Lowdown doubledealin backstabbin larcenous perverted WORM!

No holds barred discussion. Someone train you and steal your rare spawn? Let everyone know all about it! (Not for the faint of heart!)

Moderator: TheMachine

Post Reply
User avatar
masteen
Super Poster!
Super Poster!
Posts: 8197
Joined: July 3, 2002, 12:40 pm
Gender: Mangina
Location: Florida
Contact:

Lowdown doubledealin backstabbin larcenous perverted WORM!

Post by masteen »

The entire school board got infected by the Nachi worm. It got into the fucking mail server, the network login server (2 discrete machines) and brought our network to its knees.

The truly sad part is that the vscan we're running was perfectly able to detect and remove it. It's just that the dumbasses who work here were too stupid to USE it.

On the plus side, at the moment, I'm one of about 10 users hogging the T for my own purposes! Muahaha!
Last edited by masteen on August 27, 2003, 5:25 pm, edited 1 time in total.
User avatar
Neost
Almost 1337
Almost 1337
Posts: 911
Joined: July 3, 2002, 1:56 pm
Gender: Male
XBL Gamertag: neost
Wii Friend Code: neost
Contact:

Post by Neost »

Awwwww, poor baby...

Talk to me when you have routers all over the US failing due to the icmp flood created by nachi. Talk to me when you have over 22k workstations and desktop services is too stupid to automatically push a patch out. Talk to me when you have VPN/RAS users that use any POS machine they have at home connecting to your network and trying to re-infect everything you just spent a week trying to clean. Talk to me when half of your monitoring systems that rely on pings for basic connectivity testing are worthless because icmp echo/echo-reply is being dropped at every major distribution router in the network. Talk to me when b2b VPN's and GRE tunnels don't work because they use icmp type 3 and type 4 packets to establish connectivity and negotiate MTU size and someone denied ALL icmp packets in firewalls and routers. Talk to me after you've been on a 3 day conference call trying to contain that bullshit.

Anyone caught writing and distributing virii should have their hands shoved up their asses until you can see their fingers wriggling through their eye sockets. Try typing out your code then fucktards.
User avatar
Aabidano
Way too much time!
Way too much time!
Posts: 4861
Joined: July 19, 2002, 2:23 pm
Gender: Male
Location: Florida

Post by Aabidano »

We've got AV on the mail servers and the firewalls\proxy servers, and still got hit, though not badly.

Someone's got scripts running that looks for traffic indicating an infection, and shuts down the users port\VPN connection until they call the help desk :)

Using non-corporate resources to attach to our network is grounds for termination, and gets enforced.
"Life is what happens while you're making plans for later."
User avatar
Neost
Almost 1337
Almost 1337
Posts: 911
Joined: July 3, 2002, 1:56 pm
Gender: Male
XBL Gamertag: neost
Wii Friend Code: neost
Contact:

Post by Neost »

We only got hit by workstations. All of our windows based servers were patched.

We tried to get the vpn/ras policy changed to only allow company owned assets but then that would mean providing those assets to people. Someone thought it would save some money to allow Paul Pencilpusher to use their own home machine to work from home at night.

And once again, why in the hell could our desktop services group not get that patch pushed out via our software distribution channels? They oughta fire that whole group and start from scratch.
User avatar
Aabidano
Way too much time!
Way too much time!
Posts: 4861
Joined: July 19, 2002, 2:23 pm
Gender: Male
Location: Florida

Post by Aabidano »

Because SMS is such a convoluted PoS, and companies aren't smart enough to realize that you really need someone competent operate it. It can't be just your average Windoze admin dork. SMS is great if you've got someone really good running it, unfortunately I've only met 3-4 people that fell into that catagory. Require domain login and force the script on them at connect, it's pretty simple and straightforward.

