misterx: (Default)
[personal profile] misterx
It figures... I sent out an email alerting my office mates weeks ago to update their systems. So what happens? The graphics guy was "too busy", and now he got blasted. Well, not busy now, are ya? Because I'm sitting in your chair, fixing your system.

on 2003-08-12 08:37 am (UTC)
Posted by [identity profile] voltbang.livejournal.com
If he was too busy to attend to it proactively, there's no reason you should be rushing to attend to it reactively. You did your part weeks ago.

on 2003-08-12 09:32 am (UTC)
Posted by [identity profile] alabastermoon.livejournal.com
I read one piece that says all Windows versions are affected, and then read another that says 98 is excluded.

What are the facts, fact dude?

on 2003-08-12 10:04 am (UTC)
Posted by [identity profile] misterx.livejournal.com
Systems that have the flaw that lets the worm in are:
Win NT
Win 2000
Win XP
Win Server 2003

Win ME does not have the flaw.

According to Microsoft:
"Previous versions are no longer supported, and may or may not be affected by this vulnerability."
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-026.asp
Gee, thanks guys.

For what it is worth, Symantec says 95 and 98 are not vulnerable:
http://securityresponse.symantec.com/avcenter/venc/data/w32.blaster.worm.html

Here's a link to the group that found the flaw:
http://www.lsd-pl.net/special.html
It should be noted the group worked with Microsoft, and did NOT release any exploit code.

A little over a week later, a group out of China called Xfocus figured out the details and published them.
http://www.xfocus.org/documents/200307/2.html

MetaSploit wrote the first exploit:
http://www.metasploit.com/releases.html

It was only a short time until it became a worm.

I'd like to point out that when I read the first post from LSD on bugtraq, I predicted it would become a worm. As I put it to my coworker, reading bugtraq and vuln-dev in the days after that post was like watching a slasher flick... you knew it was coming, you just didn't know when. Not that this was genius or anything, just saying. :)

May 2017

S M T W T F S
 123456
789 10111213
14151617181920
21222324252627
28293031   

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated Mar. 23rd, 2026 05:07 pm
Powered by Dreamwidth Studios