netsend spam messages

Problems? Post here...
Post Reply
User avatar
ayu
Staff
Staff
Posts: 8109
Joined: 27 Aug 2005, 16:00
18
Contact:

netsend spam messages

Post by ayu »

So, i formated the box a few days ago and reinstalled XP, needed an older version that was more stable since the one i had kept slaping my face with bluescreens. Anyway.... so when i was done...i got a netsend all of a sudden, i have gotten them some years ago but ignored the then. But for some reason i wanted to figure out where they came from.

So i shutdown all other computers, one at a time in the network, to see if any of them sent it. When all of them was off i still got the message, so i was like wtf is it from my newly installed computer?

So i check the router to see if any ports are open that may have opened it for an attack. Nothing, no ports were forwarded. I got the message once more... it looked like this, this isn't a picture taken by me, and the address was different. But it was almost the same, same text and all.

Image


anyway, so at this time i am starting to search my own computer. I made scans with Kaspersky, online scans with trend micro (sucks btw), and with adaware and spytbot. Nothing, so i checked for rootkits, nothing out of the ordinary. Check regristry run paths and other suspicious spyware places. I checked processes and newly created files in the windows and system32 folder. Yet i found nothing, i then checked the system logs and it had the message loged, but no information about the sender.

So i googled arround, and i found out that it was messages from the net (b_b had told me once also, it's not that i didn't believe him, it's just that it was odd....), and after a while i accepted the fact that they came from outside my network. But what i couldn't accept was that no ports were forwarded to my computer.

and our network looks like this

[pc1]--\
[pc2]---\
[pc3]---------[router]-----[WAN]
[pc4]--/


so how could the message be forwarded to my computer? and mine only...the other computer didn't get it...and one of the others doesn't even have a firewall...


Does anyone have a logical answer? maybe it's really simple and i have missed it.....and i will accept my faulty searches..just tell me!! O_O
"The best place to hide a tree, is in a forest"

Chaos1986
Fame ! Where are the chicks?!
Fame ! Where are the chicks?!
Posts: 412
Joined: 03 May 2006, 16:00
17
Location: United States Of America
Contact:

Post by Chaos1986 »

Well I Went Directly To Microsoft's Page And This Is What I Found.
Messenger Service window that contains an Internet advertisement appears
View products that this article applies to.
Article ID : 330904
Last Review : May 7, 2007
Revision : 8.4
This article was previously published under Q330904
On This Page
SYMPTOMS
CAUSE
RESOLUTION
You connect to the Internet directly
You are running Windows XP
You are running Windows 2000
You connect to the Internet through a small network that you manage
You are running Windows XP with Internet Connection Sharing
You are running Windows with a hardware Internet Connection Sharing device
You connect to the Internet though a network that you do not manage
WORKAROUND
MORE INFORMATION
SYMPTOMS
You may receive an Internet advertisement in a Messenger service window. The advertisement contains text that is similar to the following text:
Messenger Service
Message from source to your_computer_name.ISP_name on date time
Message Text
These messages are also known as "messenger spam."

Back to the top
CAUSE
This issue may occur if you receive a net send message from someone who is using the Messenger service in Windows. The Messenger service is a Windows service that transmits net send messages and messages that are sent through the Alerter service between client computers and servers. For example, network administrators use Messenger service to send administrative alerts to network users. Windows and other software programs can also use the Messenger service. For example, Windows may use it to inform you when a print job is completed or when you lose power to your computer and switch to an uninterruptible power supply (UPS). Your antivirus program may use the Messenger service to send you notifications. The Messenger service is not related to your Web browser, e-mail program, Windows Messenger, or MSN Messenger. This issue may occur if the following conditions exist:
• The Messenger service is started.
• The Remote Procedure Call service is started.
• Inbound NetBIOS (NetBIOS over TCP/IP) and UDP broadcast traffic is turned on for your Internet connection.

Back to the top
RESOLUTION
To resolve this issue, install or turn on a firewall that blocks inbound NetBIOS and UDP broadcast traffic. The method that you use to resolve this issue depends on your operating system and how you connect to the Internet. The following sections provide examples of several different configurations and possible methods of resolution.

Back to the top
You connect to the Internet directly
If you use a single computer that is connected to the Internet directly (by using a cable modem, a DSL modem, or a dial-up modem, for example), install a firewall and block inbound NetBIOS and UDPbroadcast traffic on your computer.
You are running Windows XP
If you are running Windows XP and connect to the Internet directly (by using a cable modem, a DSL modem, or a dial-up modem, for example), install Windows XP Service Pack 1 (SP1) and turn on Internet Connection Firewall (ICF). By default, the installation of Windows XP SP1 permits Internet Connection Firewall (ICF) to block all incoming traffic (unicast, multicast, and broadcast). By default, if you have installed Windows XP Service Pack 2 (SP2), Windows Firewall (WF) is turned on.

For additional information about this change in ICF blocking behavior in Windows XP SP1, click the following article number to view the article in the Microsoft Knowledge Base:
329928 (http://support.microsoft.com/kb/329928/) ICF now blocks insolicited inbound unicast, multicast, and broadcast traffic
For additional information about how to obtain Windows XP SP1, click the following article number to view the article in the Microsoft Knowledge Base:
322389 (http://support.microsoft.com/kb/322389/) How to obtain the latest Windows XP service pack
For additional information about how to turn on ICF, click the following article number to view the article in the Microsoft Knowledge Base:
283673 (http://support.microsoft.com/kb/283673/) How to turn on or turn off the Internet firewall in Windows XP
You are running Windows 2000
If you are running Windows 2000 and connect to the Internet directly (by using a cable modem, a DSL modem, or a dial-up modem, for example), obtain and install a third-party firewall product that blocks inbound NetBIOS and UDP broadcast traffic. For additional information about firewalls, visit the following Microsoft Web site:
http://www.microsoft.com/athome/securit ... efits.mspx (http://www.microsoft.com/athome/securit ... efits.mspx)

Back to the top
You connect to the Internet through a small network that you manage
If your network uses connection sharing to provide Internet access to multiple computers, install or enable the firewall only on the shared Internet connection.
You are running Windows XP with Internet Connection Sharing
If you use Internet Connection Sharing in Windows XP to provide Internet access to multiple computers, install Windows XP SP1 on the Internet Connection Sharing host computer and turn on ICF only on the Internet Connection Sharing host computer.
You are running Windows with a hardware Internet Connection Sharing device
If you use a router or other hardware device to provide Internet access to multiple computers, configure the connection sharing device to block inbound NetBIOS and UDP broadcast traffic. Contact the manufacturer of your third-party connection sharing device for more information.

Back to the top
You connect to the Internet though a network that you do not manage
If you connect to the Internet by using a corporate network, or if your Internet service provider (ISP) uses a firewall, ask the network administrator to configure the firewall to block inbound NetBIOS and UDP traffic. Contact your network administrator or ISP for more information.

Back to the top
WORKAROUND
To work around this issue, turn off the Messenger service. To do this, follow these steps:
1. Click Start, and then click Control Panel (or point to Settings, and then click Control Panel).
2. Double-click Administrative Tools.
3. Double-click Services.
4. Double-click Messenger.
5. In the Startup type list, click Disabled.
6. Click Stop, and then click OK.
Note If the Messenger service is stopped, messages from the Alerter service (notifications from your antivirus software, for example) are not transmitted. If the Messenger service is turned off, any services that explicitly depend on the Messenger service do not start, and an error message is logged in the system event log. Therefore, Microsoft recommends that you install a firewall and configure it to block NetBIOS and RPC traffic instead of turning off the Messenger service.

Back to the top
MORE INFORMATION
The Messenger service uses UDP ports 135, 137, and 138; TCP ports 135, 139, and 445; and an ephemeral (that is, short-lived) port number greater than 1024.

Firewalls help prevent net send messages and help protect your computer from other malicious attacks over the Internet. These attacks can be designed to perform the following tasks:
• Access your private information
• Distribute software illegally by appropriating space on your hard disk
For additional information about this issue, visit the following Microsoft Web site:
http://www.microsoft.com/windowsxp/usin ... amv45.mspx (http://www.microsoft.com/windowsxp/usin ... amv45.mspx)

Back to the top
APPLIES TO
• Microsoft Windows XP Professional
• Microsoft Windows XP Home Edition
• Microsoft Windows XP Tablet PC Edition
• Microsoft Windows XP Media Center Edition 2002
• Microsoft Windows XP Professional for Itanium-based systems
• Microsoft Windows 2000 Advanced Server
• Microsoft Windows 2000 Server
• Microsoft Windows 2000 Professional Edition
• Microsoft Windows Messenger 4.6
• Microsoft Windows Messenger 4.7
• MSN Messenger 5.0
• Microsoft Windows XP Service Pack 2
• Microsoft Windows XP Service Pack 2
• Microsoft Windows XP Service Pack 2
• Microsoft Windows XP Tablet PC Edition 2005 :twisted: :evil:
If Man Made It Man Can Crack Or Hack It & If You Want To Be A True Hacker You Need To Keep Your Mind Open And Always Be Willing To Learn
[img]http://img384.imageshack.us/img384/9996/chaos19862ub.png[/img]

User avatar
ayu
Staff
Staff
Posts: 8109
Joined: 27 Aug 2005, 16:00
18
Contact:

Post by ayu »

Did you have to copy/paste the WHOLE page? =P


anyway, we have talked about this already Chaos, and i will wait until i get the message again and set up a port listener and try to capture the IP that it comes from, or log the incoming packet. Anyway, these are projects for tomorrow ^^ need some sleep now.

Thanks for your reply Chaos, goodnight =)
"The best place to hide a tree, is in a forest"

Post Reply