dua

(Untitled)

May 18, 2004 11:03

V annoyed. I appear to have acquired a cold in time for exams. Which is exactly what happened last time! My immune system is obviously aware of exam stuff. (And it's nothing to do with stress or lack of sleep compromising my immune system, mmkay?!) Still, I picked up some co-codamols for my back on Saturday, so they're just getting used to fend of ( Read more... )

Leave a comment

Comments 13

_cheiron_ May 18 2004, 03:20:46 UTC
Noooo!

You don't need Linux *spits* ;)

Nah..LSASS is a winbloze security authentication process and loads up normally. There was a buffer overrun vulnerability that the sasser worm exploited which makes it go boom and crash; the result of which is that ftp.exe is loaded up and the sasser is uploaded to your machine and starts doing the same to others. When lsass crashes winblose authentication prompts you for a shutdown in 60 seconds. You can goto "run" and type "shutdown -a" to stop that happening and patch your system against it.

Since it targets specific ports (I don't remmeber which); if you have a firewall that's letting things through one way and not the other you may wanna change a few settings. It's not much of a "fix" but it should stop most infections from occuring.

Maybe the reboot was something else?

[PS: give Knoppix 3.4 a try!]

Reply

dua May 18 2004, 03:31:37 UTC
Well, given that I worked out that 99% of what I do at the moment, I can do it on Linux, it kind of seems like it's pointless running Windoze. I might experiment with FreeBSD or something as well though :-)

Anyway, I eventually figured out that lsass was indeed a proper Windoze program, given that I wasn't infected and it was running :-) What d'you mean about the firewall letting things through one way and not the other? The only ports I've got open on my linux box are http, https, ftp, ssh & edonkey ones...

I was partly so miffed when I thought I had it because I figured that if I *had* managed to get a virus like that even with the set up I've got, there wasn't a lot more I could do to protect myself...

And last summer I ended up using Knoppix for quite a while as my BIOS had a fit and lost one of my hard disks (which had My Documents on it). Windows doesn't do its own fsck so didn't find My Documents and wouldn't boot, whereas knoppix merrily worked as soon as I put the CD in, pretty much :-)

Reply

_cheiron_ May 18 2004, 04:29:32 UTC
Heh; I figure you can use any OS for most tasks anyway; but some of them just let you get on with the tasks at hand and others leave you wasting time messing about with the innards (they call it "administering", heh.) When you've finally got things running well enough you corrupt your apt database thingy and nothing installs the way it used to anymore; or you install from source and find that you have mismatching library versions; or the rsync server goes poo; etc, etc. A bit of hair-pulling later you've still not worked things out even when you RTFM'ed so you ask a more condascending knowledgable person for advice. He explains that its one of "those things" and solves it easy enough with a solution that simply doesn't make sense but works; or sometimes tells you to reinstall the OS because getting the database working again is more difficult :) And so you go abut your merry ways until the next time it happens; when your printer refuses to co-operate for some unusual reason or your mouse buttons decide to swap over or something ( ... )

Reply

dua May 18 2004, 04:55:51 UTC
I know what you mean. But I just don't trust Windows. Which is possibly irrational, but there you go :-) It's partly that Windows is so frequently targetted that it seems somewhat foolish to open myself up to it. And anyway, installing Linux gives me something to do over the bits of the holidays when I'm not doing other stuff ( ... )

Reply


ifyouknew May 19 2004, 16:27:10 UTC
Hope you'll feel better soon!!

Reply

dua May 20 2004, 10:20:08 UTC
Thank you sweetie! Still feeling a bit bleurgh but not too bad. Hope you're doing OK. Sorry I haven't been keeping up very well :-/

Reply


Leave a comment

Up