Go Back   Professional Soldiers ® > Technical FAQ Forum > Technology News and Reviews

Reply
 
Thread Tools Display Modes
Old 08-19-2005, 09:48   #1
BMT (RIP)
Quiet Professional
 
BMT (RIP)'s Avatar
 
Join Date: Jan 2004
Location: Red State
Posts: 3,774
US Customs 'Puters

http://apnews.myway.com/article/20050819/D8C2RE000.html

WTF disabled NORTON AV???

BMT
__________________
Don't mess with old farts...age and treachery will always overcome youth and skill! Bullshit and brilliance only come with age and experience.
BMT (RIP) is offline   Reply With Quote
Old 08-19-2005, 10:02   #2
fusion94
Asset
 
Join Date: Jun 2005
Location: El Granada, CA
Posts: 35
Well it would appear (just based on what the article states) that the US Customs is using Microsoft SQL Server and got hit with one of the many worms that it's vulnerable to. In today's day and age I really don't understand why so many Government systems are as insecure as they are.

From my firewall logs as of a few minutes ago:

Quote:
Date: 08/19 01:42:11 Name: MS-SQL Worm propagation attempt
Priority: 2 Type: Misc Attack
IP info: 219.129.139.187:4373 -> 24.0.76.5:1434

Date: 08/19 03:40:15 Name: MS-SQL Worm propagation attempt
Priority: 2 Type: Misc Attack
IP info: 219.145.169.136:3047 -> 24.0.76.5:1434
fusion94 is offline   Reply With Quote
Old 08-19-2005, 10:05   #3
Dan
Administrators
 
Dan's Avatar
 
Join Date: Feb 2004
Location: Fayetteville, NC
Posts: 2,264
They most likely got hit with a ZOTOB worm variant and the travelers had to pay the stupid tax for them because they didt keep their OS up to date.
Dan is offline   Reply With Quote
Old 08-19-2005, 10:24   #4
fusion94
Asset
 
Join Date: Jun 2005
Location: El Granada, CA
Posts: 35
Well Zotob spreads by exploiting the Microsoft Windows Plug and Play Buffer Overflow Vulnerability and AFAIK only affects Windows 2000 servers. I can more or less understand why they use Windows 2000 and MS SQL even though I wouldn't. What I don't understand is why any Windows 2000 server would have the PnP service turned on. That's just shoddy administration IMO.
fusion94 is offline   Reply With Quote
Old 08-19-2005, 10:29   #5
Dan
Administrators
 
Dan's Avatar
 
Join Date: Feb 2004
Location: Fayetteville, NC
Posts: 2,264
Quote:
Originally Posted by fusion94
That's just shoddy administration IMO.
Exactly...they don't know enough to not keep it turned off or keep their OS's up to date in general. They aren't alone...look at the 250,000+ reported systems that were effected by this worm. CNN and ABC news servers were taken down early on just to name some other big name folks that got nailed.
Dan is offline   Reply With Quote
Old 08-19-2005, 10:38   #6
fusion94
Asset
 
Join Date: Jun 2005
Location: El Granada, CA
Posts: 35
Roger that Dan.

I was wrong, it CAN affect XP and Windows Server 2003 as well if this variable has been set in the registry:

HKLM\System\CurrentControlSet\Control\LSA\Restrict AnonymousSam = 0

or

HKLM\System\CurrentControlSet\Control\LSA\Restrict Anonymous = 0

DWORD value needs to be set to 1 to restrict anonymous access.
fusion94 is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump



All times are GMT -6. The time now is 07:54.



Copyright 2004-2022 by Professional Soldiers ®
Site Designed, Maintained, & Hosted by Hilliker Technologies