New VIRUS warning

IBhacknU

Diamond Member
Oct 9, 1999
6,855
0
0
To those of you running servers (NT and 2000) please take note of this new virus dubbed Code Blue. As was pointed out to me, this could really screw up our efforts in SETI and other DC projects.

Thanks to a member of the cowbell community for bringing this to my attention ;)
 

Viztech

Platinum Member
Oct 9, 1999
2,807
0
0
It looks like the Code Red/ Q300972 patch covers it though...

What will they do next?

viz
 

aiex

Senior member
Jul 5, 2001
914
0
0
hmm anybody ever wish they knew how to run linux?? i know i run it if i could :)

ai3x
 

Shuxclams

Diamond Member
Oct 10, 1999
9,286
15
81


For those who are running W2K and IIS 5, please download and install all the patches;

http://download.microsoft.com/download/win2000platform/Patch/Q275657/NT5/EN-US/Q275657_W2K_SP2_x86_en.EXE

http://download.microsoft.com/download/win2000platform/Patch/Q277873/NT5/EN-US/Q277873_W2K_SP2_x86_en.EXE

http://download.microsoft.com/download/win2000platform/Patch/q280322/NT5/EN-US/Q280322_W2K_SP2_x86_en.EXE

http://download.microsoft.com/download/win2000platform/Patch/Q285985/NT5/EN-US/Q285985_W2K_SP3_x86_en.EXE

http://download.microsoft.com/download/win2000platform/Patch/q286818/NT5/EN-US/Q286818_W2K_SP3_x86_en.EXE

http://download.microsoft.com/download/win2000platform/Patch/q291845/NT5/EN-US/Q291845_W2K_SP2_x86_en.EXE

http://download.microsoft.com/download/win2000platform/Patch/q296576/NT5/EN-US/Q296576_W2K_SP2_x86_en.EXE

http://download.microsoft.com/download/win2000platform/Patch/q293826/NT5/EN-US/Q293826_W2K_SP3_x86_en.EXE

http://download.microsoft.com/download/win2000platform/Patch/q294831/NT5/EN-US/Q294831_W2K_SP3_x86_en.EXE

http://download.microsoft.com/download/iis50/Utility/1.0/NT5/EN-US/Iis5Recycle.exe

http://download.microsoft.com/download/iis50/Tool/1.0/NT45/EN-US/CodeRedCleanup.exe

http://download.microsoft.com/download/iis50/Utility/1.0/NT45/EN-US/IISLockD.exe

http://download.microsoft.com/download/win2000platform/Patch/q304135/NT5/EN-US/Q304135_W2K_SP3_x86_en.EXE

Yes it is so easy to run IIS in comparison to Linux/Apache yadda-yadda, not the point. Apache has had its own issues before as well, the point is - IF YOU ARE RUNNING A SERVICE ON A SERVER THEN SECURE IT. You are a administrator of a server, you are responsible for the email server, w3 server ftp server etc....





SHUX
 

Orange Kid

Elite Member
Oct 9, 1999
4,429
2,210
146
Shuxclams
Wouldn't most of that be installed as long as Service Pack 2 has been installed and all the latest updates from Microsoft are in place?
 

ElFenix

Elite Member
Super Moderator
Mar 20, 2000
102,389
8,547
126
windows update will get me this stuff, right?
 

ElFenix

Elite Member
Super Moderator
Mar 20, 2000
102,389
8,547
126
i think i'll install SP2... though SP1 made my computer less stable... we'll see how SP2 is... i can always uninstall it.
 

Shuxclams

Diamond Member
Oct 10, 1999
9,286
15
81
Yes, but its a reminder to the folks who are running IIS to update and patch. My logs are filled with "GET defualt.ida XXXXXXXXXXXXXXX" for weeks now and they are basically from misconfigured and poorly admin'd W3 servers. :disgust: Its annoying and it cuts down on my total bandwidth. Besides it does also affect DSL modems and some routers, it causes them to stop responding and I hate having to reboot those damn things constantly.








SHUX
 

Shuxclams

Diamond Member
Oct 10, 1999
9,286
15
81
n0c,
Thats all fine and dandy but the same can be said of Apache when running FTP services on the same machine. root access can be gotten through WWW unless you've install the update which alot of folks havent, Lame. It has more to do with bad Admin'ing then bad products, although IIS isnt a very good product IMHO and even though thats what I primarily use since all I get to do these days is M$ stuff. Would rather have everthing on Linux or Solaris but I don't have the time anymore.









SHUX
 

n0cmonkey

Elite Member
Jun 10, 2001
42,936
1
0


<< n0c,
Thats all fine and dandy but the same can be said of Apache when running FTP services on the same machine. root access can be gotten through WWW unless you've install the update which alot of folks havent, Lame. It has more to do with bad Admin'ing then bad products, although IIS isnt a very good product IMHO and even though thats what I primarily use since all I get to do these days is M$ stuff. Would rather have everthing on Linux or Solaris but I don't have the time anymore.

SHUX
>>



I agree totally. But it helps that I CANT use IIS, which is more along the lines of what I was getting at. Like I said, I flet bad saying it in HERE, but I had to say it. Plus I have customers that use IIS... So this WILL affect me no matter what I do...
 

aiex

Senior member
Jul 5, 2001
914
0
0
Ok i run IIS 5 and i have service pack 2 and i think all of the updates that are needed.

You refur to you log though and i am new to this where is the log of my activity and incomming requests and how can i check it??

Thanks :)

Ai3x
 

Shuxclams

Diamond Member
Oct 10, 1999
9,286
15
81
I always create a link on the desktop to C:\winnt\system32\LogFiles, under the W3SVC# there will be entries for each day. Be sure that your W3 service in Internet Services Manager is set to log everything including the kitchen sink. I found that connection time was a good thing to include in there as well. :)











SHUX