EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS


Eye on Microsoft: Another Messy Week for Security

Posted in Microsoft, Security, Windows at 5:25 pm by Dr. Roy Schestowitz

The state of the botnet is a reality that can’t be immediately escaped unless there is a large-scale disconnection of Windows-running PCs. However, rather than making steps in the right direction, the situation appears to be worsening.

This post is a quick roundup (due to time constraints) of the past week’s developments, with special emphasis on complete comprise that brings the world SPAM, DDOS attacks, espionage, ransom, and wasted productivity.

Rise of the Zombies

Halloween is far behind, but the zombies are back.

Most of Srizbi’s new command and control servers were located in Estonia and all of its domains were registered in Russia. For about 13 hours, some 100,000 or so infected machines had the ability to connect to those servers, though it’s not clear exactly how many of them did so, since many of them were likely not powered on, Lanstein said.

IDG covered this too.

The zombie computers used to send spam are coming back to life.

Security vendors say spammers are reconnecting with hacked PCs used for sending spam as evidenced by a rising number of spam messages circulating on the Internet the last few days. Spam levels suddenly dropped two weeks ago after the shutdown of McColo, a rogue ISP (Internet Service Provider) based in San Jose, California, whose connectivity was used to control networks of hundreds of thousands of computers to send spam, known as botnets.

According to the following report, these botnets can easily increase their size by recruiting more nodes.

A new analysis of botnets has come up with a possible reason for their prodigious ability to infect PCs — many anti-virus programs are near to useless in blocking the binaries used to spread them.

SPAM on the Rise Again

A recent statistic suggested that over 150 billion SPAM messages are sent per day. Biblical proportions by all means! Some of this can be intercepted at server level, but it increases load on the servers (and thus everyone’s connection fees), not to mention the severe issue of false positives (especially affecting businesses that rely on E-mail).

With increase in botnet activity comes increase in SPAM that threatens small businesses.

The fight against spam rages on after a spike in spam levels following the shut-down of hosting service McColo. SMBs are particularly vulnerable to malware and spam; ensuring secure, spam-free email should be a prominent security interest.

This was also covered by the BBC.

Spam on rise after brief reprieve

Some 450,000 infected computers have been spotted trying to connect to the largest of the networks McColo hosted.

Worms Warming Up

More worm problems emerge:

1. Vulnerable Windows Machines Sitting Ducks for the Conficker Worm

First Microsoft, and now McAfee is warning Windows users to expedite the process of applying a patch for a Critical vulnerability in Server Service affecting both client and server versions of the operating system.

According to the Redmond company, all supported platforms are vulnerable, including Windows 2000, Windows XP (even SP3), Windows Vista RTM/SP1, Windows Server 2003, Windows Server 2008 and Windows 7. McAfee has indicated that users not deploying the patch are vulnerable, while Microsoft has already informed that it had detected active attacks and infections in the wild, following a period when exploits were just targeted.

2. Windows worm infection accelerates

Microsoft is currently observing an increase in the spread of a new Windows worm that exploits the known vulnerability in the RPC functions of the Server service to penetrate systems. The infection rate of Conficker.A worm is reported to be accelerating over company networks in particular. The Microsoft Malware Protection Center says most reports are coming from the USA, but customers in Europe, Asia and South America too are affected, and reports have also been received from several hundred home users.

3. Microsoft Warns of Worm Attack on Windows

Security researchers at Microsoft Corp. last week warned of a significant climb in exploits of a Windows bug it patched with an emergency fix last month, confirming earlier reports by Symantec Corp.

Microsoft again urged users to apply the MS08-067 patch if they have not already done so.

4. Microsoft Warns Of Attack Exploiting Windows Vulnerability

Specifically, the worm deletes any use-created System Restore points, and attempts to contact numerous sites, including those of Google, Yahoo, MSN and ask.com, to obtain the current date, according to researchers at the SANS Institute. The worm then uses the date information to generate a list of domain names, which it then contacts in an attempt to download additional malicious files onto a user’s affected computer.

5. Microsoft warns of new Windows attacks

The new attacks, which Microsoft’s Malware Protection Center said began over the weekend but spiked during the past two days, use the same worm that Symantec first spotted last Friday.

6. Microsoft: Worm Exploiting Networked Computers via HTTP

Microsoft informed in its most recent security bulletin that a worm dubbed Win32/Conficker.gen!A is messing around with computers across a network by exploiting a vulnerability in the Windows Server service, allowing remote code execution to take place while file sharing is enabled.

How did computing fall into this mess? Well, the following article magically vanished (we did try to find it again, to no avail), but its headline was (is) “Microsoft Not Rushing To Fix Vista Kernel Vulnerability.” The disappearance of this article might be innocent, but it still raises a brow.

We covered this last week. Even when severe flaws are found, Microsoft will leave them unpatched unless or until there is an attack exploiting them, i.e. when it’s too late. It is not only vain but it’s also irresponsible. It also enables Microsoft to ‘massage’ and lie about security using meaningless figures [1, 2, 3].

