Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

seven minutes ...

2 views
Skip to first unread message

Doug Mentohl

unread,
Dec 9, 2005, 3:45:44 PM12/9/05
to
An acquaintance of mine asked me to connect him to the Internet. Seven
minutes connected to the Internet is all it took to kill a fully
patched Windows boxen.

12:40pm: Boot up Windows 2003 ..

12:47pm: Message: lsass.exe terminated unexpectedly with status code
1073740972 ...

Virus scan reports the generic.gm virus and the file rdriv.sys as the
contaminants bit is unable to remove them.

What possesses them to design Windows in such a way that when a virus
attacks the computer the system shuts down so as to prevent you from
fixing the issue. It's almost as if protecting MS software from piracy
is more important than reliability.

Boris

unread,
Dec 27, 2005, 8:29:25 AM12/27/05
to
"Doug Mentohl" <doug.m...@gmail.com> wrote in message
news:1134161144.3...@g47g2000cwa.googlegroups.com...

> An acquaintance of mine asked me to connect him to the Internet. Seven
> minutes connected to the Internet is all it took to kill a fully
> patched Windows boxen.
1. You should never connect a server to Internet directly: always use a
hardware firewall or router.
For client PCs, you should use (at least) a software firewall.

2. Isn't it possible that worm got to your server via 3-rd party app
(listening on a port, for example)?

3. Win2003 has built-in software firewall. Did you poke any holes in it, by
any chance?

0 new messages