PDA

View Full Version : Je Suis Screwed.



Ben
October 27th, 2002, 02:59
OK, i go to watch Analyze This, and I leave my computer online, WITH my firewall software running. When I get back I see this window that says "Messenger Service" and is advertising all kinds of stuff. The only background services running, and I have checked, are my antivirus, mozilla loader, and my firewall software. I have a feeling someone "net send"ed me, but how it got through my firewall I have yet to find out. WHAT HAPPENED?

Check this screencapture.

Coolin
October 27th, 2002, 03:01
What firewall software do you use?

Jan
October 27th, 2002, 03:03
It seems to be some form of spam :mad:

http://www.geekvillage.com/forums/showthread.php?s=&threadid=19019

Ben
October 27th, 2002, 03:08
Originally posted by Coolin
What firewall software do you use?
Agnitum Outpost....i'll have to check the logs...

[add]
Odd.....it shows no record of the event

xsnetwork
October 27th, 2002, 06:22
They are sent via a windows command : net send, it's easy enough to do, all that it requires is for the target computer to have the messenger service installed and it will send a message. Try it yourself, open a dos prompt and type in net send 127.0.0.1 _Your_Message_here_ :)

Akalon
October 27th, 2002, 07:37
I think Ben is aware of net send but the question is how did it pass his firewall.

Jan
October 27th, 2002, 07:40
It is just a new version of a popup ad :confused2

http://www.usatoday.com/tech/news/2002-10-21-pop-up-spam_x.htm

xsnetwork
October 27th, 2002, 07:56
After replying to this I got one :mad:

I don't think a firewall would pick it up as it is a part of the messenger service so if the messenger service is allowed to recieve connections from the internet they can be recieved.

Bruce
October 27th, 2002, 08:00
Originally posted by Akalon
I think Ben is aware of net send but the question is how did it pass his firewall. Net send isn't blocked by [most] firewalls.

The only solution is to disable the Microsoft Messenger Service. You don't need it if you have broadband anyway.

Dean
October 27th, 2002, 15:17
Easier way...
NOTE: REMOVE '.TXT' to run the batch