Once infected, nothing on a machine can be trusted, as proven by this new report.

A DANGEROUS new variant of malware is attacking PCs in the UK, the INQ has discovered. It hijacks the victim’s browser and directs them to a fake site masquerading as AVG’s own front page.

Needless to say, without radical change, things are bound to get worse before they get better. It’s time for consideration of secure platforms.

Fire alarm

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one


  1. oiaohm said,

    November 30, 2008 at 6:17 pm


    Problem is a lot deeper. Look at MS so call security systems.

    If the core security system of the OS does not work all it takes is a exploit to see the complete OS fail.

    Reports have been in for years that the DAC on windows needs work. Even the new MIC from Microsoft is not up to scratch.

  2. advocatus said,

    December 1, 2008 at 2:28 am


    Missing article’s still in Google cache:

    ‘Monday November 24, 2008
    Microsoft Not Rushing To Fix Vista Kernel Vulnerability

    Software Patches, Vulnerabilities, Windows Vista

    TCP/IP, vista, vulnerabilities, windows xp

    A vulnerability in the Windows Vista Kernel hasn’t generated much panic from either researchers or Microsoft several days after its public release.

    The vulnerability occurs in adding a route entry to the IPv4 routing table through the CreateIpForwardEntry2 API. It can be exploited through the route command line tool, which is included with Vista. The disclosure claims there are no workarounds. According to this article, Microsoft says that they will fix the bug in the next Vista service pack.

    The vulnerability requires that the user be a member of either the Administrator group or the Network Configuration Operators group, and this explains the lack of concern. In Windows XP this would not be much of a barrier for a vulnerability, as so many users run as Administrators, but in Vista this is much less common.

    To exploit the vulnerability, the attacker would have to convince the user to execute a malicious program on the PC. This might be as simple as a batch file which ran the route command, or a specially-crafted executable. The vulnerability is a stack overflow in the TCP/IP code, and a successful exploit would give the attacker full control over the PC,

    But since the exploit is a buffer overflow, it also has to get past the Vista barriers of DEP and ASLR. As I have discussed recently, these are formidable barriers to invoking an exploit on Vista. The lack of interest in what would be a top-tier vulnerability in XP is yet another sign of how far Vista has gone to block such exploits.’

What Else is New

  1. The Broken Window Economics of Patent Trolls Are Already Coming to Europe

    The plague which is widely known as patent trolls (non-practicing entities that prey on practicing companies) is being spread to Europe, owing in part to misguided policies and patent maximalists

  2. Debunking the EPO's Latest Marketing Nonsense From Les Échos and More on Benoît Battistelli's Nastygram to French Politician

    Our detailed remarks about French brainwash from the EPO's media partner (with Benoît Battistelli extensively quoted) and the concerns increasingly raised by French politicians, who urge for national or even continental intervention

  3. The Sun King Delusion: The Views of Techrights Are Just a Mirror of EPO Staff Unions

    Tackling some emerging spin we have seen coming from Battistelli's private letters -- spin which strives to project the views of Techrights onto staff unions and why it's very hypocritical a form of spin

  4. Links /11/2015: Webconverger 33.1, Netrunner 17 Released

    Links for the day

  5. United They Stand: FFPE-EPO Supports Suspended Staff Representatives From SUEPO

    An obscure union from the Dutch side of things at the EPO is expressing support for the suspended colleagues from SUEPO (more German than Dutch)

  6. Censoring WIPR Article About Censorship by EPO

    A testament to how terrified journalists have become when it comes to EPO coverage, to the point of deleting entire paragraphs

  7. Censorship at the EPO Escalates: Now We Have Threats to Sue Publishers

    Having already blocked Techrights, the EPO's management proceeds to further suppressions of speech, impeding its staff's access to independently-distributed information (neither ordinary staff nor management)

  8. Response to Bogus Accusations That EPO Staff Protests Are Really an Attempt to Derail UPC

    Common myths about staff protests in the European Patent Office (EPO) debunked, with some additional background and general perspective on recent events, the unitary patent (UPC) and so on

  9. New Heise Article Makes It Clear That 'Nazi'-Themed Accusations Against the Suspended Board Judge Were Insufficiently Substantiated

    The personal attacks on a judge who was illegally suspended (a so-called 'house ban') increasingly look like the management's own campaign of defamation, mostly intended to marginalise and punish a judge who spoke about serious charges against VP4 (Željko Topić)

  10. Links 24/11/2015: Asus Chromebit CS10, Second Linux 4.4 RC

    Links for the day

  11. European Central Bank Staff Committee Adds to Growing Pressure on Abusive EPO Management

    The staff representatives of the European Central Bank E-mail their colleagues -- with European Central Bank managers' approval -- regarding the European Patent Office and its attacks on staff unions

  12. Gross Violation of Workers' Rights in EPO: Denial of Christmas Vacation/Leave for Slower Workers

    A look at an E-mail from within the EPO which shows how Christmas is used to squeeze staff, urging them to work even faster (despite speed gains) or lose their Christmas leave

