Messenger Service ????

T

teeter

I keep receiving this message alot, and I would like to
know if it is legit:

Message from MICROSOFT NETWORKS to WINDOWS USER on
3/22/2004
Microsoft Security Bulletin MS03-043
Buffer overrun Messenger Service Could Allow Code
Execution
Affected Software:
?
?
?
?
Non Affected Software:
?
Your system is affected, please type in the following
address into your internet browser and click "ok". The
address will disappear once you hit ok

Then it gives me an adress www.????.info

The question marks are information I left out for
security. If you can help me let me know by posting a
response.
 
G

Guest

Greetings --

There are at least three varieties of pop-ups, and the
solutions vary accordingly. Which specific type(s) is
troubling you?

1) Does the title bar of these pop-ups read "Messenger
Service?"

This type of spam has become quite common over the
past several months, and unintentionally serves as a valid
security "alert." It demonstrates that you haven't been
taking sufficient precautions while connected to the
Internet. Your data probably hasn't been compromised by
these specific advertisements, but if you're open to this
exploit, you may well be open to other threats, such as
the Blaster Worm that recently swept cross the Internet.
Install and use a decent, properly configured firewall.
(Merely disabling the messenger service, as some people
recommend, only hides the symptom, and does little or
nothing to truly secure your machine.) And ignoring or
just "putting up with" the security gap represented by
these messages is particularly foolish. A free good
firewall you can get is ZoneAlarm.

Messenger Service of Windows
http://support.microsoft.com/default.aspx?scid=KB;en-
us;168893

Messenger Service Window That Contains an Internet
Advertisement Appears
http://support.microsoft.com/?id=330904

Stopping Advertisements with Messenger Service Titles
http://www.microsoft.com/windowsxp/pro/using/howto/communic
ate/stopspam.asp

Blocking Ads, Parasites, and Hijackers with a Hosts File
http://www.mvps.org/winhelp2002/hosts.htm

Whichever firewall you decide upon, be sure to ensure
UDP ports 135, 137, and 138 and TCP ports 135, 139, and
445 are _all_blocked. You may also disable Inbound
NetBIOS (NetBIOS over TCP/IP). You'll have to follow the
instructions from firewall's manufacturer for the specific
steps.

You can test your firewall at:

Symantec Security Check
http://security.symantec.com/ssc/vr_main.asp?
langid=ie&venid=sym&plfid=23&pkj=GPVHGBYNCJEIMXQKCDT

Security Scan - Sygate Online Services
http://www.sygatetech.com/

Oh, and be especially wary of people who advise you to
do nothing more than disable the messenger service.
Disabling the messenger service, by itself, is a "head in
the sand" approach to computer security. The real problem
is _not_ the messenger service pop-ups; they're actually
providing a useful, if annoying, service by acting as a
security alert. The true problem is the unsecured
computer, and you've been advised to merely turn off the
warnings. How is this helpful?

2) For regular Internet pop-ups, you might try the
free 12Ghosts Popup-killer from
http://12ghosts.com/ghosts/popup.htm, Pop-Up Stopper from
http://www.panicware.com/, or the Google Toolbar from
http://toolbar.google.com/. Also a good firewall can stop
these(such as nortons internet security).

3) To deal with pop-ups caused by any sort
of "adware" and/or "spyware,"such as Gator, Comet Cursors,
Xupiter, Bonzai Buddy, or KaZaA, and their remnants, that
you've deliberately (but without understanding the
consequences) installed, two products that are quite
effective (at finding and removing this type of scumware)
are Ad-Aware from www.lavasoft.de and SpyBot Search &
Destroy from www.safer-networking.org/. Both have free
versions. It's even possible to use SpyBot Search &
Destroy to "immunize" your system against most future
intrusions. Use both and generally perform manual scans
every week or so to clean out cookies, etc.


