The Lizard Lounge
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
 
User Name:
Password:
Remember me
 
Go Back   Dev Articles Community ForumsCommunityThe Lizard Lounge

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Display Modes
 
Unread Dev Articles Community Forums Sponsor:
  #1  
Old August 12th, 2003, 12:03 PM
iahmed iahmed is offline
Contributing User
Dev Articles Newbie (0 - 499 posts)
 
Join Date: May 2003
Location: USA
Posts: 171 iahmed User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 42 m 58 sec
Reputation Power: 6
RPC DCOM Attack

If You want to check whether your server is vulnerable to RPC DCOM attack (recent ongoing attack on Windows server), download free software from:

http://www.eeye.com/html/Research/Tools/RPCDCOM.html

Reply With Quote
  #2  
Old August 13th, 2003, 03:01 AM
stumpy's Avatar
stumpy stumpy is offline
May contain nuts.
Dev Articles Regular (2000 - 2499 posts)
 
Join Date: Aug 2002
Location: Sydney, AU
Posts: 2,058 stumpy User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 5 h 8 m 57 sec
Reputation Power: 9
Send a message via ICQ to stumpy Send a message via MSN to stumpy
FYI: A lengthy registration form is required to be filled out.

I took a look at my firewall logs today - it's interesting to note that the virus only seems to be searching for addresses on the same B class (correct me if i'm wrong someone).

e.g. my current IP is something like 138.130.30.1 (example only)
All the hits on 135 (the port the RPC attack occurs on) all seem to come from people on 138.130.x.x

Reply With Quote
  #3  
Old August 13th, 2003, 08:32 PM
stumpy's Avatar
stumpy stumpy is offline
May contain nuts.
Dev Articles Regular (2000 - 2499 posts)
 
Join Date: Aug 2002
Location: Sydney, AU
Posts: 2,058 stumpy User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 5 h 8 m 57 sec
Reputation Power: 9
Send a message via ICQ to stumpy Send a message via MSN to stumpy
They way this worm attack has intruiged me - I just found this info about how it generates it's IPs. (for those that care )

Quote:
Update:
The worm uses a 60/40 split to determine its starting target subnet. The algorithm works by generating a random number and dividing it by 20. If the remainder of this division (the modulo of the original number) is greater than or equal to 12 (40% chance), then the new range is based off the current local host IP address, otherwise, a random starting point is used.
Given the local host IP address is used (A.B.C.D), D is set to zero. If C is greater than 20, a random number (less than 20) is subtracted from C. Once this semi random IP address has been calculated, the worm will continually increment the IP address, attacking in a sequential order. This means the local subnet will become saturated with port 135 requests prior to exiting the local subnet.
Conversely, if the remainder is less than 12 then the high 3 octets of the IP address are randomized.
Regardless of how the starting point of the scan has been determined, the worm will continue to scan indefinitely, incrementing the IP address by one to determine the next target host. The current IP address range is not randomized again until the worm is restarted.

Reply With Quote
  #4  
Old August 13th, 2003, 10:58 PM
wastedbreath wastedbreath is offline
Contributing User
Dev Articles Newbie (0 - 499 posts)
 
Join Date: Aug 2003
Location: BC, Canada
Posts: 35 wastedbreath User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 6
Send a message via AIM to wastedbreath
I was talking to a guy who is in a cracking group and knows several hackers. He said the attack is supposed to take down the internet..the second half to start with ddos ing on the 15th.

This could all be bs..my friend has been to his house to confirm he is in a cracking group..or is good with Kazaa :P But he did tell us(a small forum group) about the attack a week before it started ..up to you guys to beleive or not

Reply With Quote
  #5  
Old August 13th, 2003, 11:06 PM
stumpy's Avatar
stumpy stumpy is offline
May contain nuts.
Dev Articles Regular (2000 - 2499 posts)
 
Join Date: Aug 2002
Location: Sydney, AU
Posts: 2,058 stumpy User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 5 h 8 m 57 sec
Reputation Power: 9
Send a message via ICQ to stumpy Send a message via MSN to stumpy
Yup - I've heard the 16th. Apparently all the infected computers are going to attempt to connect to windows update at the same time. This will cause a few problems. One, say half a billion computers are infected - that's a **** load of traffic all attempting to make something like 20 connections each....
The other issue is that windows update will be DDOS'd. For some reason, no-one seems to be mirroring the patch, just linking to the MS site - pointless.

