Ping: Ken Blake

From: David H. Lipman (DLipman~nospam~_at_Verizon.Net)
Date: 03/03/04


Date: Tue, 2 Mar 2004 20:29:38 -0500

Regarding your reply in the thread "Blaster virus"

Mistakes Ken !

The information I extracted from your post is incorrect !

What you have provided is NOT a patch. It is the Lovsan/Blaster & Nachi/Welchia removal
tool. It will not correct the RPC/RPCSS Buffer Overflow Vulnerability that is addressed by
Microsoft Security Bulletin MS03-39 http://support.microsoft.com/?kbid=824146 That is the
"patch" to prevent the Internet worms.

A *better* tool (non Microsoft) is McAfee's Stinger: http://vil.nai.com/vil/stinger/ for
removing the infectors that exploit the RPC/RPCSS vulnerability.

Dave

"Ken Blake, MVP" <kblake@this.is.an.invalid.domain> wrote in message
news:eqAGDxLAEHA.2316@TK2MSFTNGP10.phx.gbl...
| b. If you've disconnected your internet connection, reconnect it.
| Download and install the Microsoft patch at
|
http://www.microsoft.com/downloads/details.aspx?FamilyID=e70a0d8b-fe98-493f-ad76-bf673a38b4cf&displaylang=en
|
| That will remove the vulnerability that the worm exploits.



Relevant Pages

  • [Full-Disclosure] MS02-065 vulnerability
    ... Microsoft security bulletin ... visit a web site or open an HTML mail". ... vulnerability, exploitable by a Web page or email; ... Just as exploitable after the patch. ...
    (Full-Disclosure)
  • Re: Blaster virus
    ... What you have provided is NOT a patch. ... It will not correct the RPC/RPCSS Buffer Overflow Vulnerability that is addressed by ... Microsoft Security Bulletin MS03-39 http://support.microsoft.com/?kbid=824146 That is the ... "patch" to prevent the internet worms. ...
    (microsoft.public.windowsxp.general)
  • Microsoft Security Bulletin MS06-067 (922760) Question
    ... Now that the patch for Microsoft Security Bulletin MS06-067 has ... been applied and supposedly fixed the Direct Animation control ... vulnerability, does this mean we can remove the kill bit (per Security ...
    (microsoft.public.win2000.security)
  • Re: Security issue with making NNTP accessible?
    ... to the best of my knowledge, there has only been one exploit and patch ... for Windows NNTP. ... Microsoft Security Bulletin MS04-036 ... Vulnerability in NNTP Could Allow Remote Code Execution ...
    (microsoft.public.security)
  • Re: Download.ject - commentary - LONG
    ... > patch recently released by Microsoft. ... > vulnerability in question, but instead is just a partial workaround. ... > Granted these are known security best practices related to Internet ... > a new default browser to users and hope that it will be safe enough. ...
    (microsoft.public.win2000.security)