Home News Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | The Experimentâ„¢


You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Security & Virus Discussion

The Experimentâ„¢
Reply
 
Thread Tools
Old 11-05-2005, 19:08   #1
cf.mega poster
 
Join Date: Jun 2003
Age: 29
Posts: 6,273
Richard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze array
Richard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze array
The Experimentâ„¢

One week, one unpatched XP box
Summary

I freed up a Linux box this week and I had an interesting idea.
In these days of the wild internet, I wondered what would happen to an unpatched Windows XP computer.

Well, I'm going to get a good chance to find out as this weekend is the start of The Experiment? - place an unpatched, unprotected Windows XP Pro computer on the internet and watch the results.
I happen to have several spare XP Pro disks, and the one I'm going to be using is the very first edition - no service packs here folks.

Machine Spec

The computer used is nothing particularly special, but is ideal because it's exactly the sort that your mum or dad will be using to check their mail and sell stuff on eBay.
  • AMD Athlon 1800+
  • 512MB PC133 SDRAM
  • 80GB IDE hard disk
  • NVidia GeForce 4 MX440
  • Soundblaster Live 5.1 soundcard
  • Standard 10/100 ethernet card

As previously stated, it will be Windows XP Pro running a default installation.
The only exceptions are detailed below.

Software & Firewall Configuration

There are several important changes that will be made to the OS:
  • Enabling of "Remote Desktop" - this will let me check the computer from work and lets me log in from any computer at home.
  • TCP/IP - static IP addressing will be used and the computer will be placed in a DMZ to protect the part of the network I want to keep secure.
  • The reserved ports 1-1024 will be opened on the firewall and configured to port-forward to the new machine.

Schedule

So when will this happen, and how?

I'll format the disk (currently running Linux) then install Windows XP on Saturday at around 12PM (UK time).
The configuration mentioned in the previous chapter will then take place, then the ethernet cable will be connected to the switch.

The test will run for one week, unless something really interesting happens that forces me to cut the test short or extend it.

Expectations & Possibilities

I'm expecting the box to be "0wned" within an hour, possibly less.
Depending on what happens, I might do some random browsing on a default Internet Explorer - sites that your kids might visit for example, all those flashing banner ads giving away free smiley icons etc.

I'm also expecting to be hit hard by the Blaster worm, this can cause the machine to reboot constantly which will make the test a bit difficult.
If this turns out to be the case, I'll have to stop the RPC service although it'll be interesting to see how long it takes to get infected.

SANS has a top 10 Windows threats list available.

Comments

Please post your comments in the below forum thread
Richard M is offline   Reply With Quote
Old 11-05-2005, 19:15   #2
Google it!!
 
Paul's Avatar
 
Join Date: Jun 2003
Location: Essex
Age: 34
Services: Sky Digital + 16Mb ADSL BT Telephone
Posts: 14,952
Paul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered stars
Paul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered stars
Re: The Experimentâ„¢

What's the IP then
__________________
Paul is offline   Reply With Quote
Old 11-05-2005, 19:16   #3
Rob
Cable Forum Team
 
Rob's Avatar
 
Join Date: Jun 2003
Age: 44
Posts: 11,707
Rob has a pair of shiny starsRob has a pair of shiny stars
Rob has a pair of shiny starsRob has a pair of shiny starsRob has a pair of shiny starsRob has a pair of shiny starsRob has a pair of shiny starsRob has a pair of shiny starsRob has a pair of shiny starsRob has a pair of shiny starsRob has a pair of shiny starsRob has a pair of shiny starsRob has a pair of shiny starsRob has a pair of shiny starsRob has a pair of shiny starsRob has a pair of shiny starsRob has a pair of shiny stars
Re: The Experimentâ„¢

If you aren't actually doing anything on the PC, it may take a while for it to get infected with something. It's visiting sites, getting dodgy emails and the like that is the real killer.
__________________
The NTHW Gaming Clan! ~ Call of Duty Gameservers and More!

Help Cable Forum's MiniCity grow:
Population|Industry|Transport|Security|Environment|Business
Rob is online now   Reply With Quote
Old 11-05-2005, 19:19   #4
Busy Admin
 
Paul M's Avatar
 
Join Date: Oct 2003
Location: Nottingham
Age: 45
Services: VM Phone : Sky+ Multiroom : VM Cable (20 Mbps)
Posts: 14,485
Paul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny star
Paul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny star
Send a message via ICQ to Paul M
Re: The Experimentâ„¢

What's the reason for doing this ? - it probably isn't going to last long, but not many such machines really exist.

Even the pc I bought in late 2002 had SP1 on it.
__________________
DigiGuide Click here for a real, interactive, tv guide.
Paul M is offline   Reply With Quote
Old 11-05-2005, 19:20   #5
cf.mega poster
 
Join Date: Jun 2003
Age: 29
Posts: 6,273
Richard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze array
Richard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze array
Re: The Experimentâ„¢

If you'd like to spam the article link to hell on websites in the coming days, feel free.
I'm going to submit the link to several computer news websites myself, security problems need to be brought to attention.
Richard M is offline   Reply With Quote
Old 11-05-2005, 19:20   #6
CableForum - Talk to me!
 
