Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Zotob Worm strikes CNN, ABC, other news orgs (no link)

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Latest Breaking News Donate to DU
 
AlGore-08.com Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-16-05 04:49 PM
Original message
Zotob Worm strikes CNN, ABC, other news orgs (no link)
Heard on CNN's Wolf-Blitzer-a-thon, no links yet.

Article on the Zotob Worm:

http://www.entmag.com/news/article.asp?EditorialsID=6864
Printer Friendly | Permalink |  | Top
Janice325 Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-16-05 04:52 PM
Response to Original message
1. I'm wondering how much this will effect those of us on the internet.
Edited on Tue Aug-16-05 04:55 PM by Janice325
Like DU, DailyKos, things relating to Cindy, etc.
That would be an effective way to shut many of us down.
Oh, great. I'm listening to CNN and a woman just said the FBI isn't aware of anything happening in the last 24 hours. Whoopie doo.
Printer Friendly | Permalink |  | Top
 
AlGore-08.com Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-16-05 04:55 PM
Response to Reply #1
2. Depends on the servers - - Zotob strikes Windows 2000, not later versions
So if the site is run off a server using Windows 2000, it is vulnerable unless the system administrators use a patch Microsoft issued Friday - - if the patch part is wrong, please correct me, DU computer geek gods... :)
Printer Friendly | Permalink |  | Top
 
bpilgrim Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-16-05 05:55 PM
Response to Reply #2
32. MS: How to Recover from Infection ---------- ------------ > LINK
Edited on Tue Aug-16-05 06:05 PM by bpilgrim
http://www.microsoft.com/security/encyclopedia/details.aspx?name=Worm:Win32/Zotob.A#Recovery

Symantec offers a free detection/deletion tool that takes care of the Zotob.a and Zotob.b variants. It can be downloaded from the vendor's Web site.
http://securityresponse.symantec.com/avcenter/venc/data/w32.zotob.removal.tool.html

peace
Printer Friendly | Permalink |  | Top
 
JanusAscending Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-16-05 04:55 PM
Response to Original message
3.  WORM~~~
Edited on Tue Aug-16-05 04:57 PM by discerning christian
I was just watching CNN, and now ABC computers using windows 2000 are infected. They say it's not affecting emergency networks YET! Could this have something to do with silencing cyberspace because of the "WAR GAMES" coming up tomorrow? :nuke:
Printer Friendly | Permalink |  | Top
 
Old Vet Donating Member (618 posts) Send PM | Profile | Ignore Tue Aug-16-05 04:58 PM
Response to Reply #3
4. Affects 2000 And XP Platforms per Cnn
Printer Friendly | Permalink |  | Top
 
JanusAscending Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-16-05 05:07 PM
Response to Reply #4
7. Hey, Old Vet!!
I'm old too, so what you said means "nada" to me. I'm a "little computer illiterate!!! I can work my way around well enough tho', and am thankful that I have windows 98 !!! So.......what does this mean?:shrug:
Printer Friendly | Permalink |  | Top
 
ChairmanAgnostic Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-16-05 05:05 PM
Response to Reply #3
6. ! ! ! ! ! ! ! ! ! !
Thanks for the reminder, just as I was relaxing.
But, damn. it makes sense.

lull everyone into a stupor, lower the warning color alert level, then concoct something absolutely vile.

Printer Friendly | Permalink |  | Top
 
JanusAscending Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-16-05 05:26 PM
Response to Reply #6
16. Deja Vu!!!!!
I don't know if any of you on line now read my post the other day about my ESP, or gift of "discernment" Damn it!! I just know things sometimes before they happen. Well I've been feeling strongly lately that "something BIG" was getting ready to happen. I've warned all my kids, that I wasn't sure yet whether it was going to be good or bad, but the feeling I'm getting right this very minute is DUCK AND COVER!!!! I hate to Alarm anyone, but when I read the post #11 from Tahiti nut, I experienced Deja Vu, like this has all happened before! So whether or not you doubt my sanity, please be very diligent!! If I'm wrong, you can all cuss me out later, but I'm usually right.:grouphug:
Printer Friendly | Permalink |  | Top
 
ChairmanAgnostic Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-16-05 05:53 PM
Response to Reply #16
31. oh pleeze oh pleeze oh pleeze be wrong.
pretty please, with cane sugar on top.
Printer Friendly | Permalink |  | Top
 
