Re: Questions about "net" messenger service (NOT MSN Messenger)

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Alex Nichol (alexn.mvpdts_at_ntlworld.delete.com)
Date: 03/09/04


Date: Tue, 09 Mar 2004 12:05:29 +0000

Steve Lee wrote:

>Thanks for your reply, Alex. So, when you say, "that way", are you
>talking about the "net send"/messenger command or the possible adware
>I talked about in the second paragraph?
>
>Sorry for being so the redundant question, but port 135 is used by the
>messenger/"net send" service, then are you saying that mean that "net
>send" command is actually capable of sending binary files, such as
>pictures to appear in the message window?

Net /send isn't. But programs can get through port 135 to hit a
loophole in the messenger service and hence display adverts. And other
malicious programs can get through to hit other loopholes - this is how
BLAST gets in. The vulnerability that plugged is now fixed (indeed the
fix was available three weeks before BLAST hit) - but there may be other
targets. You should be sure that 135 is blocked to any Internet
connection - leave it open on LAN ones, but there you generally do not
have a firewall active anyway

-- 
Alex Nichol MS MVP (Windows Technologies)
Bournemouth, U.K.  Alexn@mvps.D8E8L.org (remove the D8 bit)


Relevant Pages

  • RE: Can not print (print server is Win2000 machine)
    ... Hit the offline button ... Standard Port Monitor ... Click Start, point to Settings, and then click Printers. ... Click Standard TCP/IP Port, ...
    (microsoft.public.win2000.general)
  • Linksys Cable/DSL router Port Forwarding
    ... I have a web server running on the static IP for testing ... LAN using the internal IP and/or I want to hit it using the external IP ... I have internet access on all three machines. ... I have opened port 8090 in port forwarding for the static IP that the NT 4 ...
    (comp.security.firewalls)
  • Re: Git via a proxy server?
    ... Doesn't even appear to hit the proxy server. ... MIS had opened up the port ... Try using the HTTP protocol. ...
    (Linux-Kernel)
  • re: Syn packets hitting port 80, not webserver
    ... Syn packets hitting port 80, ... Most hit twice ... Listen to your Yahoo! ...
    (Incidents)
  • Re: Are Tiscali blocking news.individual.net in the evening?
    ... see it as a loophole that needs to be filled ... Look at the Newsserver I am using and ... when you sign up look for the SSL option. ... I also tried the non-standard port 443 and port 80, and those didn't work either, so maybe they're blocking is a bit more sophisticated than just by port. ...
    (uk.telecom.broadband)