TheBlueRaja's Avatar
 
Join Date: Dec 2003
Location: Baw deep in a munter
Age: 32
Services: Initiations, rep rigging and orgies!
Posts: 5,772
TheBlueRaja has a nice shiny starTheBlueRaja has a nice shiny starTheBlueRaja has a nice shiny starTheBlueRaja has a nice shiny starTheBlueRaja has a nice shiny star
TheBlueRaja has a nice shiny starTheBlueRaja has a nice shiny starTheBlueRaja has a nice shiny starTheBlueRaja has a nice shiny starTheBlueRaja has a nice shiny starTheBlueRaja has a nice shiny starTheBlueRaja has a nice shiny starTheBlueRaja has a nice shiny starTheBlueRaja has a nice shiny starTheBlueRaja has a nice shiny starTheBlueRaja has a nice shiny starTheBlueRaja has a nice shiny star
Re: The Experimentâ„¢

Quote:
Originally Posted by Paul
What's the IP then
What he said...
__________________
XBox Live Member TE3BLUERAJA /// Go Retro Gaming here
TheBlueRaja is offline   Reply With Quote
Old 11-05-2005, 19:22   #7
cf.mega poster
 
Join Date: Jun 2003
Age: 29
Posts: 6,273
Richard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze array
Richard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze array
Re: The Experimentâ„¢

Quote:
Originally Posted by Paul M
What's the reason for doing this ? - it probably isn't going to last long, but not many such machines really exist.

Even the pc I bought in late 2002 had SP1 on it.
Thanks for mentioning that, I recently read somewhere that around 40% of XP machines do not have SP1 - can't find the link though.
Richard M is offline   Reply With Quote
Old 11-05-2005, 19:39   #8
Eric Cartman Wannabe
 
punky's Avatar
 
Join Date: Jun 2003
Location: Cockney geeza land
Age: 27
Services: c:\> net start punky
Posts: 12,086
punky has a lot of silver blingpunky has a lot of silver blingpunky has a lot of silver blingpunky has a lot of silver blingpunky has a lot of silver bling
punky has a lot of silver blingpunky has a lot of silver blingpunky has a lot of silver blingpunky has a lot of silver blingpunky has a lot of silver blingpunky has a lot of silver blingpunky has a lot of silver bling
Re: The Experimentâ„¢

Quote:
Originally Posted by Richard M
http://www.cableforum.co.uk/board/article.php?a=67

1 unpatched XP box, 1 week.
This should be interesting...
Good luck. The other day I put a clean installed XP SP1 computer on the internet, and got a net send alert within about 10 seconds , and within about 5 mins, it had already been exploited. This was exploited before I had chance to download MS antipyware (which isn't as good as it first seems now, I think). The spyware I, (or MS antispyware and spybot S&D), couldn't get rid of it, so I had to delete, reinstall, and then reinstall SP2, antispyware before connecting it to the net again.

If it is SP2 you might last a bit longer, but SP1 will probably be exploited in minutes. (On BT openworld's network anyway)

Its a bit annoying as I wouldn't mind having SP2 on my desktop, but the b****rd won't install, and I can't seem to get round it.
__________________
"We're not here for a long time, we're here for a good time" - Mike Ness (Social Distortion)
"Reach for the sky, 'cause tomorrow may never come" - Reach For The Sky (Social Distortion)
punky is offline   Reply With Quote
Old 11-05-2005, 19:41   #9
I am not a geek!
 
philip.j.fry's Avatar
 
Join Date: Jul 2003
Posts: 1,395
philip.j.fry has reached the bronze age
philip.j.fry has reached the bronze agephilip.j.fry has reached the bronze agephilip.j.fry has reached the bronze agephilip.j.fry has reached the bronze age
Re: The Experimentâ„¢

Quote:
Originally Posted by TheBlueRaja
What he said...
***** (probably)

EDIT: Removed IP because after a traceroute I don't think it is.
EDIT #2: Ping phpfuture.net to see

Perhaps you should put up a Linux box as well for comparison Rich?

Last edited by philip.j.fry; 11-05-2005 at 19:49.
philip.j.fry is offline   Reply With Quote
Old 11-05-2005, 19:50   #10
Karateka
 
Gareth's Avatar
 
Join Date: Dec 2003
Age: 33
Posts: 7,098
Gareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny stars
Gareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny stars
Re: The Experimentâ„¢

I'm with Paul M on this one... why exactly are you doing it? It's been done before. I remember seeing a report at sans about an out-of-the-box XP machine being compromised within 18 minutes. If I remember correctly, this article itself is a couple of years old now. I'll try and find it again if you're interested.
__________________
Quidquid latine dictum sit, altum sonatur.
Gareth is offline   Reply With Quote
Old 11-05-2005, 19:52   #11
I am not a geek!
 
