Patch your machines - serious MS vulnerability

EyeMWing

Banned
Jun 13, 2003
15,670
1
0
Oh joy of joyous joys. My machine is on at home and connected to the internet. $10 says that I'm infected by the time I get home.
 

spidey07

No Lifer
Aug 4, 2000
65,469
5
76
Well, there are no known bugs for it now but I'd say give it about a week and there will be another blaster/nachi type worm.
 

XZeroII

Lifer
Jun 30, 2001
12,572
0
0
Major linux vulnerability! Everyone running linux, download this patch, untar it, patch your machine, recompile your kernel... oh wait. No one uses Linux at home! :eek:
 

Descartes

Lifer
Oct 10, 1999
13,968
2
0
Originally posted by: EyeMWing
Oh joy of joyous joys. My machine is on at home and connected to the internet. $10 says that I'm infected by the time I get home.

If you're in such a sad state as to leave the associated ports open, imo, you deserve it :)
 

Rob9874

Diamond Member
Nov 7, 1999
3,314
1
81
Originally posted by: Descartes
Originally posted by: EyeMWing
Oh joy of joyous joys. My machine is on at home and connected to the internet. $10 says that I'm infected by the time I get home.

If you're in such a sad state as to leave the associated ports open, imo, you deserve it :)

What does that even mean? What are associated ports, and how do you close them? Do you guys really go to that much trouble with your security? I just install Zone Alarm, and I'm done.
 

Descartes

Lifer
Oct 10, 1999
13,968
2
0
Originally posted by: Rob9874
Originally posted by: Descartes
Originally posted by: EyeMWing
Oh joy of joyous joys. My machine is on at home and connected to the internet. $10 says that I'm infected by the time I get home.

If you're in such a sad state as to leave the associated ports open, imo, you deserve it :)

What does that even mean? What are associated ports, and how do you close them? Do you guys really go to that much trouble with your security? I just install Zone Alarm, and I'm done.

If you installed Zone Alarm then you are, for the most part, done; it takes care of it for you.

I'm just talking about EyeMWing is seemingly worried about infection when the services associated with these ports have been traditionally exploited.
 

spidey07

No Lifer
Aug 4, 2000
65,469
5
76
From cert.org:

You may wish to block access from outside your network perimeter, specifically by blocking access to TCP & UDP ports 138, 139, and 445. This will limit your exposure to attacks. However, blocking at the network perimeter would still allow attackers within the perimeter of your network to exploit the vulnerability. It is important to understand your network's configuration and service requirements before deciding what changes are appropriate.

For a home user with a firewall or router it isn't that big of a deal. But for a business network it is.
 

alkemyst

No Lifer
Feb 13, 2001
83,769
19
81
if you show update 828035 in your add / remove proggie list you have the patch already.
 

Savij

Diamond Member
Nov 12, 2001
4,233
0
71
1. Turn on WinXP firewall or zone alarm or whatever and you're OK on this one.
2. This is an MS update, not a worm.
3. If you have WinXP andf had the previous patches already installed then you don't need to worrry about this one

"Note: The Windows XP security updates that released on October 15th as part of Security Bulletin MS03-043 (828035) include the updated file that helps protect from this vulnerability. If you have applied the Windows XP security updates for MS03-043 (828035) you do not have to reapply this update."
 

skace

Lifer
Jan 23, 2001
14,488
7
81
828035 only works in the XP scenario. This is still a critical issue for 2K machines, as the article states.
 

Savij

Diamond Member
Nov 12, 2001
4,233
0
71
Originally posted by: FoBoT
Savij, that must be why there wasn't a critical update alert email, perhaps

Not really sure about the emails. I was just trying to say it isn't something to panic about...yet.
 

Megatomic

Lifer
Nov 9, 2000
20,127
6
81
It's gotten to the point that I run Windows Update at least every other day. I'm not kidding. I got patched up last night...