EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

01.18.09

Microsoft Botnets: The Chaos Continues

Posted in Microsoft, Security, Windows at 6:50 pm by Dr. Roy Schestowitz

Zombie
Fear not the Windows zombies

There are many ways to “Suck at Information Security”, but one easy way is to choose a platform that leads to entire military bases getting cracked.

The British military is one of the very few which choose this tactless route even for nuclear submarines and it costs it dearly.

Virus ‘sends RAF e-mails to Russia’

THE Ministry of Defence is investigating a major breach in security amid claims that all e-mail traffic from a number of RAF stations has been sent to a Russian internet server.

The e-mails were allegedly diverted to the Russian sender by a worm virus that entered the MoD systems 12 days ago bringing down computers and blocking e-mail communications across the military.

The world is already filled with about 320 million Windows PCs that are zombies, so what’s another massive botnet anyway?

New Botnets Replace Vanquished Pests

Although the shutdown of a California Web hosting company eradicated several prominent botnets last year, others have stepped up to fill the gaps, a security researcher says.

Gone from the landscape, said Joe Stewart, director of research at Atlanta-based SecureWorks Inc., are “Srizbi” and “Storm,” the botnets Stewart ranked as No. 1 and No. 5, respectively, in an April 2008 botnet census.

How can anyone combat Windows worms that appear all the time in new forms?

A variant of a malicious worm that targeted Microsoft Windows now is spreading via USB sticks, researchers say.

Security company BitDefender Labs, based in Bucharest, Romania, detected the Windows worm variant in late December. The original worm known as Win32.Worm.Downadup, first made its appearance in late November, exploiting a Microsoft vulnerability in the Windows RPC Server Service. Since then, it has rapidly spread across numerous corporate networks with the aim of distributing malicious software on susceptible computers.

Even an Instant Messaging (IM) program is no longer safe because Microsoft turned simple communication protocols into something that can invoke unknown executables.

Internet MSN users are warned. Some programme writers are now using IM to spread malicious programs such as viruses and worms. These viruses can spread when a person opens an infected file, such as pictures of pornographic nature, that is sent through IM by someone who appears to be a contact.

Why is a program for exchange of text leading to the running of untrusted code? This is an architectural deficiency that would prove costly. Outlook and ActiveX are almost perfect examples and they requires no social engineering to lead to a raft of menaces.

“Our products just aren’t engineered for security.”

Brian Valentine, Microsoft executive

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

3 Comments

  1. Needs Sunlight said,

    January 19, 2009 at 9:15 am

    Gravatar

    The recurrence of MSN worms ought to be a warning that it’s past time to switch IM protocols and networks, for those still in the stoneage.

    MSN, live.com, and any other worm site ought to be blocked at the firewall. Same for ports used by MS Messenger.

    XMPP and Jabber are the next-generation chat/messenging protocols. Use them or lose out.

  2. The Mad Hatter said,

    January 19, 2009 at 9:09 pm

    Gravatar

    And of course whenever a worm/virus/security hole is mentioned in the news, they never mention that it’s a Microsoft only problem, and if you point this out to the news media, they don’t take any action. The fact that Microsoft is often one of their major advertisers has nothing to do with this of course.

  3. Roy Schestowitz said,

    January 19, 2009 at 10:07 pm

    Gravatar

    Here’s an E-mail that I received this morning (for sharing):


    Hi, Roy,

    Here’s an example of pro-MSFT spin on headlines. All it takes is one
    bad member on the editorial team and an entire publication can be
    compromised, like here:

    http://www.cnn.com/2009/TECH/ptech/01/16/virus.downadup/index.html?eref=rss_tech” title=”Downadup virus exposes millions of PCs to hijack

    The title is “Downadup virus exposes millions of PCs to hijack”. If we
    stick with the standard usage of the verb “expose” then the correct
    title is “Windows exposes millions of PCs to hijack”


    Had it been a Linux worm, there would probably be a different headline, no? The mythology of Microsoft is that “all computers” are not secure and “Windows is the standard”.

What Else is New


  1. Microsoft Tired of Pretending to be Nice to Free/Open Source Software (FOSS), Microsoft 'Open' Technologies Dumped

    Microsoft dumps its proxy (misleadingly named 'Open Tech') and other attacks on Free software persist from the inside, often through so-called 'experts' whose agenda is to sell proprietary software



  2. More Translations of French Article About the EPO

    German and Dutch translations of the Le Monde article are now available



  3. Links 17/4/2015: Wipro and the Netherlands Want FOSS

    Links for the day



  4. Microsoft's Multi-Dimensional Assault on Android/Linux: Extortion, Lobbying of Regulators, and Bribes

    Microsoft's vicious war on Linux (and Android in its current incarnation) takes more sophisticated -- albeit illegal (as per the RICO Act) -- forms



  5. Microsoft's Plot to Associate Windows with 'Open Source' is Proving Effective, Despite Being Just a Big Lie

    A look at the latest headlines which can lead to a false perception that Microsoft is now in bed with 'Open Source'