Reply With Quote
  #6  
Old August 13th, 2003, 11:30 PM
wastedbreath wastedbreath is offline
Contributing User
Dev Articles Newbie (0 - 499 posts)
 
Join Date: Aug 2003
Location: BC, Canada
Posts: 35 wastedbreath User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 6
Send a message via AIM to wastedbreath
Quote:
just linking to the MS site - pointless


Maybe..I kinda wanna see if they take them down..even for an hour. I should scan to see if I'm infected..I don't use firewall(my dad just took my router) but I did shut off the RPC service..hmm

Reply With Quote
  #7  
Old August 13th, 2003, 11:35 PM
stumpy's Avatar
stumpy stumpy is offline
May contain nuts.
Dev Articles Regular (2000 - 2499 posts)
 
Join Date: Aug 2002
Location: Sydney, AU
Posts: 2,058 stumpy User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 5 h 8 m 57 sec
Reputation Power: 9
Send a message via ICQ to stumpy Send a message via MSN to stumpy
Download Zone Alarm - it's free. There's no excuse to get attacked.

Reply With Quote
  #8  
Old August 13th, 2003, 11:47 PM
wastedbreath wastedbreath is offline
Contributing User
Dev Articles Newbie (0 - 499 posts)
 
Join Date: Aug 2003
Location: BC, Canada
Posts: 35 wastedbreath User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 6
Send a message via AIM to wastedbreath
ZA's free?..I was looking at BlackIce but I gotta pay..oh right..ZA is free for personal use

Reply With Quote
  #9  
Old August 13th, 2003, 11:52 PM
stumpy's Avatar
stumpy stumpy is offline
May contain nuts.
Dev Articles Regular (2000 - 2499 posts)
 
Join Date: Aug 2002
Location: Sydney, AU
Posts: 2,058 stumpy User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 5 h 8 m 57 sec
Reputation Power: 9
Send a message via ICQ to stumpy Send a message via MSN to stumpy
Here's the direct link to the free version of the ZoneAlarm firewall for anyone else who isn't protected: http://download.zonelabs.com/bin/fr...etup_37_202.exe

Reply With Quote
  #10  
Old August 14th, 2003, 12:01 AM
wastedbreath wastedbreath is offline
Contributing User
Dev Articles Newbie (0 - 499 posts)
 
Join Date: Aug 2003
Location: BC, Canada
Posts: 35 wastedbreath User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 6
Send a message via AIM to wastedbreath
Thanks stumpy..running ZA now

Reply With Quote
  #11  
Old November 18th, 2004, 02:00 AM
Triped Triped is offline
Registered User
Dev Articles Newbie (0 - 499 posts)
 
Join Date: Nov 2004
Posts: 1 Triped User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Angry Dont use ZA !!!

Dont use ZA, its gonna suck your RAM ! I used to have it until I found out it was using up to 80% of my processor ! No joke ! use Sygate ! hey, and that virus... I've received like at least 5 attacks a minute for the past 3 hours now ! My server sucks bad !

Reply With Quote
  #12  
Old November 22nd, 2004, 01:31 PM
MadCowDzz's Avatar
MadCowDzz MadCowDzz is offline
I'm Internet Famous
Dev Articles Frequenter (2500 - 2999 posts)
 
Join Date: Jan 2003
Location: Toronto, Canada
Posts: 2,890 MadCowDzz User rank is Lance Corporal (50 - 100 Reputation Level)MadCowDzz User rank is Lance Corporal (50 - 100 Reputation Level)MadCowDzz User rank is Lance Corporal (50 - 100 Reputation Level) 
Time spent in forums: 1 Week 16 h 14 m 9 sec
Reputation Power: 8
I haven't had a problem with Zonealarm... although I've heard the latest version has some bugs.. don't quote me on that though.

Reply With Quote
  #13  
Old November 22nd, 2004, 01:41 PM
Viper_SB's Avatar
Viper_SB Viper_SB is offline
Moderator
Dev Articles Newbie (0 - 499 posts)
 
Join Date: Oct 2003
Location: Canada
Posts: 331 Viper_SB User rank is Private First Class (20 - 50 Reputation Level)Viper_SB User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: 1 Day 4 h 53 m 7 sec
Reputation Power: 6
Quote:
Originally Posted by MadCowDzz
although I've heard the latest version has some bugs


........

Reply With Quote
Reply

Viewing: Dev Articles Community ForumsCommunityThe Lizard Lounge > RPC DCOM Attack


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support |