Spybot Search and Destroy
http://www.safer-networking.net/

Lavasoft AdAware
http://www.lavasoft.de

CWSShredder
http://www.spywareinfo.com/~merijn/downloads.html

Hijack This!
http://mjc1.com/mirror/hjt/
 
B

Bruce Chambers

Greetings --

This type of spam has become quite common over the past year or
so, and unintentionally serves as a valid security "alert." It
demonstrates that you haven't been taking sufficient precautions while
connected to the Internet. Your data probably hasn't been compromised
by these specific advertisements, but if you're open to this exploit,
you undoubtedly open to other threats, such as the Blaster Worm that
still "haunts" the Internet. Install and use a decent, properly
configured firewall. (Merely disabling the messenger service, as some
people recommend, only hides the symptom, and does little or nothing
to truly secure your machine.) And ignoring or just "putting up with"
the security gap represented by these messages is particularly
foolish.

Messenger Service of Windows
http://support.microsoft.com/default.aspx?scid=KB;en-us;168893

Messenger Service Window That Contains an Internet Advertisement
Appears
http://support.microsoft.com/?id=330904

Stopping Advertisements with Messenger Service Titles
http://www.microsoft.com/windowsxp/pro/using/howto/communicate/stopspam.asp

Blocking Ads, Parasites, and Hijackers with a Hosts File
http://www.mvps.org/winhelp2002/hosts.htm

Whichever firewall you decide upon, be sure to ensure UDP ports 135,
137, and 138 and TCP ports 135, 139, and 445 are _all_ blocked. You
may also disable Inbound NetBIOS (NetBIOS over TCP/IP). You'll have
to follow the instructions from firewall's manufacturer for the
specific steps.

You can test your firewall at:

Symantec Security Check
http://security.symantec.com/ssc/vr_main.asp?langid=ie&venid=sym&plfid=23&pkj=GPVHGBYNCJEIMXQKCDT

Security Scan - Sygate Online Services
http://www.sygatetech.com/

Oh, and be especially wary of people who advise you to do nothing
more than disable the messenger service. Disabling the messenger
service, by itself, is a "head in the sand" approach to computer
security. The real problem is _not_ the messenger service pop-ups;
they're actually providing a useful, if annoying, service by acting as
a security alert. The true problem is the unsecured computer, and
you've been advised to merely turn off the warnings. How is this
helpful?


Bruce Chambers

--
Help us help you:




You can have peace. Or you can have freedom. Don't ever count on
having both at once. -- RAH
 
K

Kevin Davis³

Oh, and be especially wary of people who advise you to
do nothing more than disable the messenger service.
Disabling the messenger service, by itself, is a "head in
the sand" approach to computer security. The real problem
is _not_ the messenger service pop-ups; they're actually
providing a useful, if annoying, service by acting as a
security alert. The true problem is the unsecured
computer, and you've been advised to merely turn off the
warnings. How is this helpful?

Don't forget that the Messenger Service would also provide a useful
service to hackers if it is not patched:

http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/ms03-043.asp

Setup a firewall first, but if you don't need the Messenger Service,
turn it off. If you need it, patch it. You would also be well
advised to spend $50 and buy a home router.

Be especially wary of people who would insist on having you keep the
Messenger Service on as a "helpful feature" and conveniently
forgetting to inform you that it has a very serious vulnerability that
needs to be patched immediately.

And of particular interest is that Microsoft itself and security
experts are seriously reconsidering the role of the Messenger service:

http://www.infoworld.com/article/03/10/28/HNmessengeroff_1.html

http://www.pcworld.com/news/article/0,aid,113321,tk,dn110703X,00.asp

http://news.com.com/2100-7355_3-5095935.html

http://www.cnn.com/2003/TECH/internet/11/07/microsoft.popup.reut/index.html


Here's a link where Microsoft actually outright advises the user to
turn off the Messenger Service:

http://www.microsoft.com/WindowsXP/pro/using/howto/communicate/stopspam.asp


Those who would advise not to turn off the Messenger Service for the
less than trivial unintended side benefit of being a warning is
dispensing advice which contradicts the advice of many real security
professionals.
The real problem is _not_ the messenger service pop-ups;
they're actually providing a useful, if annoying, service by acting as
a security alert.

If you were protecting your house and you had one door that nobody
ever used and that door was really loud and squeaky, would you:

A: Keep the door unlocked all the time and actually depend on the
loud squeak of the door to be an integral part of your house alarm
system to alert you of an intruder?

or

B. Since no legitimate people would ever use the door, bar the door
shut so that there was no chance no-one could enter through it?
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top