EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

11.30.08

Eye on Microsoft: Another Messy Week for Security

Posted in Microsoft, Security, Windows at 5:25 pm by Dr. Roy Schestowitz

The state of the botnet is a reality that can’t be immediately escaped unless there is a large-scale disconnection of Windows-running PCs. However, rather than making steps in the right direction, the situation appears to be worsening.

This post is a quick roundup (due to time constraints) of the past week’s developments, with special emphasis on complete comprise that brings the world SPAM, DDOS attacks, espionage, ransom, and wasted productivity.

Rise of the Zombies

Halloween is far behind, but the zombies are back.

Most of Srizbi’s new command and control servers were located in Estonia and all of its domains were registered in Russia. For about 13 hours, some 100,000 or so infected machines had the ability to connect to those servers, though it’s not clear exactly how many of them did so, since many of them were likely not powered on, Lanstein said.

IDG covered this too.

The zombie computers used to send spam are coming back to life.

Security vendors say spammers are reconnecting with hacked PCs used for sending spam as evidenced by a rising number of spam messages circulating on the Internet the last few days. Spam levels suddenly dropped two weeks ago after the shutdown of McColo, a rogue ISP (Internet Service Provider) based in San Jose, California, whose connectivity was used to control networks of hundreds of thousands of computers to send spam, known as botnets.

According to the following report, these botnets can easily increase their size by recruiting more nodes.

A new analysis of botnets has come up with a possible reason for their prodigious ability to infect PCs — many anti-virus programs are near to useless in blocking the binaries used to spread them.

SPAM on the Rise Again

A recent statistic suggested that over 150 billion SPAM messages are sent per day. Biblical proportions by all means! Some of this can be intercepted at server level, but it increases load on the servers (and thus everyone’s connection fees), not to mention the severe issue of false positives (especially affecting businesses that rely on E-mail).

With increase in botnet activity comes increase in SPAM that threatens small businesses.

The fight against spam rages on after a spike in spam levels following the shut-down of hosting service McColo. SMBs are particularly vulnerable to malware and spam; ensuring secure, spam-free email should be a prominent security interest.

This was also covered by the BBC.

Spam on rise after brief reprieve

Some 450,000 infected computers have been spotted trying to connect to the largest of the networks McColo hosted.

Worms Warming Up

More worm problems emerge:

1. Vulnerable Windows Machines Sitting Ducks for the Conficker Worm

First Microsoft, and now McAfee is warning Windows users to expedite the process of applying a patch for a Critical vulnerability in Server Service affecting both client and server versions of the operating system.

According to the Redmond company, all supported platforms are vulnerable, including Windows 2000, Windows XP (even SP3), Windows Vista RTM/SP1, Windows Server 2003, Windows Server 2008 and Windows 7. McAfee has indicated that users not deploying the patch are vulnerable, while Microsoft has already informed that it had detected active attacks and infections in the wild, following a period when exploits were just targeted.

2. Windows worm infection accelerates

Microsoft is currently observing an increase in the spread of a new Windows worm that exploits the known vulnerability in the RPC functions of the Server service to penetrate systems. The infection rate of Conficker.A worm is reported to be accelerating over company networks in particular. The Microsoft Malware Protection Center says most reports are coming from the USA, but customers in Europe, Asia and South America too are affected, and reports have also been received from several hundred home users.

3. Microsoft Warns of Worm Attack on Windows

Security researchers at Microsoft Corp. last week warned of a significant climb in exploits of a Windows bug it patched with an emergency fix last month, confirming earlier reports by Symantec Corp.

Microsoft again urged users to apply the MS08-067 patch if they have not already done so.

4. Microsoft Warns Of Attack Exploiting Windows Vulnerability

Specifically, the worm deletes any use-created System Restore points, and attempts to contact numerous sites, including those of Google, Yahoo, MSN and ask.com, to obtain the current date, according to researchers at the SANS Institute. The worm then uses the date information to generate a list of domain names, which it then contacts in an attempt to download additional malicious files onto a user’s affected computer.

5. Microsoft warns of new Windows attacks

The new attacks, which Microsoft’s Malware Protection Center said began over the weekend but spiked during the past two days, use the same worm that Symantec first spotted last Friday.

6. Microsoft: Worm Exploiting Networked Computers via HTTP

Microsoft informed in its most recent security bulletin that a worm dubbed Win32/Conficker.gen!A is messing around with computers across a network by exploiting a vulnerability in the Windows Server service, allowing remote code execution to take place while file sharing is enabled.

How did computing fall into this mess? Well, the following article magically vanished (we did try to find it again, to no avail), but its headline was (is) “Microsoft Not Rushing To Fix Vista Kernel Vulnerability.” The disappearance of this article might be innocent, but it still raises a brow.

We covered this last week. Even when severe flaws are found, Microsoft will leave them unpatched unless or until there is an attack exploiting them, i.e. when it’s too late. It is not only vain but it’s also irresponsible. It also enables Microsoft to ‘massage’ and lie about security using meaningless figures [1, 2, 3].

Once infected, nothing on a machine can be trusted, as proven by this new report.

A DANGEROUS new variant of malware is attacking PCs in the UK, the INQ has discovered. It hijacks the victim’s browser and directs them to a fake site masquerading as AVG’s own front page.

Needless to say, without radical change, things are bound to get worse before they get better. It’s time for consideration of secure platforms.

Fire alarm

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

2 Comments

  1. oiaohm said,

    November 30, 2008 at 6:17 pm

    Gravatar

    Problem is a lot deeper. Look at MS so call security systems.

    If the core security system of the OS does not work all it takes is a exploit to see the complete OS fail.

    Reports have been in for years that the DAC on windows needs work. Even the new MIC from Microsoft is not up to scratch.

  2. advocatus said,

    December 1, 2008 at 2:28 am

    Gravatar

    Missing article’s still in Google cache:
    http://74.125.77.132/search?q=cache:U-koBaBSiNAJ:blogs.pcmag.com/securitywatch/2008/11/microsoft_not_rushing_to_fix_v.php+http://blogs.pcmag.com/securitywatch/2008/11/microsoft_not_rushing_to_fix_v.php&hl=en&ct=clnk&cd=1

    ‘Monday November 24, 2008
    Microsoft Not Rushing To Fix Vista Kernel Vulnerability
    Categories:

    Software Patches, Vulnerabilities, Windows Vista
    Tags:

    TCP/IP, vista, vulnerabilities, windows xp

    A vulnerability in the Windows Vista Kernel hasn’t generated much panic from either researchers or Microsoft several days after its public release.

    The vulnerability occurs in adding a route entry to the IPv4 routing table through the CreateIpForwardEntry2 API. It can be exploited through the route command line tool, which is included with Vista. The disclosure claims there are no workarounds. According to this article, Microsoft says that they will fix the bug in the next Vista service pack.

    The vulnerability requires that the user be a member of either the Administrator group or the Network Configuration Operators group, and this explains the lack of concern. In Windows XP this would not be much of a barrier for a vulnerability, as so many users run as Administrators, but in Vista this is much less common.

    To exploit the vulnerability, the attacker would have to convince the user to execute a malicious program on the PC. This might be as simple as a batch file which ran the route command, or a specially-crafted executable. The vulnerability is a stack overflow in the TCP/IP code, and a successful exploit would give the attacker full control over the PC,

    But since the exploit is a buffer overflow, it also has to get past the Vista barriers of DEP and ASLR. As I have discussed recently, these are formidable barriers to invoking an exploit on Vista. The lack of interest in what would be a top-tier vulnerability in XP is yet another sign of how far Vista has gone to block such exploits.’

What Else is New


  1. Links 19/4/2018: Mesa 17.3.9 and 18.0.1, Trisquel 8.0 LTS Flidas, Elections for openSUSE Board

    Links for the day



  2. The Patent Microcosm, Patent Trolls and Their Pressure Groups Incite a USPTO Director Against the Patent Trial and Appeal Board (PTAB) and Section 101/Alice

    As one might expect, the patent extremists continue their witch-hunt and constant manipulation of USPTO officials, whom they hope to compel to become patent extremists themselves (otherwise those officials are defamed, typically until they're fired or decide to resign)



  3. Microsoft's Lobbying for FRAND Pays Off as Microsoft-Connected Patent Troll Conversant (Formerly MOSAID) Goes After Android OEMs in Europe

    The FRAND (or SEP) lobby seems to have caused a lot of monopolistic patent lawsuits; this mostly affects Linux-powered platforms such as Android, Tizen and webOS and there are new legal actions from Microsoft-connected patent trolls



  4. To Understand Why People Say That Lawyers are Liars Look No Further Than Misleading Promotion of Software Patents

    Some of the latest misleading claims from the patent microcosm, which is only interested in lots and lots of patents (its bread and butter is monopolies after all) irrespective of their merit, quality, and desirability



  5. When News About the EPO is Dominated by Sponsored 'Reports' and Press Releases Because Publishers Are Afraid of (or Bribed by) the EPO

    The lack of curiosity and genuine journalism in Europe may mean that serious abuses (if not corruption) will go unreported



  6. The Boards of Appeal at the European Patent Organisation (EPO) Complain That They Are Understaffed, Not Just Lacking the Independence They Depend on

    The Boards of Appeal have released a report and once again they openly complain that they're unable to do their job properly, i.e. patent quality cannot be assured



  7. Links 18/4/2018: New Fedora 27 ISOs, Nextcloud Wins German Government Contract

    Links for the day



  8. Guest Post: Responding to Your Recent Posting “The European Patent Office Will Never Hold Its Destroyers Accountable”

    In France, where Battistelli does not enjoy diplomatic immunity, he can be held accountable like his "padrone" recently was



  9. The EPO in 2018: Partnering With Saudi Arabia and Cambodia (With Zero European Patents)

    The EPO's status in the world has declined to the point where former French colonies and countries with zero European Patents are hailed as "success stories" for Battistelli



  10. For Samsung and Apple the Biggest Threat Has Become Patent Trolls and Aggressors in China and the Eastern District of Texas, Not Each Other

    The latest stories about two of the world's largest phone OEMs, both of which find themselves subjected to a heavy barrage of patent lawsuits and even embargoes; Samsung has meanwhile obtained an antisuit injunction against Huawei



  11. The EPO Continues to Lie About Patent Quality Whilst Openly Promoting Software Patents, Even Outside Europe

    EPO patent quality continues to sink while EPO management lies about it and software patents are openly being promoted/advocatedEPO patent quality continues to sink while EPO management lies about it (the article above is new) and software patents are openly being promoted/advocated



  12. SCOTUS on WesternGeco v Ion Geophysical Almost Done; Will Oil States Decision Affirm the PTAB's Quality Assurance (IPRs) Soon?

    Ahead of WesternGeco and Oil States, following oral proceedings, it's expected that the highest court in the United States will deliver more blows to patent maximalism



  13. Links 17/4/2018: Linux 5.x Plans and Microsoft's 'Embrace'

    Links for the day



  14. The European Patent Office (EPO) Grants Patents in Error, Insiders Are Complaining That It's the Management's Fault

    The EPO has languished to the point where patents are granted in error, examiners aren't happy, and the resultant chaos benefits no-one but lawyers and patent trolls



  15. The European Patent Office Will Never Hold Its Destroyers Accountable

    With only one in seven EPO stakeholders believing that Battistelli's pick (António Campinos) will turn things around for the better, it certainly does not seem like people are happy and there's no real hope that Battistelli will ever be held accountable for his abuses after his immunity expires



