823559: Security Update for Microsoft Windows
Okay, I've looked everywhere for an answer, but I just
can't find it. Everytime I come to Windows update, this
patch is listed as critical. But I've already installed it
8 times since it was realeased. Does anyone know why it's
still listed? Tag: FWD: Apply this corrective package Tag: 38970
** READ THIS BEFORE POSTING - answers to frequently asked questions 2003.11.03
Before you post a question to a Microsoft.public.*.security newsgroup, note
that your question may already be answered below:
Answers to Top Frequently Asked Questions:
http://securityadmin.info
My question is not mentioned below. How do I get an answer immediately,
with no waiting?
http://securityadmin.info/faq.htm#moreinfo
See also: http://www.google.com/groups?as_ugroup=microsoft.public.*
See also: http://www.google.com/advanced_group_search
See also: http://www.google.com
I want to post a problem or question to the newsgroup. What info do I need
to post in order to get a correct answer quickly?
http://securityadmin.info/faq.htm#netiquette
I just heard about a new Microsoft security patch update. Where can I get
the patch?
http://windowsupdate.microsoft.com OR
http://www.microsoft.com/technet/security/current.asp
I just installed a Microsoft security patch update, and now my computer is
having problems.
http://securityadmin.info/faq.htm#patchbroke
I received an email from Microsoft / Microsoft Support / Microsoft Internet
Security Center claiming to be a security patch [or comprehensive Internet
Explorer update]. Is this a virus?
http://securityadmin.info/faq.htm#microsoftemail
ALSO NOTE: www.grisoft.com is free antivirus, USE IT.
I received a virus email from a Microsoft email address. Who do I report
this to?
http://securityadmin.info/faq.htm#microsoftemail
I have the RPC Blaster worm "virus," what do I do?
http://www.microsoft.com/security/incident/blast.asp
ALSO NOTE: www.grisoft.com is free antivirus, USE IT.
My computer is giving RPC Remote Procedure Call messages.
There is a TFTP message or file on my computer.
My computer keeps locking up, and/or rebooting, or telling me that it will
reboot in 1 minute.
http://www.microsoft.com/security/incident/blast.asp
ALSO NOTE: www.grisoft.com is free antivirus, USE IT.
Where can I download the Blaster worm / RPC DCOM patch?
http://windowsupdate.microsoft.com OR
http://www.microsoft.com/technet/security/current.asp
I'm having a problem caused by the JDBGMGR.EXE Teddy Bear "virus" hoax, or I
want to replace this file.
http://securityadmin.info/faq.htm#jdbgmgr
I forgot my Windows logon password and can't log in. How do I reset it?
http://securityadmin.info/faq.htm#password
I have a problem or a question with a virus or with antivirus.
http://securityadmin.info/faq.htm#virus
NOTE: www.grisoft.com is free antivirus, USE IT.
Why is Outlook Express blocking my attachments as "unsafe"?
http://securityadmin.info/faq.htm#attachments
How do I stop getting pop-up messages? Or adware? Or spyware?
http://securityadmin.info/faq.htm#pop-ups
How do I block people from viewing adult or objectionable content on a
computer?
http://securityadmin.info/faq.htm#contentfilter
How do I block spam emails?
http://securityadmin.info/faq.htm#spam
There is a Content Advisor password blocking me from certain web sites.
http://securityadmin.info/faq.htm#contentadvisor
How do I delete an FTP folder that a hacker put on my computer and I cannot
delete?
http://securityadmin.info/faq.htm#ftpfolder
Have I been hacked? What do I do if I've been hacked?
http://securityadmin.info/faq.htm#hacked
How do I re-secure a computer that has been hacked?
http://securityadmin.info/faq.htm#re-secure
How do I test or improve the security on my computer to avoid being hacked?
http://securityadmin.info/faq.htm#harden
How do I investigate a suspicious IP address that may be trying to hack me?
http://securityadmin.info/faq.htm#trace
How do I report a hacker?
http://securityadmin.info/faq.htm#reporthacker
How do I use a port scanner or vulnerability scanner to test my security?
http://securityadmin.info/faq.htm#portscanner
How do I encrypt my files and/or hard drive?
http://securityadmin.info/faq.htm#encryption
How do I get a firewall? IDS?
http://securityadmin.info/faq.htm#firewall
I want to use the IPSec filtering or IP filtering feature of Windows to
block certain ports and have a problem or question.
http://securityadmin.info/faq.htm#ipsec
I have a problem or question with the XP ICF firewall.
http://securityadmin.info/faq.htm#icf
I have a problem or question with the IIS URLScan tool.
http://securityadmin.info/faq.htm#urlscan
How do I change the banner on my computer or server to hide what software
version I'm using?
http://securityadmin.info/faq.htm#banner
How do I enable Windows Auditing to tell who logged into Windows or who
accessed a file?
http://securityadmin.info/faq.htm#auditing
How do I inspect and disable programs that start up when Windows starts?
http://securityadmin.info/faq.htm#startup
How do I use RUNAS or let someone use RUNAS to run commands as administrator
without having to type the password?
http://securityadmin.info/faq.htm#runas
How do I let non-administrator users run Defrag or change their IP address?
http://securityadmin.info/faq.htm#runas
My question is not mentioned above. How do I get an answer immediately,
with no waiting?
http://securityadmin.info/faq.htm#moreinfo
See also: http://www.google.com/groups?as_ugroup=microsoft.public.*
See also: http://www.google.com/advanced_group_search
See also: http://www.google.com
I want to post a problem or question to the newsgroup. What info do I need
to post in order to get a correct answer quickly?
http://securityadmin.info/faq.htm#netiquette
Note that this is NOT a full list of all the questions answered in the FAQ.
Chances are, your question has probably already been answered. The complete
FAQ is at:
http://securityadmin.info/faq.htm#contents
I hope this is helpful. Feedback, suggestions and criticism regarding the
FAQ are welcome and may be emailed to me.
kind regards,
Karl Levinson, CISSP, MCSE, MVP
email: levinson_k@despammed.com Tag: FWD: Apply this corrective package Tag: 38967
Content Advisor
Does anyone know how to get a new password if you forgot
your old one in ME Content Advisor?
Thanks Tag: FWD: Apply this corrective package Tag: 38959
lsass.exe
every time I connect to the internet, my firewall software
warns me that lsass.exe is trying to access the internet.
I've been blocking access each time. What is it trying to
do, why, and do I have to block it? Tag: FWD: Apply this corrective package Tag: 38952
monitoring
i have played on zone bridge, with mostly same partner
for last year. today my partner gets message when we
start to play that i am being monitored for something.
how this come about, and how do i find out what going
on/??? Tag: FWD: Apply this corrective package Tag: 38951
KB 826939
Dear Microsoft,
Your recent update as mentioned in my subject is causing
full screen application issues with the mouse. If you
point to something like in a game , it drops to the
desktop with the application minimized. You cant click on
anything in an application. Tag: FWD: Apply this corrective package Tag: 38949
pop ups
HI i just started my online service and i keep getting
this windows service pop up that is on a gray screen and
i get a message saying that if i get this kind of
messages my ip address is leaking please help Tag: FWD: Apply this corrective package Tag: 38941
HELP!!!
Please can someone help, i was trying to access my
hotmail account and for some reason it will not let me in
and i cant even go through the process of trying to reset
it as, it tells me the information provided is wrong.
Does anyone know or have a contact number for Microsoft
as i cant seem to find one.
Thanks
Ramzan Tag: FWD: Apply this corrective package Tag: 38927
Security Log
Hi, people. I have found the following message in the
Event Viewer:
Logon Failure:
Reason: Unknown user name or bad password
User Name: user1
Domain: MYDOMAIN
Logon Type: 3
Logon Process: KSecDD
Authentication Package:
MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Workstation Name: \\VAIO
It seems that someone is trying to gain access to my
computer, right? But the question is: from where? I have
stopped the WWW Publishing service but this server is
running Exchange. I have one attack every 5 seconds, for
about 2 hours in the early morning.
Any help?
Thanks,
JK Tag: FWD: Apply this corrective package Tag: 38921
Files Being Deleted
I have some excel files that one of my users keeps
deleting from a shared folder on the network. Problem is
that I have 200 users and do not know who is doing it. Is
there an event log that I could view to see who is
deleting files from a server? Any help would be excellent.
Server is running Windows 2000 SP4.
lou Tag: FWD: Apply this corrective package Tag: 38920
It is not the *IN* thing to do.
Replying to Tracker is not the *IN* thing to
do. But you trolls allready knew that right?
--
BuZZard
mhm33x29
news:alt.fan.sharon-osbourne
news:alt.buzzard.rules
news:alt.binaries.buzzard
If your news server doesn't carry these groups,
email them and request that they do.
(º·.¸(¨*·.¸ ¸.·*¨)¸.·º)
«.·°·. BuZz .·°·.»
(¸.·º(¸.·¨* *¨·.¸)º·.¸)
http://www.buzzardnest.com/ Tag: FWD: Apply this corrective package Tag: 38896
823559: Security Update for Microsoft Windows
I have Windows Critial Update program activated. I have
been advised that 823559: Security Update for Microsoft
Windows is available and can be downloaded. I have
downloaded and installed this file 15 times. Again this
morning I was advised to install the update. Any idea why
this file is not installing or why I am reminded again to
install it. Thanks for any assistance.
Dave Tag: FWD: Apply this corrective package Tag: 38885
Disabling IE Downlaods using an Active Directory GPO
Hi,
Is it possilbe to use AD to disable the abiable users
ability to download files form the internet. There is a
option in IE to disable downloads. But I cant see where I
can set this in my "Group Policy Object"
Any ideas folks??????
G Tag: FWD: Apply this corrective package Tag: 38879
email from "microsoft"
I am get an email from "microsoft" that I do not open
because the suject is USE THIS PATCH IMMEDIATELY.
Is this email really from Microsoft? They keep sending
after I erease it, so they know that I have not used it.
If it a patch that I need, I want to use it!
Does anyone know what is happening with this "patch" email?
Thanks,
Sam Tag: FWD: Apply this corrective package Tag: 38876
Block Copy
Hi all,
There's some way to block some user when he try to copy a
larger amount of data from the network to his own PC ??
Any suggestion ??
Thanks. Guido Tag: FWD: Apply this corrective package Tag: 38871
SVCHOST.EXE
Sygate Pro (firwall) has started telling me that SVCHOST.
EXE is trying to broadcast to 239.255.255.250 using port
1900. Using XP Pro.
I have googled for info on SVCHOST.EXE and read the MS
posting, but no mention of this "problem".
239.255.255.250 is Internet Assigned Names Authority.
Should I allow access? Any security issues here at all?
T.I.A. Tag: FWD: Apply this corrective package Tag: 38868
Cannot load ssl pages
Hi,
I haven't had this before, a customer cannot open SSL
pages ie https:// using ie6 encr 128 on WinXP Pro. Also
cannot access Windows Messenger. All worked OK before?
Can anyone help please.
Options Advanced have all been set to accepr ssl 2.0 3.0
etc
Cheers
Geoff Tag: FWD: Apply this corrective package Tag: 38866
pb with MS03-043
I am using a VBS script to retrieve information from the
Active Directory.
After the installation of the security patch MS03-043 on
my NT 4.0 workstation, the following command does not work
anymore.
Set User=GetObject("WinNT://" & UserDomain & "/" &
UserName & ",user")
Error # = 800708AD
Any Idea ?
I replaced the netapi32.dll from MS03-043 with the
previous one and it works fine.
I know that Microsoft has revised a version of the
security patch for Windows 2000, Windows XP, and Windows
Server 2003 to correct the issue documented by Knowledge
Base Article 830846.
There is not revised version for Windows NT 4.0
Workstation.
Regards
Stephane. Tag: FWD: Apply this corrective package Tag: 38864
Why do you waste your time canceling my accounts?
Why do so many of you waste your time canceling my accounts unless the
information which is posted by me on Usenet is inaccurate and
misinforming? You do this because you know this babe is here to help
the innocent victims. Everyone knows how to avoid spammers and even
if you claim my posts as spam you still try to hurt the innocent
victims. Why is that? You can't keep this babe from posting and you
know that. I'm a hacker and I know so many of your malicious
activities and you hate me. Continue to hate me for 10 or 20 years
because this babe will never go away, nor will I back down.
Usenet is a small part of the Internet, try Yahoo, Message Boards and
IRC Servers to have fun on.
Tracker Tag: FWD: Apply this corrective package Tag: 38856
MAKING YOUR COMPUTER SYSTEM SECURE AFTER IT'S BEEN COMPROMISED
Copyright 2003 by Debbie X. All rights Reserved. No part of this
publication may be reproduced in any form or by any means, or stored
in a data base or retrieval system, without prior written permission
of the publisher. You may pass along this information, but give
credit where credit is due.
MAKING YOUR COMPUTER SYSTEM SECURE AFTER IT'S BEEN COMPROMISED:
I highly recommend keeping the hacked hard drive and purchasing a new
one. Of course you could mirror the drive, but you still need a
replacement drive to perform this task. You can't produce the same
results by replicating files versus viewing the actual hard drive
itself. If your system was used to attack and crash a Network, or
System, you have proof for the FBI or any Law Enforcement Agency.
This would show you were not involved in any illegal activities until
you discovered your system was hacked.
The proper method is to re-format your hard drive, and install from
original CD-ROM. To safe guard against software manufacturer employee
malicious activity always virus check your CD-ROM. Not too long ago,
I decided to install X Software Application on a computer, media form
was a CD-ROM. Immediately, Norton Anti-virus told me a suspicious
file named "install.exe" was trying to load into my hard drive boot
sector. We all know an application doesn't need to load in a boot
sector of a drive. After telling the computer not to install this
application, it still made it's way and changed the name of my hard
drive. The computer access slowed down, while viewing directories the
screen started to move back and forth.
Virus check all floppy disks because hackers DO install a Backdoor,
Trojan Horse, or Virus on disks. They enjoy doing this especially
when you're online using your computer, with a floppy in the drive.
My preference is to obtain a replacement CD-ROM if your software
applications are on a floppy. What concerned me most is a Backdoor
was planted in a .zip file and unopened. Norton's Anti-virus
application couldn't detect it. Let's one day you come along and for
no reason, you decide to open this .zip file, voila, the Backdoor is
unleashed.
There will always be evil code applications (to knock your system into
becoming a victim) out in this world which anti-virus applications
won't be able to catch. Either the Trojan Horse already installed on
your system will eat the floppies alive, or hacker's will. Hackers
will bind or disguise their applications and install them on your
floppy disks. Many Trojan Horses "hide" all traces of their
applications they run on your system. On your computer perform a
search for a file named "backdoor.zip". I will warn you now, if you
unleash this baby after a complete application install and go online,
you will unleash many of the secrets to the "underground" hackers
world.
A number of Internet Service Providers allow free dial-up access with
DSL and Cable connections. Note: Hackers are taking advantage of
your canceled accounts even when they were closed. Until certain
Internet Services Providers and Telecommunication Companies correct
their major error; telecon your ISP and ask them to change your
password since malicious hackers are abusing your canceled account,
holding you liable.
Disabling all unnecessary Window Services will assist in making your
computer system secure. How to accomplish this task is presented
under "Windows Services you might want to disable". If running any
type of Server, update the latest application patches.
Once you are able to view all Hidden Files and Folders, it would be
smart to make a backup copy of your registry. To perform this, do