  13. The Bogus Narrative Floated by EPO Management: Our Judges and Examiners Are Armed and Violent

    A look at the union-busting and protest-crushing moves from high-level EPO managers, who are trying to convince politicians that they do so in an effort to stop terrorists and neo-Nazis

  14. Support SUEPO or End Up Like They and Some of the Boards Did

    SUEPO, the fast-growing staff union of the EPO, increasingly needs the support and protection offered by action and participation from staff

  15. NRC Handelsblad (Dutch Evening Newspaper) Speaks About EPO's Refusal to Accept Court Orders From The Hague

    Article explains the depths of the issues inside the EPO and the unacceptable immunity that management at the EPO continues to exploit, shaming or discrediting the very notion of the rule of law in Europe

  16. HeBS Digital and Black Duck Press Releases Treated Like Articles, Used to Muddy the FOSS Waters

    Free/Open Source software (FOSS) is under attack again, and it's the proprietary software lobby that's responsible for that

  17. EPO President Battistelli Now Intimidates Even National Delegations

    Report about an embarrassing incident implicating Benoît Battistelli and some angry comments cast over the witch-hunting of a judge, using all sorts of questionable tactics

  18. A Look at the Latest Gross Deletionism at the EPO's 'Media Partner', French Newspaper Les Échos

    The EPO's bogus 'journal of record, which Team Battistelli likes to cite in order to bolster its warped version of events at the EPO while maintaining a close secret relationship with the publisher, keeps censoring its own reporters (spiked paragraphs, silently self-censored or censored after publications)

  19. Rumour About Efforts to Dismiss a Board Judge by Intimidating Boards of Appeal

    Comment found online accuses the Administrative Council of pressuring, by threats, Directorate-General 3 to dismiss a judge who is silently accused (with selective 'leaks' to the media, reportedly orchestrated by EPO managers) but not even proven guilty

  20. President Battistelli Now Pressures/Threatens Politicians Who 'Dare' to Complain About Abuses and Unacceptable Conditions at the EPO

    Pierre-Yves Le Borgn’, a French politician, unleashes an angry letter from Benoît Battistelli and reveals just to what lengths the EPO's Team Battistelli is willing to go in order to crush political backlash

  21. EPO: It's Like a Family Business - Part IV

    Some more background information about Elodie Bergot and Gilles Requena, who are married whilst also sharing positions of power at the EPO (and also strong connections/ties with the EPO's President, Mr. Battistelli); Rumours afloat at the EPO -- some with ever-increasing circulation too -- are worth noting

  22. Translation of Thomas Magenheim-Hörmann's Article in the German Media, Urging European Politicians to Intervene in EPO Chaos and Lawlessness

    Frankfurt-based media presents an opinion piece written by a Munich-based economic correspondent, Thomas Magenheim-Hörmann

  23. German Press Says Broken EPO Lets President Severely Punish Staff Not Even Guilty of Any Wrongdoing

    Juve publishes an article which attempts to be 'balanced' (meaning it believes everything that EPO officials say) but at the same time reveals unacceptable practices that go in inside the EPO

  24. German Media Reveals That Out-of-Control EPO Management is Even Threatening and Abusing Lawyers Now

    The EPO's longstanding fight against justice escalates to an unprecedented war on lawyers themselves; “After this latest move,” says a German newspaper, “even lawyers are starting to feel threatened by the Office.”

  25. Washington Post Only Entertains Debate About Patent Trolls (But Not Patent Scope) Whilst US Lawyers Trick the System to Patent Software

    The Bezos-owned Washington Post continues to help those who wish to eliminate patent trolls (which bother Amazon amongst other large conglomerates) but remains void of any coverage about patent scope, including software patents that patent lawyers work so hard to defend

  26. It Pays (Off) to 'Bribe' the Media: Watch How Les Échos Covers EPO Matters and Self-Censors

    French newspaper Les Échos is self-censoring yet again and it is framing the EPO scandals as the fault of employees, not the fault of abusive managers who are working with Les Échos as a so-called 'media partner' (the EPO management is French-dominated)

  27. 'Leaked' PDF Shows How EPO Management Tried to Crush Judge Who 'Dared' to Criticise EPO Management

    The EPO's management continues to chill potential critics and is now making an example of a board's judge, despite having no such authority over him

  28. Links 21/11/2015: Community Appreciation Day, Jolla's Problems

    Links for the day

  29. EPO: It's Like a Family Business - Part III

    A look at how the EPO's management (Željko Topić in particular) defended the unprecedented promotion of Ms Bergot (wife of the president's close assistant), even in the face of outcry from EPO staffwarning

  30. In an Effort to Counter EPO Staff Narrative (After ~2,000 of Staff Protest) EPO Management Portrays Staff as Violent But Provides No Evidence

    The EPO's management has a poor record on accuracy and truth and the latest staff-shaming tactics serve to reinforce that track record


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time


Recent Posts