12.15.08

Gemini version available ♊︎

Microsoft™ Windows™ Zombies®

Posted in GNU/Linux, Microsoft, Security, Windows at 5:53 am by Dr. Roy Schestowitz

Do something good for yourself: spread GNU/Linux

This month was a particularly bad one for Microsoft security, but it’s getting worse. It’s easy to see why Microsoft has become so paranoid when it comes to perceptions of Windows security (insecurity). It even twists the arms of journalists now.

There are several important reports that we have not included here yet, so here is a quick rundown.

Internet Explorer Under Fire

This is pretty serious. Here is coverage of the key point:

1. IE zero day bites broader group of users

Secunia goes on to revise what it says is the cause of the vulnerability. Contrary to earlier reports that pinned the blame on the way IE handles certain types of data that use the extensible markup language, or XML, format, the true cause is faulty data binding, meaning exploit code need not use XML.

2. Microsoft: IE5, IE6 Also Affected by Browser Vulnerability

An unpatched vulnerability found in Internet Explorer 7 also affects older versions of the browser as well as the latest beta version, Microsoft warned Thursday.

The new information widens the pool of users who could be at risk of inadvertently becoming infected with malicious software installed on their PC, as Microsoft does not yet have a patch ready.

In an advisory updated on Thursday, Microsoft confirmed that IE 5.01 with Service Pack 4, IE6 with and without Service Pack 1 and IE8 Beta 2 on all versions of the Windows operating system are potentially vulnerable.

3. All Internet Explorer Versions Have Hole?

The unpatched bug in Internet Explorer 7 (IE7) that hackers are now exploiting also exists in older versions of the browser, including the still-widely-used IE6, Microsoft Corp. said.

Friday, a Danish security researcher added that Microsoft’s original countermeasure advice was insufficient, and recommended users take one of the new steps the company spelled out.

There is an early fix for this flaw. It’s called Mozilla Firefox, but there are other fixes available.

Having Only Oneself to Blame

Would it be considered acceptable that Microsoft is patching a known security hole 7 years late?

Microsoft recently released two new patches, one of which fixes a security hole that the company has been trying to plug since 2001.

It was only days ago that Microsoft patched no less than six “critical” flaws.

Palo Alto Networks today announced that its Threat Research Team discovered one of the six critical vulnerabilities communicated in Microsoft’s Patch Tuesday security bulletin this week.

The Future

With so many holes that are most severe, no wonder virtually every Windows box is open to hijackers and almost half of them are already hijacked. The press is rightly preoccupied with stories about the global financial crisis, but one security vendor believes that cybercrime has become an even greater problem.

You might have noticed that the economy is in the tank. Something about this “credit crunch” and “recession” and whatnot. But the amount of attention governments around the world are paying to these issues is giving cybercrime a foothold, according to a new study from a — yep, you guessed it — security vendor…

As the economy declines, this is bound to get worse.

Desperate IT workers who have been laid off will go rogue in 2009, selling corporate data and using crimeware, reports have predicted.

The credit crunch will drive some IT workers to use their skills to steal credit-card data using phishing attacks, and abuse their privileged corporate computer access to sell off valuable financial and intellectual information, forensic experts have warned.

How did we get here and how will we get out of this? Download a fix now.

Ogg Theora

Direct link

Share in other sites/networks: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Reddit
  • email

Decor ᶃ Gemini Space

Below is a Web proxy. We recommend getting a Gemini client/browser.

Black/white/grey bullet button This post is also available in Gemini over at this address (requires a Gemini client/browser to open).

Decor ✐ Cross-references

Black/white/grey bullet button Pages that cross-reference this one, if any exist, are listed below or will be listed below over time.