I've succelfully avoided SMS pushes and the subsequent downtime for a couple years now. Of course I'm generally ahead of corporate IT on patches\updates, and screen all my traffic locally.
"Life is what happens while you're making plans for later."
User avatar
masteen
Super Poster!
Super Poster!
Posts: 8197
Joined: July 3, 2002, 12:40 pm
Gender: Mangina
Location: Florida
Contact:

Post by masteen »

The dipshits who did the SMS at my last company were the fucking dumbest motherfuckers. They'd be pushing DATs that were 2 revisions BEHIND what I was already running.
User avatar
Vaemas
Almost 1337
Almost 1337
Posts: 996
Joined: July 5, 2002, 6:23 pm
Gender: Male
XBL Gamertag: BeaverButter
Location: High Ministry of Accountancy

Post by Vaemas »

<--- small company employee, virus free! yeah baby!
High Chancellor for Single Malt Scotches, Accounting Stuffs and Biffin Greeting.
/tell Biffin 'sup bro!
User avatar
Bubba Grizz
Super Poster!
Super Poster!
Posts: 6121
Joined: July 3, 2002, 12:52 pm
Gender: Male
Location: Green Bay, Wisconsin

Post by Bubba Grizz »

Neost wrote:Awwwww, poor baby...

Talk to me when you have routers all over the US failing due to the icmp flood created by nachi. Talk to me when you have over 22k workstations and desktop services is too stupid to automatically push a patch out. Talk to me when you have VPN/RAS users that use any POS machine they have at home connecting to your network and trying to re-infect everything you just spent a week trying to clean. Talk to me when half of your monitoring systems that rely on pings for basic connectivity testing are worthless because icmp echo/echo-reply is being dropped at every major distribution router in the network. Talk to me when b2b VPN's and GRE tunnels don't work because they use icmp type 3 and type 4 packets to establish connectivity and negotiate MTU size and someone denied ALL icmp packets in firewalls and routers. Talk to me after you've been on a 3 day conference call trying to contain that bullshit.

Anyone caught writing and distributing virii should have their hands shoved up their asses until you can see their fingers wriggling through their eye sockets. Try typing out your code then fucktards.
Anyone else actually hear the octive in his voice go up gradually? Made me think of Chavez from Young Guns, "AND IT MEANS NOTHING TO ME?"
User avatar
Lalanae
Way too much time!
Way too much time!
Posts: 3309
Joined: September 25, 2002, 11:21 pm
Location: Texas
Contact:

Post by Lalanae »

perververted
Lalanae
Burundi High Chancellor for Tourism, Sodomy and Pie
Unofficial Canadian, Forbidden Lover of Pie, Jesus-Hatin'' Sodomite, President of KFC (Kyoukan Fan Club), hawt, perververted, intellectual submissive with E.S.P (Extra Sexual Persuasion)
CobsTheWarlord
No Stars!
Posts: 46
Joined: July 16, 2002, 7:46 am

Spyware

Post by CobsTheWarlord »

Just on a note i thought i would tell everyone that you should run a spyware remover. go to download.com and type in spyware find a spyware removed and download it.

spyware tells people when you are online and they try to upload things onto your computer. This is the main way things like the blaster worm which is still going around are put onto your computer. Im running the scanner right now and i have found over 1,000 spyware componets on my computer and its still climbing.
User avatar
Sargeras
Way too much time!
Way too much time!
Posts: 1604
Joined: July 3, 2002, 2:35 pm
Location: Mental Insanity of Life

Post by Sargeras »

I run Ad-aware every week :P
User avatar
Canelek
Super Poster!
Super Poster!
Posts: 9380
Joined: July 3, 2002, 1:23 pm
Gender: Male
XBL Gamertag: Canelek
Location: Portland, OR

Post by Canelek »

And don't forget ALL the times he sold DOPE disguised as a NUN.
en kærlighed småkager
User avatar
Marbus
Way too much time!
Way too much time!
Posts: 2378
Joined: July 4, 2002, 2:21 am
Contact:

Post by Marbus »

We blocked it on RAS/VPN and all the servers were patched so we didn't have any problems at all. Neo let me know if you hear of any mgt jobs and maybe I'll come help ya out :razz:

Marb
User avatar
Animalor
Super Poster!
Super Poster!
Posts: 5902
Joined: July 8, 2002, 12:03 pm
Gender: Male
XBL Gamertag: Anirask
PSN ID: Anirask
Location: Canada

Post by Animalor »

I'm still in the process of tracking down more people that are infected with Sobig and have people from my office on their mailing lists.

The suckiest part is that sobig infected messages are being picked up by our server-side anti-spam filters and I have 3x more shit to filter through to find potential false positives.

Tracking times between then a message was received and the time it came in on a SMTP log is not a fun task =(
Pilsburry
Way too much time!
Way too much time!
Posts: 1306
Joined: July 26, 2002, 4:48 pm
Location: Cincinnati, OH
Contact:

Post by Pilsburry »

Dude did you think end users would run anti-virus?

They wouldn't even run that if you sent them an e-mail in bold red letters that said "click me".

Trust me I hear techs complain about stuff like that all the time. When I worked in the office it was so small I just did it all myself "trust noone" was my motto.
-retired-
User avatar
Canelek
Super Poster!
Super Poster!
Posts: 9380
Joined: July 3, 2002, 1:23 pm
Gender: Male
XBL Gamertag: Canelek
Location: Portland, OR

Post by Canelek »

We have Antigen on our servers, but lots of email spam gets through(with disabled viruses). After 3 hours of playing EQ tonight, I got 100+ messages to the webmaster@valleycrest.com address from some pseudo-antivirus addy... I want to beat them to death with a clawhammer for wasting my time! :)
en kærlighed småkager
User avatar
masteen
Super Poster!
Super Poster!
Posts: 8197
Joined: July 3, 2002, 12:40 pm
Gender: Mangina
Location: Florida
Contact:

Post by masteen »

Canelek wrote:And don't forget ALL the times he sold DOPE disguised as a NUN.
I just glad SOMEBODY caught the reference.
User avatar
Krimson Klaw
Way too much time!
Way too much time!
Posts: 1976
Joined: July 22, 2002, 1:00 pm

Post by Krimson Klaw »

Bubba Grizz wrote:
Neost wrote:Awwwww, poor baby...

Talk to me when you have routers all over the US failing due to the icmp flood created by nachi. Talk to me when you have over 22k workstations and desktop services is too stupid to automatically push a patch out. Talk to me when you have VPN/RAS users that use any POS machine they have at home connecting to your network and trying to re-infect everything you just spent a week trying to clean. Talk to me when half of your monitoring systems that rely on pings for basic connectivity testing are worthless because icmp echo/echo-reply is being dropped at every major distribution router in the network. Talk to me when b2b VPN's and GRE tunnels don't work because they use icmp type 3 and type 4 packets to establish connectivity and negotiate MTU size and someone denied ALL icmp packets in firewalls and routers. Talk to me after you've been on a 3 day conference call trying to contain that bullshit.

Anyone caught writing and distributing virii should have their hands shoved up their asses until you can see their fingers wriggling through their eye sockets. Try typing out your code then fucktards.
Anyone else actually hear the octive in his voice go up gradually? Made me think of Chavez from Young Guns, "AND IT MEANS NOTHING TO ME?"
ROFL
User avatar
Canelek
Super Poster!
Super Poster!
Posts: 9380
Joined: July 3, 2002, 1:23 pm
Gender: Male
XBL Gamertag: Canelek
Location: Portland, OR

Post by Canelek »

masteen wrote:
Canelek wrote:And don't forget ALL the times he sold DOPE disguised as a NUN.
I just glad SOMEBODY caught the reference.

HANGIN'S TOO GOOD FOR HIM. BURININS TO GOOD FOR HIM! HE SHOULD BE TORN INTO ITSY PIECES AND BURIED ALIVEEEEEE. I'LL KEEL IMMM RAWR!
en kærlighed småkager
User avatar
Akaran_D
Way too much time!
Way too much time!
Posts: 4151
Joined: July 3, 2002, 2:38 pm
Location: Somewhere in my head...
Contact:

Post by Akaran_D »

The idiots in charge of the WVUP computer labs JUST YESTERDAY lost one entire lab (30? computers) and a partial loss on a second one (another 6).

Would have been different IF they had lost them when the worms really hit. They lost them what.. two? weeks after the instructions on how to prevent them and kill them became mainstream.

Farking idiots.
Akaran of Mistmoore, formerly Akaran of Veeshan
I know I'm good at what I do, but I know I'm not the best.
But I guess that on the other hand, I could be like the rest.
User avatar
Neost
Almost 1337
Almost 1337
Posts: 911
Joined: July 3, 2002, 1:56 pm
Gender: Male
XBL Gamertag: neost
Wii Friend Code: neost
Contact:

Post by Neost »

They arrested some 18 year old, 6'4" 320 lb asshole in St. Paul, MN and are charging that he is the person who released MSBlaster or Nachi.

If he's the one, I hope they fry his balls on a 2.4 ghz P4 overclocked to the max.
Post Reply