  16. With Liars Like These...

    The European Patent Office continues to lie about the Unified Patent Court (UPC) amongst other things, still revealing its reluctance to say anything which is truthful or work to repair the damage caused by Benoît Battistelli



  17. Links 16/4/2018: Linux 4.17 RC 1, Mesa 18.0.1 RC, GNOME 3.28.1

    Links for the day



  18. IAM, Patently-O and Watchtroll (the Patent Trolls' Lobby) Try to Stop Patent Oppositions/Petitions (PTAB)

    In spite of fee hikes, introduced by Iancu's interim predecessor, petitions (IPRs) at the PTAB continue to grow in number and the patent maximalists are losing their minds over it



  19. The Patent Trial and Appeal Board (PTAB) is Ending Software Patents One Patent at a Time

    At an accelerating pace and with growing determination, PTAB (part of AIA) crushes patent trolls and software patents; the statistics and latest stories speak for themselves



  20. Academics and Think Tanks for Patent Maximalism

    Right-wing think tanks and impressionable academics continue to lobby for patent maximalism, rarely revealing the funding sources and motivations; in reality, however, such maximalism mainly helps large (already-wealthy) corporations, monopolists, and law firms



  21. Killing Patent Quality and Encouraging 'Covert' Software Patents Using the Buzzwords Du Jour

    The epidemic of buzzwords and/or hype waves that are being exploited to dodge or bypass patent scope/limitations, as seen in Europe and the US these days



  22. Crisis of Quality at the EPO Extends to Staff (Notably Examiners) and Management as Institutional Integrity is Severely Compromised

    A rather pessimistic but likely realistic outlook for the European Patent Office (EPO), which seems unable to attract the sort of staff it attracted for a number of decades



  23. The 'Blockchaining' of Software Patents (to Dodge the Rules/Guidelines) Now Coming to Europe

    A lot of software patents are being declared invalid (or not granted in the first place); having said that, using all sorts of hype waves (like calling databases “blockchains”) firms and individuals manage to still be granted software patents and sometimes patent trolls hoard these



  24. Links 14/4/2018: Wine 3.6, KDE Elisa 0.1

    Links for the day



  25. East Asia Should Have Adopted the Patent Strategy of South Asia, Notably India

    China seems to be so interested in patent maximalism that it has lost sight of the effect on foreign investment, e.g. US/European/Taiwanese/Japanese/Korean firms operating/manufacturing in mainland China



  26. Samsung is the 'New IBM', Sans the Trolling With Patents

    The 'relic' company, IBM, loses its patent leadership (as measured using some yardstick) to Samsung, a company which is relatively calm when it comes to patent activity (unless/only when sued, as happens a lot nowadays)



  27. David Barcelou May or May Not be a Patent Troll, But He is Certainly a SLAPPing Bully and Watchtroll is Fine With It

    Like a thin-skinned person/entity (which many in the patent microcosm are), David Barcelou and Automated Transactions (“ATL”) SLAPP their critics and surprisingly enough it's Watchtroll, who has been threatened by WIPO, coming to the bully's rescue (double standards)



  28. Links 12/4/2018: Stable New Kernels, Neptune 5.1

    Links for the day



  29. The USPTO Has a Nepotism and Lobbying Problem That Jeopardises the Rationality of US Patent Law

    The influence games of Washington are spilling over to the US patent office and poisoning/harming its ability to conduct professional operations without corporate influence (from either side, both corporations and law firms)



  30. Patent Trolls in the United States Show the Importance of Stopping Software Patents (Trolls' Favourite) Worldwide

    The abundance of entities that exist for no purpose other than to initiate lawsuits is a contagious threat to real innovation (or science and technology being practiced); a new jury verdict (record-breaking $500,000,000) is a reminder of this


CoPilotCo

RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

CoPilotCo

Recent Posts