Decor ▢ Respond and Discuss

Black/white/grey bullet button If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

DecorWhat Else is New


  1. IRC Proceedings: Saturday, June 03, 2023

    IRC logs for Saturday, June 03, 2023



  2. Links 04/06/2023: Azure Outage Again (So Many!) and Tiananmen Massacre Censored

    Links for the day



  3. Links 03/06/2023: Qubes OS 4.2.0 RC1 and elementaryOS Updates for May

    Links for the day



  4. Gemini Links 03/06/2023: Hidden Communities and Exam Prep is Not Education

    Links for the day



  5. Links 03/06/2023: IBM Betraying LibreOffice Some More (After Laying off LibreOffice Developers)

    Links for the day



  6. Gemini Links 03/06/2023: Bubble Woes and Zond Updates

    Links for the day



  7. Links 03/06/2023: Apache NetBeans 18 and ArcaOS 5.0.8

    Links for the day



  8. IRC Proceedings: Friday, June 02, 2023

    IRC logs for Friday, June 02, 2023



  9. The Developing World Abandons Microsoft Windows, GNU/Linux at All-Time Highs on Desktops/Laptops

    Microsoft, with 80 billion dollars in longterm debt and endless layoffs, is losing the monopolies; the media doesn’t mention this, but some publicly-accessible data helps demonstrate that



  10. Links 02/06/2023: Elive ‘Retrowave’ Stable and Microsoft's Half a Billion Dollar Fine for LinkeIn Surveillance in Europe

    Links for the day



  11. Linux Foundation 'Research' Has a New Report and Of Course It Uses Only Proprietary Software

    The Linux Foundation has a new report, promoted by Clickfraud Spamnil and others; of course they’re rejecting Free software, they’re just riding the “Linux” brand and speak of “Open Source” (which they reject themselves)



  12. Links 02/06/2023: Arti 1.1.5 and SQL:2023

    Links for the day



  13. Gemini Links 02/06/2023: Vimwiki Revisited, SGGS Revisited

    Links for the day



  14. Geminispace/GemText/Gemini Protocol Turn 4 on June 20th

    Gemini is turning 4 this month (on the 20th, according to the founder) and I thought I’d do a spontaneous video about how I use Gemini, why it's so good, and why it’s still growing (Stéphane Bortzmeyer fixed the broken cron job — or equivalent of it — a day or two after I had mentioned the issue)



  15. HMRC Does Not Care About Tax Fraud Committed by UK Government Contractor, Sirius 'Open Source'

    The tax crimes of Sirius ‘Open Source’ were reported to HMRC two weeks ago; HMRC did not bother getting back to the reporters (victims of the crime) and it’s worth noting that the reporters worked on UK government systems for many years, so maybe there’s a hidden incentive to bury this under the rug



  16. Our IRC at 15th Anniversary

    So our IRC community turns 15 today (sort of) and I’ve decided to do a video reflecting on the fact that some of the same people are still there after 15 years



  17. IRC Proceedings: Thursday, June 01, 2023

    IRC logs for Thursday, June 01, 2023



  18. Links 02/06/2023: NixOS 23.05 and Rust 1.70.0

    Links for the day



  19. Gemini Links 02/06/2023: Flying High With Gemini and Gogios Released

    Links for the day



  20. Links 01/06/2023: KStars 3.6.5 and VEGA ET1031 RISC-V Microprocessor in Use

    Links for the day



  21. Gemini Links 01/06/2023: Scam Call and Flying High With Gemini

    Links for the day



  22. Links 01/06/2023: Spleen 2.0.0 Released and Team UPC Celebrates Its Own Corruption

    Links for the day



  23. IRC Proceedings: Wednesday, May 31, 2023

    IRC logs for Wednesday, May 31, 2023



  24. Tux Machines Closing the Door on Twitter Because Twitter is Dead (for a Lot of People)

    Tux Machines recently joined millions of others who had already quit Twitter, including passive posting (fully or partly automated)



  25. Links 31/05/2023: Inkscape’s 1.3 Plans and New ARM Cortex-A55-Based Linux Chip

    Links for the day



  26. Gemini Links 31/05/2023: Personality of Software Engineers

    Links for the day



  27. Links 31/05/2023: Armbian 23.05 Release and Illegal UPC

    Links for the day



  28. IRC Proceedings: Tuesday, May 30, 2023

    IRC logs for Tuesday, May 30, 2023



  29. Gemini Protocol About to Turn 4 and It's Still Growing

    In the month of May we had zero downtime (no updates to the system or outages in the network), which means Lupa did not detect any errors such as timeouts and we’re on top of the list (the page was fixed a day or so after we wrote about it); Gemini continues to grow (chart by Botond) as we’re approaching the 4th anniversary of the protocol



  30. Links 31/05/2023: Librem Server v2, curl 8.1.2, and Kali Linux 2023.2 Release

    Links for the day


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts