Spam: A New Mode

No holds barred discussion. Someone train you and steal your rare spawn? Let everyone know all about it! (Not for the faint of heart!)

Moderator: TheMachine

Post Reply
User avatar
Arborealus
Way too much time!
Way too much time!
Posts: 3417
Joined: September 21, 2002, 5:36 am
Contact:

Spam: A New Mode

Post by Arborealus »

Ok so this really pisses me off...

I demilitarize (basically take the firewall from in front of) one of my computers trying to allow some traffic that into that machine. Go back to what I was doing on another.

*Bink* Window pops up on the dmz'ed machine...To see whatever the spammer wants you to see click OK now. This is not an explorer window and it is addressed to my IP address. Ok so do a netstat and voila port 139. WTF!

Basically spammers are now IP broadcasting Netsends via spamware called IP_Bulker. So if you have an unfirewalled machine...its time to get that firewall and learn how to use it.

These spam windows will crash EQ. And worse yet, no one who would use this sort of spamware is responsible enough to maintain their machines so clicking the ok button (did this on accident, thanks laptop membrane pad) will get you an viral infection (Nimda E in my case).

Short Term Fix: Go to Control Panel, Administrative Tools, Services find Messenger (this isn't MS Messenger) double click on it set Service status to stopped and Startup Type to Disabled.

Medium Term Fix: Buy a firewall and keep Port 139 slammed shut.

Long Term Fix: Persecute the sort of shits that engage in Spam of any sort. These asses are eating up all of our bandwidth with junk email and now directly broadcasting at us.
User avatar
noel
Super Poster!
Super Poster!
Posts: 10003
Joined: August 22, 2002, 1:34 am
Gender: Male
Location: Calabasas, CA

Post by noel »

Yes!

I occastionaly DMZ my box for UT2003 Hosting etc., and this happens to me ALL THE TIME when I'm DMZed.

I fucking hate that!
Oh, my God; I care so little, I almost passed out.
User avatar
Bakara
Gets Around
Gets Around
Posts: 56
Joined: July 3, 2002, 3:47 pm
Location: Texas
Contact:

...

Post by Bakara »

Go into your control panel, administrative, services - turn off windows messenger. Problem solved.
User avatar
KilornCloudwalker
Almost 1337
Almost 1337
Posts: 600
Joined: July 3, 2002, 2:32 pm
Location: Louisiana
Contact:

Post by KilornCloudwalker »

Just found this out the other day... Had been getting those popups for weeks before I formatted the machine..I figured something I installed was doing it and I missed it... then it happened on a clean machine and I couldn't figure it out...shoulda just asked here forst..but yeah, killed Messenger service and its all good now...


Guess I better run a virus scan...gah...anyone recommend a good free one?
Kilorn Cloudwalker
62 Oracle - Retired
User avatar
Arborealus
Way too much time!
Way too much time!
Posts: 3417
Joined: September 21, 2002, 5:36 am
Contact:

Re: ...

Post by Arborealus »

Bakara wrote:Go into your control panel, administrative, services - turn off windows messenger. Problem solved.
See Short Term...

That however is not a solution.

The solution is to drive those who use our bandwidth unethically off the internet.
User avatar
Arborealus
Way too much time!
Way too much time!
Posts: 3417
Joined: September 21, 2002, 5:36 am
Contact:

Post by Arborealus »

KilornCloudwalker wrote:Just found this out the other day... Had been getting those popups for weeks before I formatted the machine..I figured something I installed was doing it and I missed it... then it happened on a clean machine and I couldn't figure it out...shoulda just asked here forst..but yeah, killed Messenger service and its all good now...


Guess I better run a virus scan...gah...anyone recommend a good free one?
Actually Antivirus.com has a good free online scanner
User avatar
Midnyte_Ragebringer
Super Poster!
Super Poster!
Posts: 7062
Joined: July 4, 2002, 1:59 pm
Gender: Male
XBL Gamertag: Daellyn
Location: Northeast Pennsylvania

Post by Midnyte_Ragebringer »

Just download a trial version of one then stop by astalavista.box.sk for the crack
User avatar
Munt
Gets Around
Gets Around
Posts: 137
Joined: July 8, 2002, 12:06 pm
Location: Belfarse, Northern Ireland
Contact:

Post by Munt »

That sorta shit really pisses me off ... and the fact that all spam just pisses you off means you're not gonna buy shit from them ... what's the logic ? ... Bush should start a war on spam and nuke the bastards.

I hate advertising full stop. I especially hate advertisments being FORCED on me. Fuck that, and fuck them ... they're all going to a hell of eternal pyrimid scheming and penis enlargement advertisements.

Sorry about that.
Last edited by Munt on December 5, 2002, 5:16 pm, edited 1 time in total.
User avatar
Arborealus
Way too much time!
Way too much time!
Posts: 3417
Joined: September 21, 2002, 5:36 am
Contact:

Post by Arborealus »

What really really torques me is that I am paying for them to advertise at me...
User avatar
Animalor
Super Poster!
Super Poster!
Posts: 5902
Joined: July 8, 2002, 12:03 pm
Gender: Male
XBL Gamertag: Anirask
PSN ID: Anirask
Location: Canada

Post by Animalor »

The long term solution is to force MS to secure their PoS OS.
User avatar
Arborealus
Way too much time!
Way too much time!
Posts: 3417
Joined: September 21, 2002, 5:36 am
Contact:

Post by Arborealus »

AniRask wrote:The long term solution is to force MS to secure their PoS OS.
Because Macs don't get spam?...

Granted Windows is riddled with holes...but filling those will not stop the use of bandwidth for Bullshit like this...Every OS is exploitable it's just a question of popularity that makes Windows flaws more commonly exploited. Make it profitable and someone will find the holes in any OS.
User avatar
Animalor
Super Poster!
Super Poster!
Posts: 5902
Joined: July 8, 2002, 12:03 pm
Gender: Male
XBL Gamertag: Anirask
PSN ID: Anirask
Location: Canada

Post by Animalor »

I wasn't referring e-mail spam though. I was referring to the popup window one. Just wait till porn people get wind of this and all of a sudden pictures of people fucking start appearing on your screen.

edit long day, nonsensical sentence correction
User avatar
pyrella
>()))>
Posts: 1499
Joined: July 2, 2002, 9:53 pm
Gender: Mangina
Location: SoCal
Contact:

Post by pyrella »

As has been pointed out this uses Messenger service, it's used most commonly to relay Text only information for things like printers telling you the job is done, or for simple notices like remote shutdown, or announcements, strictly a Messenger service - clicking ok just makes the box go away, and as said before, disable the messenger service, and when the spammer does his port scan it will be bounced back with no message recieved.
Pyrella - Illusionist - Leader of Ixtlan on Antonia Bayle

if you were walking around and you came upon a tulip with tits, would you let it be for the rest of the world to enjoy.. or would you pick it and carry it off to a secluded area to motorboat them?
-Cadalano
User avatar
Sylvus
Super Poster!
Super Poster!
Posts: 7033
Joined: July 10, 2002, 11:10 am
Gender: Male
XBL Gamertag: mp72
Location: A², MI
Contact:

Post by Sylvus »

Nah, they can't actually pop stuff up, they can just send text that will show up in an alert dialog, if I'm thinking about this correctly. Similar to a "net send". At least that's what it appears to look like.
"It's like these guys take pride in being ignorant." - Barack Obama

Go Blue!
User avatar
Boo
Gets Around
Gets Around
Posts: 90
Joined: July 9, 2002, 2:53 am
Location: Nursing Home for Retired Pr0nstar

Post by Boo »

The only time I use microsuck windoze is for EQ.

Solaris is your god, and Linux is your daddy.
Boo. Oogah Boo. Double Uh-Oh. Licensed to slow.
User avatar
Aabidano
Way too much time!
Way too much time!
Posts: 4861
Joined: July 19, 2002, 2:23 pm
Gender: Male
Location: Florida

Post by Aabidano »

Sylvus wrote:Nah, they can't actually pop stuff up, they can just send text that will show up in an alert dialog, if I'm thinking about this correctly. Similar to a "net send". At least that's what it appears to look like.
Partially true, the messenger service can only send messages of this type.

There are a bunch of adware trojans running around that will send html adverts directly to your screen. The people running (some) banner sites try to auto install them, most aren't polite enough to ask before they do. They also track your net usage and sell the information. Hurray for spyware.

Software that blocks connections that originate externally, and those originate locally on a per application basis is about the only way to stop it. Windows scripting, ActiveX and MS based Java are all riddled with holes and not designed for security. Not to mention the MS OS's themselves.
"Life is what happens while you're making plans for later."
Post Reply