. It listed two critical update patches that were dated February and March.
 
Aug 1, 2003 at 12:54 AM Post #8 of 35
*patches machine*

thanks for the heads-up.

cool.gif
 
Aug 1, 2003 at 1:01 AM Post #9 of 35
Andy,

You also need to have at least Service Pack 2 in order to install this update, so I can't install it. My dial-up takes over 5 minutes per MB to download, so just the Service Pack download would take more than 3 hours to download, and that means almost $7 worth of phone usage! Man, I wish that Microsoft made their updates available online to download using any computer as I could have my in-laws use their cable modem to download it and send it to me. Bummer!
 
Aug 1, 2003 at 1:09 AM Post #10 of 35
Quote:

Originally posted by ServinginEcuador
Andy,

You also need to have at least Service Pack 2 in order to install this update, so I can't install it. My dial-up takes over 5 minutes per MB to download, so just the Service Pack download would take more than 3 hours to download, and that means almost $7 worth of phone usage! Man, I wish that Microsoft made their updates available online to download using any computer as I could have my in-laws use their cable modem to download it and send it to me. Bummer!


THen again, with dialup, you should be, at the very least, a lot less susceptible to this than others
smily_headphones1.gif


But you're still vulnerable.. I, too, hate how MS doesn't have a download now and install later option.. especially when I want to re-install a patch..
tongue.gif
 
Aug 1, 2003 at 1:11 AM Post #11 of 35
Aug 1, 2003 at 1:13 AM Post #12 of 35
Quote:

Originally posted by donovansmith
Try this SIE: http://download.microsoft.com/downlo.../W2KSP4_EN.EXE

If that doesn't work, go to http://www.microsoft.com/Windows2000...4/download.asp and download the network installation. That includes every file you might need for the service pack. It's a 125MB file so it will take a little time even on a cable modem, but you can download it from any computer at least.


Doug,

If it's the 125MB one that you need, let me know. I'll d/l it and mail it to you.
 
Aug 1, 2003 at 1:14 AM Post #13 of 35
Quote:

so if you're saavy enough to do a netstat -a


for those pc non-harcore people, you->

Start->Run->type CMD-> MS-DOS emulator pops up, then type netstat -a...make sure there's a space in between n and -

kinda like...when you had to do stuff like that in games...heh, I remember dialing and answering for C&C...a looong time ago
biggrin.gif
 
Aug 1, 2003 at 1:24 AM Post #14 of 35
Quote:

Originally posted by vwap
Doug,

If it's the 125MB one that you need, let me know. I'll d/l it and mail it to you.


Yep, I would need and greatly appreciate this andy! I'll PM you the address and directions for sending it down here to me thru a friend of mine here.

Thanks.
cool.gif
 

Users who are viewing this thread

Back
Top