Re: windows security bulletin

From: Bruce Chambers (bruce_a_chambers_at_h0tmail.com)
Date: 02/27/05


Date: Sat, 26 Feb 2005 18:58:31 -0700

noname wrote:
> I get a following message of and on with title 'Messnger Service'
> Important windows security bulletin,buffer overrun in messenger
> service allows remote code execution ,virus infection and unexpected
> shutdown, your system if affected, download the patch from the
> addresss below
> address www.updatepatch.info
> I dont know whether I should go to this address and download what they
> are suggesting to download. some good advice thanks
>

     It's a scam, plain and simple. It's from a very unscrupulous
"business." They're trying to sell you patches that Microsoft provides
free-of-charge, and using a very intrusive means of advertising. It's
also demonstrating that your PC is very unsecure.

     This type of spam has become quite common over the past couple of
years, and unintentionally serves as a valid security "alert." It
demonstrates that you haven't been taking sufficient precautions while
connected to the Internet. Your data probably hasn't been compromised
by these specific advertisements, but if you're open to this exploit,
you most definitely open to other threats, such as the Blaster,
Welchia, and Sasser Worms that still haunt the Internet. Install and
use a decent, properly configured firewall. (Merely disabling the
messenger service, as some people recommend, only hides the symptom,
and does little or nothing to truly secure your machine.) And
ignoring or just "putting up with" the security gap represented by
these messages is particularly foolish.

Messenger Service of Windows
http://support.microsoft.com/default.aspx?scid=KB;en-us;168893

Messenger Service Window That Contains an Internet Advertisement
Appears
http://support.microsoft.com/?id=330904

Stopping Advertisements with Messenger Service Titles
http://www.microsoft.com/windowsxp/pro/using/howto/communicate/stopspam.asp

Blocking Ads, Parasites, and Hijackers with a Hosts File
http://www.mvps.org/winhelp2002/hosts.htm

   Whichever firewall you decide upon, be sure to ensure UDP ports 135,
137, and 138 and TCP ports 135, 139, and 445 are all blocked. You
may also disable Inbound NetBIOS over TCP/IP). You'll have
to follow the instructions from firewall's manufacturer for the
specific steps.

     You can test your firewall at:

Symantec Security Check
http://security.symantec.com/ssc/vr_main.asp?langid=ie&venid=sym&plfid=23&pkj=GPVHGBYNCJEIMXQKCDT

Security Scan - Sygate Online Services
http://www.sygatetech.com/

     Oh, and be especially wary of people who advise you to do nothing
more than disable the messenger service. Disabling the messenger
service, by itself, is a "head in the sand" approach to computer
security. The real problem is not the messenger service pop-ups;
they're actually providing a useful, if annoying, service by acting as
a security alert. The true problem is the unsecured computer, and
you've been advised to merely turn off the warnings. How is this
helpful?

-- 
Bruce Chambers
Help us help you:
http://dts-l.org/goodpost.htm
http://www.catb.org/~esr/faqs/smart-questions.html
You can have peace. Or you can have freedom. Don't ever count on having 
both at once. - RAH


Relevant Pages

  • Re: Strange Networking Problem
    ... If you have MSN Messenger installed, and you don't use it, you might try ... disabling or uninstalling it and then see if things work properly with ... See here to disable it: How to prevent Windows Messenger from running ... Then uninstall the leftover installation information file by going to ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: Windows (XP Home) Messenger: how to disable
    ... >> windows when I boot. ... The Messenger Service is a network utility that's embedded in the operating ... firewall application or hardware device. ... fix it follow the advice in the earlier post about disabling the Messenger ...
    (microsoft.public.windowsxp.basics)
  • Re: Error
    ... Messenger Service, it may indicate that your system is not secure. ... administrators to notify Windows users about their networks. ... Disabling Messenger Service in Windows XP ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: registry scan ?
    ... The title was "Messenger Service." ... Windows has encountered an internal Error. ... ignoring or just "putting up with" the security gap represented by ... All too few people keep their antivirus software current, install patches in a timely manner, or stop to really think about that cutesy link they're about to click. ...
    (microsoft.public.windowsxp.general)
  • messenger pop-up ads fix that works!
    ... If your using windows XP,NT and 2000 and getting pop-up ... I understand you are receiving "Messenger Service" pop ... network, as well as the Internet, to any system that has ... Disabling this service will not affect your .NET ...
    (microsoft.public.windowsxp.security_admin)