  6. Microsoft Windows Remotely Crashed, Remotely Hijacked, But Still No Logo and No Branding for the Bugs

    Windows maintains its reputation as a back doors haven, but the media is still not highlighting the severity of this issue, instead focusing on accidental bugs in Free software, even very old (and already fixed) bugs



  7. Black Duck's Latest Self-Promotional Propaganda (for Proprietary Software) Still Fools Journalists

    Under the traditionally misleading title "Future of Open Source" Black Duck expresses its desire for proprietary software sales, salivating over fearful managers who may get bamboozled into buying the patents-'protected' Black Duck 'product'



  8. Links 16/4/2015: Opera for 32-bit GNU/Linux, New Chromebook Site

    Links for the day



  9. Links 15/4/2015: Plasma 5.3 Beta, Docker's New Funding

    Links for the day



  10. Microsoft is Still Googlebombing the Term Open Source and Fooling Politicians Who Now Think Microsoft is Open Source

    Microsoft's attempt to assimilate (to confuse) bears some fruit and the Microsoft-linked media plays a considerable role in it



  11. Back Doors/Bug Doors in All Versions of Microsoft Windows Need a Name, a Logo, and Branding Too

    All versions of Microsoft Windows are found to have been insecure since 1997, but the bug responsible for this is not named as candidate for back door access, let alone named (with logo and marketing) like far less severe bugs in Free/libre software such as OpenSSL



  12. OnePlus (or OnePlus Customers) Should Wipe CyanogenMod From Existing Devices and Install Something Else

    A call for OnePlus to reconsider any future updates from Microsoft's Trojan horse, Cyanogen



  13. Links 14/4/2015: 3DR Dronecode, Z1/Z2 Tizen

    Links for the day



  14. Links 13/4/2015: Linux 4.0 Released; A Look at Antergos 2015.04.12

    Links for the day



  15. EFF Uses Alice v. CLS Bank Case to Pressure USPTO to Halt Software Patenting

    A look at recent patent policies and actions from the EFF, as well as increasing secrecy at the USPTO



  16. No, Panasonic Did Not Open-Source Anything (Another Example of Openwashing for PR)

    A dissection of media deception (or media being bamboozled) regarding the act of promising not to sue using patents, which in no way relates to Free/Open Source software



  17. Yes, Software Patents Are Dying, But Media Continues to Be Dominated by Those Denying it For a Salary

    The debate about software patents in this post-Alice era parallels the Net neutrality debate, where voices of people with vested interests contribute to confusion and meddle with largely-accepted views/consensus



  18. Links 12/4/2015: Linux 4.0 Imminent, Semplice 7 Reviewed

    Links for the day



  19. GNU/Linux is Crushing Windows, So Microsoft Leaps Ahead to X+2 Vapourware (Two Versions Ahead Into the Future)

    Microsoft continues to pile up bogus claims and empty promises in an effort to stall migrations to GNU/Linux



  20. The ITC's and US Media's Surprisingly Soft Treatment of Patent Bully Apple

    Despite Apple's history of initiating patent aggression against its competition (mostly Android-backing companies), the US corporate media treats Apple like a victim



  21. Microsoft Continues to Attack (and Tax) Linux Using Software Patents

    Microsoft stabs Linux in the back while it continues to insist that it 'loves' Linux



  22. European Unitary Patent Decision Due 5th of May

    The meta-industry of patent protectionism is debating and pushing forth the Unitary Patent Court, with or without endorsement from the European public



  23. Microsoft is Still Googlebombing 'Open Source'

    Microsoft's massive campaign of deception, obfuscation and misuse of the "Open Source" brand is still on, even a week after it was cleverly started by Condé Nast



  24. Links 11/4/2015: elementary OS Freya, Mageia 5 on the Way

    Links for the day



  25. Links 10/4/2015: Linux 4.0 Imminent, ZFS On Linux Improved

    Links for the day



  26. New Article Chronicles Suicides and Nervous Breakdowns at the EPO Due to the Management's Abuses

    Article from Le Monde translated into English



  27. Links 9/4/2015: SalentOS, Semplice Releases

    Links for the day



  28. The EPO is Becoming More Like the USPTO Under Benoît Battistelli's Greed-Driven Reign

    Recent articles about the EPO and the Unitary Patent are bundled together to highlight truly disturbing developments whereby those in power beget power through instruments of state-sanctioned power, such as the EPO (stateless entity within a continent-wide 'island')



  29. More Suicides Reported at the Staff-Hostile European Patent Office

    The EPO has become so rogue that it might as well be renamed the Euthanasia-Prodding Organisation



  30. Security FUD Against Free Software Resurfaces, Using Promotional Branding From a Microsoft-Linked Firm, So Red Hat Finally Responds

    Old news is 'new' again, as Microsoft-friendly media decides to keep knocking hard on the reputation of Free software, using words rather than substance


CoPilotCo

RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

CoPilotCo

Recent Posts