Earlier quoted context omitted.
IIRC Windows XP up to SP2 was vulnerable to this. Basically if you ran the install with the DSL modem attached, your PC was compromised even before the end of setup.
When W32/Blaster[0] came out I worked at a small ISP doing tech support and computer repair. A tech and I imaged an old box we had in the corner with a clean XP, assigned it a static IP in our /24, plugged it in and started a stopwatch. It didn’t even make it two minutes before it was infected. [0] https://en.m.wikipedia.org/wiki/Blaster_(computer_worm)
Why does trying to break into the NT 3.1 kernel reboot my 486DX4 machine?
61–70 of 111 posts
Re: Why does trying to break into the NT 3.1 kernel reboot my 486DX4 machine?
#62Earlier quoted context omitted.
Remember when Win95 could be crashed or even rooted just by pinging it the right way? We really have come a long way. https://en.wikipedia.org/wiki/Ping_of_death I also remember SMB vulnerabilities that stayed unpatched for years on some machines. That was already when Metasploit existed, so you could inject VNC into most Windows hosts on local network with just a few commands. These days at least the patching is sup…
Earlier versions of Windows (98? 95?) also used to share things like drives (C$, D$) and printers with the dial-up connection by default. I remember connecting to a printer of a classmate over the internet and printing a page, to his surprise. All you needed was the IP, which was trivial to get from ICQ, back in the days.
Re: Why does trying to break into the NT 3.1 kernel reboot my 486DX4 machine?
#63Earlier quoted context omitted.
IIRC Windows XP up to SP2 was vulnerable to this. Basically if you ran the install with the DSL modem attached, your PC was compromised even before the end of setup.
When W32/Blaster[0] came out I worked at a small ISP doing tech support and computer repair. A tech and I imaged an old box we had in the corner with a clean XP, assigned it a static IP in our /24, plugged it in and started a stopwatch. It didn’t even make it two minutes before it was infected. [0] https://en.m.wikipedia.org/wiki/Blaster_(computer_worm)
For the other 99.9% percent of the users it protected them and us.
Windows was such a mess back then.
Re: Why does trying to break into the NT 3.1 kernel reboot my 486DX4 machine?
#64Ah, the retro-computing rabbit hole. Harmlessly divorced from any real-world consequences, but truly satisfying nonetheless. A real honey trap for nerds. I just had to click that 6 more comments expander
Re: Why does trying to break into the NT 3.1 kernel reboot my 486DX4 machine?
#65Earlier quoted context omitted.
Remember when Win95 could be crashed or even rooted just by pinging it the right way? We really have come a long way. https://en.wikipedia.org/wiki/Ping_of_death I also remember SMB vulnerabilities that stayed unpatched for years on some machines. That was already when Metasploit existed, so you could inject VNC into most Windows hosts on local network with just a few commands. These days at least the patching is sup…
I remember those days. Even into the late 90s early 2000, modems (including ADSL) didn't come with a router, you had to establish a PPPoE connection from your computer, which also means your home machine was directly on the WAN with no firewall protection. I can't remember which version of windows but it must have been 98 or ME, you had to rush to download and install a patch when you connected it first to the intern…
Even today modems don't always come with a routers. In fact, I like them that way :).
IIRC, the problem in the late 90s/early 2000s was routers were thought of as only necessary to get multiple computers online, and it was pretty common for people households to only own a single desktop. There wasn't enough security consciousness earned through repeated failure, so it "made sense" to direct connect consumer machines to the internet.
We actually had a LAN years before we had broadband, and I setup a PC running Linux as a router to share our 33.6 modem to the household. But before that? The PC direct dials into the ISP, and got a publicly-routable IP.
Re: Why does trying to break into the NT 3.1 kernel reboot my 486DX4 machine?
#66Re: Why does trying to break into the NT 3.1 kernel reboot my 486DX4 machine?
#67Earlier quoted context omitted.
He does mention a bit more in a hidden comment: "NTOSKRNL.EXE + debug symbols + IDA helped me understand how the remote break-in is supposed to work. I knew that something in the remote break-in code path before the first debug packet is sent is going to reboot my machine. So I patched "JMP SHORT $" instructions into the relevant code-path. If I placed it before the crash point, the machine hangs. If I placed it afte…
Not sure why this is downvoted, the comment is on point. Is it because it is partly gpt-generated content? I wonder if patching memory worked in the debugger, if not this would have to be done by manually editing the kernel file with IDA or something, and rebooting the machine. But in either case this is a good way to find the problem.
Everything in the comment before that was great, no reason vote it down for that.
Re: Why does trying to break into the NT 3.1 kernel reboot my 486DX4 machine?
#68Earlier quoted context omitted.
I remember those days. Even into the late 90s early 2000, modems (including ADSL) didn't come with a router, you had to establish a PPPoE connection from your computer, which also means your home machine was directly on the WAN with no firewall protection. I can't remember which version of windows but it must have been 98 or ME, you had to rush to download and install a patch when you connected it first to the intern…
> Even into the late 90s early 2000, modems (including ADSL) didn't come with a router, you had to establish a PPPoE connection from your computer, which also means your home machine was directly on the WAN with no firewall protection. Even today modems don't always come with a routers. In fact, I like them that way :). IIRC, the problem in the late 90s/early 2000s was routers were thought of as only necessary to get…
I agree. I have a better router that I'm going to use anyway, so I disable the router functionality in the modem if it has one.
My current one has no router or WiFi. Perfect!
Re: Why does trying to break into the NT 3.1 kernel reboot my 486DX4 machine?
#69Ah, the retro-computing rabbit hole. Harmlessly divorced from any real-world consequences, but truly satisfying nonetheless. A real honey trap for nerds. I just had to click that 6 more comments expander
Re: Why does trying to break into the NT 3.1 kernel reboot my 486DX4 machine?
#70Earlier quoted context omitted.
LSASS.exe would crash with about 5 minutes of IBR (Internet Background Radiation). I cant remember the name of the worm. XP SP3 fixed this.
> IBR (Internet Background Radiation) that is really unpleasant.. engineers worked, companies worked and volunteers also worked to make the modern Internet, then selfish-clever, thieving, control-oriented militaristic jerks from WINDOWS filled the content with WINDOWS virus activity to play cheap stealing tricks on unsuspecting people. And you call it "the Internet" .. it has nothing to do with "the Internet" as much…