[THIN] Re: *** RPC ALERT *** We got hit.

  • From: John Twilley <John.Twilley@xxxxxxxxxxxxxxxxxxxxx>
  • To: "'thin@xxxxxxxxxxxxx'" <thin@xxxxxxxxxxxxx>
  • Date: Fri, 1 Aug 2003 13:48:51 -0400

Yes.  DOS type attack against the RPC port 135 will not trigger antivirus. 



-----Original Message-----
From: George Yobst [mailto:george2@xxxxxxxxxxxxxxx] 
Sent: Friday, August 01, 2003 1:01 PM
To: thin@xxxxxxxxxxxxx
Subject: [THIN] Re: *** RPC ALERT *** We got hit.

Did you have antivirus software installed on it?
-George

John Twilley wrote:
>  
> Just a heads up...
> You all have heard on the RPC exploit that effects Win NT/2000/XP/2003.
> 
> We just got a taste of it in our Italy office...and it is BAD!  VERY BAD.
> 
> 
> Win XP / 2000 / 2003
> 
> You will notice that the DEFAULT recover setting for the RPC service 
> is to
> (Drum-Roll)
> RESTART the server after 1 minute.
> 
> Guess what, it does.   
> Server restarts every couple of minutes. 
> 
> WOW.
> 
> Take it from me... PATCH EVERYTHING NOW.   Yes.  Everything.
> 
> More Details.
> http://www.microsoft.com/technet/treeview/?url=/technet/security/bulle
> tin/MS
> 03-026.asp

---------------------------------------------------------------------------
George Yobst, Library Technology Analyst        phone: 503.723.4890
Library Information Network of Clackamas County   fax: 503.794.8238
16239 SE McLoughlin Blvd, Suite 208         web: http://www.lincc.lib.or.us
Oak Grove, OR 97267-4654                  email: george@xxxxxxxxxxxxxxx
"...it is impossible for anyone to begin to learn
  what he thinks he already knows."  - Epictetus

********************************************************
This weeks sponsor - RTOSoft TScale
Complaints about applications response time - DO SOMETHING ABOUT IT!
TScale 2.0 improves applications response time and increases terminal server
capacity. Really get MORE from your existing servers! Free eval:
http://www.rtosoft.com/enter.asp?id=130
**********************************************************
Useful Thin Client Computing Links are available at:
http://thethin.net/links.cfm

For Archives, to Unsubscribe, Subscribe or set Digest or Vacation mode use
the below link:
http://thethin.net/citrixlist.cfm
********************************************************
This weeks sponsor - RTOSoft TScale 
Complaints about applications response time - DO SOMETHING ABOUT IT!
TScale 2.0 improves applications response time and increases terminal
server capacity. Really get MORE from your existing servers! Free eval:
http://www.rtosoft.com/enter.asp?id=130
**********************************************************
Useful Thin Client Computing Links are available at:
http://thethin.net/links.cfm

For Archives, to Unsubscribe, Subscribe or 
set Digest or Vacation mode use the below link:
http://thethin.net/citrixlist.cfm

Other related posts: