Posted on 12/31/2005 10:52:26 AM PST by an amused spectator
I've been getting a large number of firewall probes all morning - on the order one every minute to two minutes.
Mostly pings and port 1026s (Windows Messenger).
I've been monitoring the WMF exploit for the last couple of days, and when I was checking up on this morning's high activity, I noticed this article:
Worry Watch -- Instant Messenger attacks rise in number and damage (from post-gazette.com, 12/31/2005)
Wonder if someone(s) are trying to use the WMF exploit via Windows Messenger in a big way?
Or at least I think I am. ;-)
It's most likely a new WMF variant.
And of course, Microsoft has yet to release a patch. Gee, thanks, Redmond!
If you are on highspeed cable or DSL, you get those kinds of things all the time.
Just make sure your firewall software or hardware is operational.
Considering the volume, it's a sure bet that YAMMW (Yet Another Microsoft Malware Worm) is in play.
Oh, but didn't you hear? Closed source is sooooooooo much more secure than Open Source! (*snerk*)
Yes, I'm aware of that. Unless I changed a setting in ZA without realizing it, this is highly abnormal for me. Normally, I get a couple of noticeable taps per day. I'm a computer guru, so I'm not just freaking out over normal activity.
Just wondered if anyone else was getting hammered. (BTW - I've got ZoneAlarm Free)
What exactly does the availability of the code have to do with this? Microsoft isn't on the ball. Apple isn't an open-source company, but you can be sure they'd have a patch for this out by now, even if it was just a temporary fix that disabled the ability to load .wmf files while they worked on something more permanent.
Nothing on my machine (cable broadband), but then I don't have port 1026 open, either.
Sometimes I wonder if they think I'm strange when I tell them they have to do something to their machine RIGHT AWAY. They don't really say much - they seem to trust my judgement...
I assumed that port 1026 was closed and stealthed on my machine, but I could be wrong. I better go check it. Thanks for the tip.
Love my dial-up. By the time viruses make the trek up hill they're too tired to do much.
Ain't it the truth! :-)
It's probably just the NSA. Hope you're not a terrorist.
From your remarks, I'd say you haven't run into Golden Eagle or Bush2000 yet. Those two, like every other vapid Microsoft shill, insist that Microsoft's closed-source approach is "more secure" because the bad guys can't see the source code and find weaknesses. They further claim that Microsoft gets its ass handed to it every other day because it's the "most popular" operating system.
Of course, those schmucks also think third-party software is all "Linux" when a bug is found in it. They like to use that argument to bolster their erroneous claim that Microsoft's crap is the "most secure" the market has to offer.
You might also want to Shoot the Messenger. No reason to leave that crap running.
OTOH, most of us Windows users don't bother will all that nonsense. We have our firewalls up, don't open unknown attachments and don't visit the porn sites that are the source of most of the malware out there.
I do a daily scan of my system, automatically, every morning at 2AM, with a constantly updated virus scanner. So far, I've never seen a single thing.
The only time I reboot is when I do an update of something.
Windows XP Professional, with all automatic updates in place and a good firewall, seems pretty darned stable. But, hey...that's just me.
I use ZoneAlarm Free, too.
I have it set to not notify me of every attempted intrusion, because they are too frequent and too distracting.
I just looked at the ZA control panel -- 1262938 access attempts have been blocked. I just installed this new version a few days ago.
If the code were open, Microsoft wouldn't have to be on the ball, now would they? You or I or self described 'computer gurus' like the OP could write our own patches. :)
Dang! I got cookies for Christmas. I wonder if the EVIL Bush Administration slipped some monitoring cookies into the batch?
Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.