![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Entrepreneur
Join Date: Oct 2002
Location: USA
Posts: 31,429
|
New Sasser Worm Can Enter Your PC Just By Going On The Net
New Internt Worm Infecting Millions of Computers
STOCKHOLM (AFP) - A new Internet worm is spreading worldwide and has probably already infected millions of computers, a Finnish anti-virus expert told AFP. The Sasser worm can infect any computer that is switched on and connected to an Internet service provider, and unlike most other worms or viruses is not spread by email, said Mikko Hyppoenen, head of anti-virus research at the Finnish Internet security firm F-Secure. "This is one of few worms that spreads automatically. It is enough for your PC to be on," he told AFP in a telephone interview from Helsinki. The worm typically shuts down the computer then automatically re-boots it, repeating the procedure several times. Hyppoenen said computers behind a firewall should be spared from the attack. Sasser was first observed at 0001 GMT Saturday, and was infecting computers that had not installed the latest Microsoft software update in the past 18 days. Installing the patch fixes the problem, but many users may find that difficult because their computer keeps on shutting down, Hyppoenen said. He expected the number of computers affected by the worm to increase dramatically on Monday, when employees who had worked on laptop computers at home over the weekend returned to work and hooked them up to the office network. The antivirus company Symantec said on its website that Sasser spreads by scanning Internet computers for "vulnerable systems" -- computers that were permanently connected to their Internet service provider. Since laptops are not protected by company firewall systems if used on another server than the company's, they would run the risk of being infected, and in turn infect the company's network when used Monday in the office.
__________________
![]() from the leaders in the field at iWebmasters.com TO LOWER YOUR COSTS AND INCREASE YOUR PRODUCTION! *** *** *** *** *** *** *** *** *** *** *** *** ![]() ![]() ![]() ![]() ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
Fucked if I know
Join Date: Dec 2002
Location: Do you have a flag?
Posts: 23,368
|
Oh joy.
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
Confirmed User
Industry Role:
Join Date: Feb 2001
Location: Calabasa, CA & Chicago, IL
Posts: 1,410
|
i dont get why folks are so slow in getting the ms updates downloaded
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 | |
Entrepreneur
Join Date: Oct 2002
Location: USA
Posts: 31,429
|
Quote:
Its really scary how many techno putzes are on the Net. If everyone would just learn some basic computing necessities these viruses would never be able to spread all over as much as they do. ![]()
__________________
![]() from the leaders in the field at iWebmasters.com TO LOWER YOUR COSTS AND INCREASE YOUR PRODUCTION! *** *** *** *** *** *** *** *** *** *** *** *** ![]() ![]() ![]() ![]() ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 |
Confirmed User
Join Date: Aug 2002
Posts: 5,235
|
http://www.channelnewsasia.com/stori.../82779/1/.html
It was first spotted on Friday, and hahahahahahas 2000, hahahahahahas Server 2003 and hahahahahahas XP were the exposed operating systems. Other hahahahahahas systems, Linux and Macintosh, among others, were not affected. as usual winblows again best thing I ever done was get ride of winblows hahaha= winblows |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
Entrepreneur
Join Date: Oct 2002
Location: USA
Posts: 31,429
|
The worm spreads with the file name: avserve.exe . Unlike many recent worms, this virus does not spread via email. No user intervention is required to become infected or propagate the virus further. The worm works by instructing vulnerable systems to download and hahahahahahaha the viral code.
Indications of Infection The virus copies itself to the hahahahahahas directory as avserve.exe and creates a registry run key to load itself at startup HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\hahahahahaha s\ CurrentVersion\Run "avserve.exe" = C:\hahahahahahaS\avserve.exe As the worm scans random ip addresses it listens on successive TCP ports starting at 1068. It also acts as an FTP server on TCP port 5554, and creates a remote shell on TCP port 9996. A file named win.log is created on the root of the C: drive. This file contains the IP address of the localhost. Copies of the worm are created in the hahahahahahas System directory as #_up.exe. Examples c:\hahahahahahaS\system32\11583_up.exe c:\hahahahahahaS\system32\16913_up.exe c:\hahahahahahaS\system32\29739_up.exe A side-effect of the worm is for LSASS.EXE to crash, by default such system will reboot after the crash occurs. The following hahahahahaha may be displayed: Method of Infection This worm spreads by exploiting a recent Microsoft vulnerability, spreading from machine to machine with no user intervention required. This worm scans random IP addresses for exploitable systems. When one is found, the worm exploits the vulnerable system, by overflowing a buffer in LSASS.EXE. It creates a remote shell on TCP port 9996. Next it creates an FTP script named cmd.ftp on the remote host and hahahahahahahas it. This FTP script instructs the target victim to download and hahahahahahaha the worm (with the filename #_up.exe as aforementioned) from the infected host. The infected host is accepts this FTP traffic on TCP port 5554. The worm spawns multiple threads, some of which scan the local class A subnet, others the class B subnet, and others completely random subnets. The destination port is TCP 445
__________________
![]() from the leaders in the field at iWebmasters.com TO LOWER YOUR COSTS AND INCREASE YOUR PRODUCTION! *** *** *** *** *** *** *** *** *** *** *** *** ![]() ![]() ![]() ![]() ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 |
Omaha Hi/Lo
Join Date: Nov 2003
Posts: 17,380
|
that is why the industry is going all condom..... damn this virus
__________________
Trump haters gonna hate. that's all they can do |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
I am cool
Join Date: Jul 2003
Posts: 14,494
|
Damn it my worm leaked.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 |
Drunk and Unruly
Join Date: Jan 2002
Location: Hollywood
Posts: 22,712
|
I wonder why they hahahahaha useless viruses like that?
__________________
I've trusted my sites to them for over a decade... Webair, bitches. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 |
Confirmed User
Industry Role:
Join Date: Jun 2002
Location: Croatia
Posts: 887
|
Yeah really, like we didn't have enough to worry about w/ one virus (HIV), now we have another.
![]()
__________________
Winning isn’t everything, but wanting to win is. –Vince Lombardi |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 |
Confirmed User
Join Date: Mar 2004
Location: LOLLIPOP ISLAND =-=-=-=-=-=-=-=-=-=-= =-=-=-=-=-=-=-=-=-=-= =-=-=-=-=-=-=-=-=-=-= =-=-=-=-=-=-=-=-=-=-= =-=-=-=-=-=-=-=-=-=-= =-=-=-=-=-=-=-=-=-=-= =-=-=-=-=-=-=-=-=-=-= =-=-=-=-=-=-=-=-=-=-= =-=-=-=-=-=-=-=-=-=-= =-=-=-=-=-=-=-=-=-=-=
Posts: 4,569
|
<font size=10><b>FIREWALL</b></font>
__________________
![]() ![]() ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 |
Confirmed User
Join Date: Feb 2002
Location: Canada
Posts: 2,370
|
Most people that are infected are new computer users or fresh installs. 10-15 seconds online without the updates or firewall and you will have at least 1 trojan installed. Its insane!
ZoiNk
__________________
"People can have the Model T in any color - so long as it's black." - Henry Ford |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 |
The O is for Oohhh
Join Date: Feb 2003
Location: AUSTIN TEJAS
Posts: 10,861
|
Damn, I was just at my Dad's trying to figure out why his lsass.exe kept popping up and shutting his computer down... my searches were fruitless...
GFY as an information source comes through again! |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 |
My time is coming...
Join Date: Jan 2004
Location: Europe --- eMail: service(at)badasscompany.com --- ICQ: 60288510
Posts: 7,476
|
I was infected. Took me 3 hours to remove the virus.
![]()
__________________
If lesbian anal is wrong, I don't want to be right. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 |
OU812
Join Date: Feb 2001
Location: California
Posts: 12,651
|
__________________
Epic CashEpic Cash works for me Solar Cash Paysite Plugin Gallery of the day freesites,POTD,Gallery generator with free hosting |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 |
Confirmed User
Join Date: Mar 2004
Posts: 812
|
Yeah, I was infected as well right after I installed hahahahahahas on new comp!
Security Update helped for that problem. That stuff is insane nowadays. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 |
Confirmed User
Join Date: Nov 2003
Posts: 4,292
|
people should put their hahahahahahas updates on automatic, it would solve a lot of problems
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#18 | |
Entrepreneur
Join Date: Oct 2002
Location: USA
Posts: 31,429
|
Quote:
__________________
![]() from the leaders in the field at iWebmasters.com TO LOWER YOUR COSTS AND INCREASE YOUR PRODUCTION! *** *** *** *** *** *** *** *** *** *** *** *** ![]() ![]() ![]() ![]() ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#19 | |
Too lazy to set a custom title
Join Date: Mar 2002
Location: Australia
Posts: 17,393
|
Quote:
![]() I decided it would be quicker to wipe it, firewall it at my router (only permitting outbound port 80 access), then reinstall. This way I could download and install all the necessary updates without any worms bugging me. Win</b></b>dows sucks. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#20 |
Too lazy to set a custom title
Join Date: Feb 2004
Posts: 1,805
|
can someone hahaha the hahahahas so my hahahahaha can stop running hahahaha?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#21 |
Entrepreneur
Join Date: Oct 2002
Location: USA
Posts: 31,429
|
Here's a good online service to quickly check how protected all your ports are. Its free also.
https://grc.com/x/ne.dll?bh0bkyd2
__________________
![]() from the leaders in the field at iWebmasters.com TO LOWER YOUR COSTS AND INCREASE YOUR PRODUCTION! *** *** *** *** *** *** *** *** *** *** *** *** ![]() ![]() ![]() ![]() ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#22 | |
Too lazy to set a custom title
Join Date: Mar 2002
Location: Australia
Posts: 17,393
|
Quote:
![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#23 | |
So Fucking Banned
Industry Role:
Join Date: Apr 2001
Location: N.Y. -Long Island --
Posts: 122,992
|
Quote:
![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#24 |
Confirmed User
Join Date: Apr 2002
Location: Los Angeles
Posts: 6,102
|
Great, I think one of my computers is infected. Keeps rebooting at random times
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#25 | |
Entrepreneur
Join Date: Oct 2002
Location: USA
Posts: 31,429
|
Quote:
![]() ![]() ![]()
__________________
![]() from the leaders in the field at iWebmasters.com TO LOWER YOUR COSTS AND INCREASE YOUR PRODUCTION! *** *** *** *** *** *** *** *** *** *** *** *** ![]() ![]() ![]() ![]() ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#26 |
Text Writer
Join Date: Feb 2001
Location: Wisconsin
Posts: 18,812
|
just ran a check, all clear!
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#27 | |
Guest
Posts: n/a
|
Quote:
Very useful resource, thanks KRL ![]() |
|
![]() ![]() ![]() ![]() ![]() |
![]() |
#28 |
lurker
Industry Role:
Join Date: Aug 2002
Location: atlanta
Posts: 57,021
|
I run my net computer behind 2 firewalls and the computer I use for work is off line . To get into that one they got to be fucking houdini lol.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#29 | |
Black Vagina Finder
Join Date: Jan 2002
Location: The Midwest
Posts: 13,975
|
Quote:
All attempts to get any information from your computer have FAILED. (This is very uncommon for a hahahahahahas networking-based PC.) Relative to vulnerabilities from hahahahahahas networking, this computer appears to be VERY SECURE since it is NOT exposing ANY of its internal NetBIOS networking protocol over the Internet. ![]()
__________________
![]() Black Pussy Click On Mr Cosby..CCbill, 60/40, 136 FHG's....The Cos Loves Black Ghetto Pussy!! |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#30 | |
Confirmed User
Join Date: Feb 2002
Posts: 720
|
Quote:
Your system has achieved a perfect "TruStealth" rating. Not a single packet ? solicited or otherwise ? was received from your system as a result of our security probing tests. Your system ignored and refused to reply to repeated Pings (ICMP Echo Requests). From the standpoint of the passing probes of any hacker, this machine does not exist on the Internet. Some questionable personal security systems expose their users by attempting to "counter-probe the prober", thus revealing themselves. But your system wisely remained silent in every way. Very nice. ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#31 |
Doing the grind since 99
Industry Role:
Join Date: Oct 2003
Location: Buffalo NY
Posts: 16,881
|
Thanks for the post. I will expect the calls to roll in Monday morning from clients that just wont listen and protect themselves.
Lets hope everyone is running the frequent hahahahahahas updates.
__________________
Living in Virtual Reality Contact: Email (preferred): furiousmale .at. gmail - Skype: live:shanedws |
![]() |
![]() ![]() ![]() ![]() ![]() |