philip.j.fry's Avatar
 
Join Date: Jul 2003
Posts: 1,395
philip.j.fry has reached the bronze age
philip.j.fry has reached the bronze agephilip.j.fry has reached the bronze agephilip.j.fry has reached the bronze agephilip.j.fry has reached the bronze age
Re: The Experimentâ„¢

Quote:
Originally Posted by Gareth
I'm with Paul M on this one... why exactly are you doing it? It's been done before. I remember seeing a report at sans about an out-of-the-box XP machine being compromised within 18 minutes. If I remember correctly, this article itself is a couple of years old now. I'll try and find it again if you're interested.
Sshh, we all want the chance to pwn his machine, think I'll turn it into an ET server for the day
philip.j.fry is offline   Reply With Quote
Old 11-05-2005, 19:54   #12
Cable Forum Team
 
David F's Avatar
 
Join Date: Feb 2005
Location: midlands
Age: 39
Services: Mummy that man was nasty to me!!!
Posts: 17,971
David F has a golden auraDavid F has a golden auraDavid F has a golden aura
David F has a golden auraDavid F has a golden auraDavid F has a golden auraDavid F has a golden auraDavid F has a golden auraDavid F has a golden auraDavid F has a golden auraDavid F has a golden auraDavid F has a golden auraDavid F has a golden auraDavid F has a golden auraDavid F has a golden aura
Send a message via AIM to David F Send a message via MSN to David F Send a message via Yahoo to David F
Re: The Experimentâ„¢

Quote:
Originally Posted by Richard M
Thanks for mentioning that, I recently read somewhere that around 40% of XP machines do not have SP1 - can't find the link though.
I come up against this yesterday,The machine was bought from a local store resently and this come with xp with no service packs,the guy had wondered why his camera said usb to slow
__________________
zinglebarb was here
The blade twists you feel it burn it hurts so bad! how many more times in this life before it kills
Arrrrrrrrrrrrrghhhhhhhhhhhhh !!!!!!!!!!!!
David F is offline   Reply With Quote
Old 11-05-2005, 21:09   #13
cf.addict
 
MrBen's Avatar
 
Join Date: Jul 2004
Location: Woking, Surrey
Posts: 103
MrBen is a splendid one to beholdMrBen is a splendid one to beholdMrBen is a splendid one to beholdMrBen is a splendid one to beholdMrBen is a splendid one to beholdMrBen is a splendid one to beholdMrBen is a splendid one to beholdMrBen is a splendid one to beholdMrBen is a splendid one to behold
Re: The Experimentâ„¢

Quote:
Originally Posted by zinglebarb
The machine was bought from a local store resently and this come with xp with no service packs
That's just shoddy in my opinion. It's not hard to install SP2 on a brand-new computer, if store uses a single image they could slipstream SP2 so they wouldn't even need to do anything after the install.

Windows XP Gold (i.e. no service packs) will now not get any further security updates.

Back on topic, I read it's only supposed to be about 20 minutes now before you get 'infected'. I wonder though if the ntl: port blocking will have an effect? ("...Blaster worms spread over port 135, which has already been blocked [by ntl:]")

Ben
MrBen is offline   Reply With Quote
Old 11-05-2005, 21:22   #14
Busy Admin
 
Paul M's Avatar
 
Join Date: Oct 2003
Location: Nottingham
Age: 45
Services: VM Phone : Sky+ Multiroom : VM Cable (20 Mbps)
Posts: 14,485
Paul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny star
Paul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny star
Send a message via ICQ to Paul M
Re: The Experimentâ„¢

Quote:
Originally Posted by Gareth
I'm with Paul M on this one... why exactly are you doing it? It's been done before. I remember seeing a report at sans about an out-of-the-box XP machine being compromised within 18 minutes. If I remember correctly, this article itself is a couple of years old now. I'll try and find it again if you're interested.
Well I wasn't worried about it being done before. I'm just curious about the reason for doing on a box with no SP at all, as SP1 has been around for so long now. I would be interested in that link about 40% of XP machines having no SP, as that's quite a surprise to me.
__________________
DigiGuide Click here for a real, interactive, tv guide.
Paul M is offline   Reply With Quote
Old 11-05-2005, 21:23   #15
cf.mega poster
 
Join Date: Nov 2003
Location: Reading
Age: 24
Services: Virgin Media Broadband Size M
Posts: 6,849
Chris W has a nice shiny star
Chris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny star
Send a message via MSN to Chris W
Re: The Experimentâ„¢

Quote:
Originally Posted by MrBen
I wonder though if the ntl: port blocking will have an effect? ("...Blaster worms spread over port 135, which has already been blocked [by ntl:]")

Ben
I doubt it will effect a machine connected via nildram
__________________
Chinese Proverb: Man who walks round with hand in pocket feels cocky all day.
Chris W is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


All times are GMT +1. The time now is 08:43.


Links
Google
 
Web www.cableforum.co.uk


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0
Copyright © 2003 - 2008, Cable Forum.
(s204569790.onlinehome.info)