Mistress Quickly Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-16-05 05:14 PM
Response to Reply #3
12. There's war games tomorrow?
I am so out of the loop.
Printer Friendly | Permalink |  | Top
 
katty Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-16-05 06:05 PM
Response to Reply #12
34. yup, war games tomorrow-closed to media and public
Printer Friendly | Permalink |  | Top
 
tridim Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-16-05 05:03 PM
Response to Original message
5. Someone check the AAR streaming servers.
Printer Friendly | Permalink |  | Top
 
Old Vet Donating Member (618 posts) Send PM | Profile | Ignore Tue Aug-16-05 05:07 PM
Response to Reply #5
8. This is NOT zotab, This is NEW worm
Printer Friendly | Permalink |  | Top
 
KTM Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-16-05 07:34 PM
Response to Reply #8
36. Regardless
Zotob and Esbot are both explioting the same flaw.. patch against it, follow the instructions from SARC to see if you have it (and disable it if you do) and you'll be fine.
Printer Friendly | Permalink |  | Top
 
Karla Marx Donating Member (85 posts) Send PM | Profile | Ignore Tue Aug-16-05 05:31 PM
Response to Reply #5
20. I couldn't get AAR to stream at all after 3 pm...
...thought it was my shitty PC at work. Tomorrow I bring a radio.
CNN is doing a story on the worm right now. Navel-gazing, anyone?
Printer Friendly | Permalink |  | Top
 
Enraged_Ape Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-16-05 05:08 PM
Response to Original message
9. Zotob knocked at my firewall today
But I guess since I have the latest McAfee personal firewall and Win98 SE, it decided to move on.
Printer Friendly | Permalink |  | Top
 
JanusAscending Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-16-05 05:12 PM
Response to Reply #9
10. Same here!!
Thank God I just installed the newest from McAffe as well!
Printer Friendly | Permalink |  | Top
 
Enraged_Ape Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-16-05 05:37 PM
Response to Reply #10
23. McAfee's great
I didn't realize how many "unwelcome visitors" I got until I installed the McAfee firewall! Almost every day someone comes knocking at my door. Pretty scary.
Printer Friendly | Permalink |  | Top
 
VegasWolf Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-16-05 05:40 PM
Response to Reply #23
25. Right, I use the Norton Firewall, I would never use the little Windows
firewall.
Printer Friendly | Permalink |  | Top
 
TahitiNut Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-16-05 05:17 PM
Response to Reply #9
13. I've been getting a LOT of UDP probes on ports 1026 and 1027
Edited on Tue Aug-16-05 05:19 PM by TahitiNut
Only a few of this kind ...
2005/08/16 6:08:42 PM GMT -0400: 3Com EtherLink 10..[0002][No
matching rule] Blocking incoming TCP: src=69.14.159.117,
dst=69.14.***.***, sport=1233, dport=445.

Port 445 is apparently its propagation vector.
Printer Friendly | Permalink |  | Top
 
VegasWolf Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-16-05 05:37 PM
Response to Reply #13
22. On 1026-1030 ....
Edited on Tue Aug-16-05 05:41 PM by VegasWolf
That's just the FBI. Teasing.

:spank:
:toast:
Printer Friendly | Permalink |  | Top
 
TahitiNut Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-16-05 05:13 PM
Response to Original message
11. It's another one that exploits buffer overflow. (sigh)
As a systems programmer (operating systems and systems software) of over 35 years, I can't even begin to express my disgust for the state of the software "art." :puke:
Printer Friendly | Permalink |  | Top
 
VegasWolf Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-16-05 05:17 PM
Response to Original message
14. My XP just updated itself and all is fine.... Wait, I'm ggettiinngg
Edited on Tue Aug-16-05 05:18 PM by VegasWolf
ffuunnyy ggrreeeennn llllighhhtttss, awwwwwww nnnoooooooooooo!

O8)
Printer Friendly | Permalink |  | Top
 
Old Vet Donating Member (618 posts) Send PM | Profile | Ignore Tue Aug-16-05 05:26 PM
Response to Reply #14
15. Talking to friends in Germany and its a real pain in the ass........
Seems if your puter gets affected you have to download patch on cd and boot up, What a Drag. I want what Vegaswolf is smoking!:toast:
Printer Friendly | Permalink |  | Top
 
htuttle Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-16-05 05:26 PM
Response to Original message
17. Hey, there's no ticker at the bottom of the screen!
Not on CNN nor CNN Headline News.

