Cable Forum

Cable Forum (https://www.cableforum.uk/board/index.php)
-   Internet Discussion (https://www.cableforum.uk/board/forumdisplay.php?f=25)
-   -   Merged: W32 Blaster Virus (https://www.cableforum.uk/board/showthread.php?t=1826)

homealone 13-08-2003 22:58

Quote:

Originally posted by ianathuth
http://visualize.phenominet.com/


EDIT. Homealone beat me to it. Both addresses lead to same info.

lol

gotta say that for peeps with Linksys routers the logviewer

here

is excellent - it gives you something to look at when nothing gets through to Zone Alarm!

Gaz:)

danielf 13-08-2003 23:09

Quote:

Originally posted by homealone
lol

gotta say that for peeps with Linksys routers the logviewer

here

is excellent - it gives you something to look at when nothing gets through to Zone Alarm!

Gaz:)

Funny you should mention that. I just decided to upgrade to the latest version of zonealarm, and I spent the last half hour or so trying to get logviewer to work again. The logs just aren't coming through, even though I gave it server rights. (and it was working fine before I upgraded zonealarm:mad: :confused:

Edit: and the attacks are coming through to logviewer the moment I witch zonealarm off...

homealone 13-08-2003 23:14

Quote:

Originally posted by danielf
Funny you should mention that. I just decided to upgrade to the latest version of zonealarm, and I spent the last half hour or so trying to get logviewer to work again. The logs just aren't coming through, even though I gave it server rights. (and it was working fine before I upgraded zonealarm:mad: :confused:
u using version 1.57 of logviewer? Maybe try uninstall & re-install?

i.e. I had upgraded Zone Alarm before I installed Logviewer?

Mine is set at ask for access & def no server?

danielf 13-08-2003 23:22

Quote:

Originally posted by homealone
u using version 1.57 of logviewer? Maybe try uninstall & re-install?

Mine is set at ask for access & def no server?

I actually downloaded it today. Have tried uninstall/reinstall, uninstall and reboot before reinstall. etc. I'm probably overlooking something silly here, but it's not working, and the moment I switch off zonealarm, it's showing the logs... Maybe the new version of zonealarm?

edit: Using version 3.0 of logviewer

homealone 13-08-2003 23:29

Quote:

Originally posted by danielf
I actually downloaded it today. Have tried uninstall/reinstall, uninstall and reboot before reinstall. etc. I'm probably overlooking something silly here, but it's not working, and the moment I switch off zonealarm, it's showing the logs... Maybe the new version of zonealarm?

edit: Using version 3.0 of logviewer

we could actually be talking about different programs with the same / similar name?

The one I'm running is at the link

http://home.debitel.net/user/svenschaef/logview/

- what's yours? :)

Gaz

danielf 13-08-2003 23:40

Quote:

Originally posted by homealone
we could actually be talking about different programs with the same / similar name?

The one I'm running is at the link

http://home.debitel.net/user/svenschaef/logview/

- what's yours? :)

Gaz

Lol. Mine's from linksys, and it's called logviewer as well. Seeing you mentioned people with Linksys routers... :D.
Anyway I see yours is for Norton Internet Security, which I don't use. Just keep mucking about I guess. I'm sure I will press the right button at some point ;)

homealone 13-08-2003 23:46

Quote:

Originally posted by danielf
Lol. Mine's from linksys, and it's called logviewer as well. Seeing you mentioned people with Linksys routers... :D.
Anyway I see yours is for Norton Internet Security, which I don't use. Just keep mucking about I guess. I'm sure I will press the right button at some point ;)

Check out the d/l from my link - it does work with Linksys routers ( well my BEFSR41 anyway) as an SNMP logging client - much better than the Linksys log viewer- graphs, tracerts, whois - give it a go?

Gaz

danielf 13-08-2003 23:49

Quote:

Originally posted by homealone
Check out the d/l from my link - it does work with Linksys routers ( well my BEFSR41 anyway) as an SNMP logging client - much better than the Linksys log viewer- graphs, tracerts, whois - give it a go?

Gaz

Doing that right now. Sounds good.

Cheers,

Daniel

zoombini 14-08-2003 09:26

It has been suggested that although this is a virus/worm its not too bad really.

Whats it do, shut down your Windows pc & popup a few messages, anything else?

AFAIKR it does not harm any data.
It appears it is only and attempt by someone who has found a flaw in the system to get MS to do something about it, not by telling them directly and getting ignored but publicly?

I think we should be thankful the person who did this was not malicious.

At the same time it is able to make people more aware of the need to run firewalls, as thats what will be likely advised when they talk to someone more informed about PC's or get information on removing it. Hopefully this will also remove the
consequences of what it has done in telling everyone else that they are unprotected.

Although behind adequate firewall protection myself, some of the people that I know had it. Hopefully not too many people will format their PC in an attempt to remove it.

Lord Nikon 14-08-2003 09:57

Looks like a new variant - MSBlaster, which is set to initiate a Denial of service attack on windowsupdate.com this saturday

Thing is... MS's update site is windowsupdate.microsoft.com so they messed up slightly, presumably MS will redirect the windowsupdate.com to 127.0.0.1 or something in the DNS tables so the attack will do nothing.


Hopefully.... Still, this is MS we are talking about so.....

trebor 14-08-2003 12:38

the worm has the ability to execute any command on the pc
how about a quick format that wouldn't do your data much good.
as it is the worm is coded to just issue the shutdown command
but it could get a lot worse.
also the port hits on 135 are not getting any less I'm up to 157 today so there is still a lot of un patched pc's out there

danielf 14-08-2003 12:43

Quote:

Originally posted by trebor
the worm has the ability to execute any command on the pc
how about a quick format that wouldn't do your data much good.
as it is the worm is coded to just issue the shutdown command
but it could get a lot worse.
also the port hits on 135 are not getting any less I'm up to 157 today so there is still a lot of un patched pc's out there

One thing I was wondering. Having the worm shut down the pc doesn't help its propagation. Apparently, the author isn't out to cause major damage (even to Microsoft), or am I overlooking something?

hawkmoon 14-08-2003 12:47

Quote:

Originally posted by BenH
Actually if I wanted to insult you I'd be going for the throat, like your website. At the moment I just want to make sure you dont have the last word.


FFS just grow up and act a little more mature.

There are reason why I ignored your posts mainly because I don't want to get into an argument about whether Linux is better than Windows or not - personally I don't care.

Yes I keep mentioning about exploits because you seem to be so taken up with your own abilities that it is bordering on arrogance.

As for could and might - well that is not my vocabulary, but that of the people that issue the adviseries. If you don't like it then take it up with them.

As I said before, please refrain from trying to belittle my comments by questioning my abilities - as I doubt that you are really impressing anyone with them and they are sadly very far from the truth.


To the Mods don't bother replying as I have got bored with this whole forum - delete this account as you see fit.

zoombini 14-08-2003 13:24

Quote:

Originally posted by trebor

but it could get a lot worse.

My point exactly... is this a simple "point" being made or a pre- emptive strike before the next version that does the damage?

Russ 14-08-2003 13:37

Quote:

Originally posted by hawkmoon
delete this account as you see fit.
No need - everyone just step back and take a breather please.


All times are GMT. The time now is 05:34.

Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
All Posts and Content are © Cable Forum