Guess the virus ate it.

:shrug:

Printer Friendly | Permalink |  | Top
 
ElsewheresDaughter Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-16-05 05:29 PM
Response to Reply #17
19. is it effecting just the cable news networks? faux news has the tickertape
Edited on Tue Aug-16-05 05:31 PM by ElsewheresDaughter
crawling across the bottom but niether CNN nor MSNBC does :shrug:
Printer Friendly | Permalink |  | Top
 
Career Prole Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-16-05 05:27 PM
Response to Original message
18. Just got this "Breaking News" e-mail from CNN
"A worm shut down computers running Windows 2000 software across the United States."

That was it...
Printer Friendly | Permalink |  | Top
 
stepnw1f Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-16-05 05:34 PM
Response to Original message
21. Gotta Love my Mac OSX
Then again I do have to worry about my PC at work.
Printer Friendly | Permalink |  | Top
 
Applepie Donating Member (143 posts) Send PM | Profile | Ignore Tue Aug-16-05 05:43 PM
Response to Reply #21
27. I'm with you
Mac for me too
Printer Friendly | Permalink |  | Top
 
bpilgrim Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-16-05 05:45 PM
Response to Reply #21
28. MS05-039 Worm in the Wild - Slashdot
Printer Friendly | Permalink |  | Top
 
Brundle_Fly Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-16-05 05:53 PM
Response to Reply #21
30. I am a solo mac in a
frenzy of PC's here at the office. I am certainly not feeling the dread the others here are.

fyi Tiger Users

Now available via Software Update:
Security Update 2005-007 delivers a number of security enhancements and is recommended for all Macintosh users. This update includes the following components:

AppKit
BlueTooth
CoreFoundation
cups
Directory Services
HIToolBox
Kerberos
loginwindow
Mail
OpenSSL
QuartzComposerScreenSaver
Security Interface
Safari
X11
zlib

For detailed information on this Update, please visit this website: http://www.info.apple.com/kbnum/n61798
Printer Friendly | Permalink |  | Top
 
boredofeducation Donating Member (194 posts) Send PM | Profile | Ignore Tue Aug-16-05 10:47 PM
Response to Reply #21
37. Gotta love my Commodore 64
The best darn platform ever! Virus Free! I love my commodore!
Printer Friendly | Permalink |  | Top
 
DeepModem Mom Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-16-05 05:38 PM
Response to Original message
24. Think CNN's now saying it may not be Zotob. nt
Printer Friendly | Permalink |  | Top
 
nadinbrzezinski Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-16-05 05:43 PM
Response to Original message
26. folks call this a very sneaky suspicion but this
Edited on Tue Aug-16-05 05:43 PM by nadinbrzezinski
has all the elements of a successful cyber attack

WOOHOO... who said DHS was gonna work on this?
Printer Friendly | Permalink |  | Top
 
Mr.Green93 Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-16-05 05:49 PM
Response to Original message
29. Wasn't there an outbreak before 9/11?
I'm going to get some duct tape.
Printer Friendly | Permalink |  | Top
 
VegasWolf Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-16-05 05:56 PM
Response to Original message
33. Good news!! All of the Porn servers are up and well! nt
Printer Friendly | Permalink |  | Top
 
KTM Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-16-05 06:34 PM
Response to Original message
35. Stop the panic & FUD !!
Edited on Tue Aug-16-05 06:36 PM by KTM
I've got a stylish collection of tin hats, but I'm not donning one for this.

It's just a worm. Actually, several variations of the same one, which is usually what happens when someone exploits a flaw that was just recently announced - it's almost always followed by rapid variants. In this case, the flaw and patch were just issued on the 8th & 9th, and the riff-raff beat most users to the punch. This was predicted by the experts the day the flaw was announced.


Reliable info on the worm, it's variants, Norton/Symantec virus definitinions, how to tell if you have it, and later version removal tools at Symantec (SARC)

Patch your PC against this exploit: (Win2K) and (WinXP)

Does not effect Microsoft Windows 98, Microsoft Windows 98 Second Edition (SE), and Microsoft Windows Millennium Edition (ME).

More info on vulnerability at Symantec and Microsoft

Removal tool from Symantec for first two variants of Zotob here.

None available yet for Esbot.
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Thu Apr 25th 2024, 04:01 PM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Latest Breaking News Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC