Bonum Certa Men Certa

Windows Botnets Go Out of Control, Obama Web Site Delivers Windows Malware

THERE ARE SO MANY MICROSOFT failure stories to share today that it's hard to decide where to start.

Sites Hijacked



Microsoft's security nightmares as of late [1, 2, 3, 4, 5, 6, 7] are where we begin by presenting the following report about a government site in Australia getting cracked and doing enough harm that it needed to be shut down.

Like you, I get masses of spam. I knew it wasn't from jobs.nsw.gov.au no matter how much it pretended to be. I deleted it figuring it was “just another” bit of junk mail, although I was surprised to find one purporting to be from the NSW Government job board; that was definitely a new one on me!

Had I thought about it deeper I might have considered this was no ordinary spam. This time there was a direct relationship between how the spammers got my e-mail address and the organisation they purported to represent.

It turns out the Department of Commerce has taken this whole incident very seriously indeed, and far more than common garden-variety spam would necessitate.

If you visit the site jobs.nsw.gov.au you will see it is inaccessible, and in fact, has been for a week. A message advises that the system is down for “system maintenance.”


The site is powered by Microsoft IIS.

Moving on a little, it turns out that Obama's Web site too is causing harm. Some pages in it are distributing Windows malware.

Web security firm Websense reports that malicious hackers have registered multiple bogus user accounts on My.BarackObama.com. The site allows legitimate punters to join groups, raise funds, or creates blogs. The griefers have established blogs with fake YouTube clips, ostensibly offering grumble flicks.


According to some new statistics, there is a sharp increase in distribution of Windows malware, with more malicious sites than one can practically keep track of:

AVG is seeing between 200,000 to 300,000 new Web sites per day hosting code that can in some cases result in a PC being infected with malware just by visiting the site, said Roger Thompson, AVG's chief research officer.


Zombies/Botnets Explode



Conficker is still running wild and it's draining resources along its path (human resources and Web resources).

The world's top virus hunters are watching every move made by the attacker in control of a nasty new Internet worm — referred to as "downadup" or "conficker."


The number of infected Windows PCs keeps growing fast.

A virulent computer virus has infected as many as 15 million computers around the world so far, according to various estimates.

The virus -- a self-replicating computer worm known as Downadup, Conficker or Kido -- spreads across computer networks using Microsoft Windows software which have not been patched or updated properly. Microsoft issued a patch that fixes the vulnerability the virus exploits last October.


This is also covered here.

Computer experts are preparing to respond to further virus outbreaks and security threats posed by the Windows worm, known as Conficker, Kido and Downadup, which has infected more than 15 million PCs worldwide.


Had Microsoft cared about security rather than premature announcements (vapourware) and irresponsible releases, the Internet would have been a better and safer place to travel.

"Our products just aren't engineered for security."

--Brian Valentine, Microsoft executive



Broken glass

Comments

Recent Techrights' Posts

Proprietary Software is Bad for Your Health, Not Just Your Finances, Privacy and So On
It would be interesting to see some charts, based on some long-term study, comparing the general health (blood pressure, BMI etc.) of people who use proprietary stuff and people who do not
Microsoft Admits Business Perils as Windows Continues to Fall
‘Microsoft missed the biggest business model…’
Technical Specifications at Times of Tyrannies
Specifications (specs) must evolve with the times
In Case Rust Censors It (Rust Has Long Been All About Censorship), Here's a Critical Look at Rust's Goals
In the case of Rust, instead of "the liberation of the digital society" we have empowerment of Microsoft GitHub and of GAFAM in general. Guess who funds this...
Gemini Links 23/02/2025: Respectful Platforms Manifesto and Internet Archive
Links for the day
The Significance of the Timing of the Ridiculous Letters From Brett Wilson LLP, Acting on Behalf of People From Microsoft
A preliminary look at the timeline and what it tells us
Politicians Ought to Invite Dr. Richard Stallman and Prof. Eben Moglen to Speak About Policies, Licensing, Digital Sovereignty
Is there something in Europe other than RMS' talk this coming Monday (that we're not yet aware of)?
The So-called 'IT' Industry Became Somewhat of a Fraud Where People Equate Usage and Power Wasted With "Value" or "Success"
When did 'IT' become a weapon rather than technology/science?
Things to Like About London
Many important or "powerful" people leave near there
 
Links 24/02/2025: Germany Looks to Distance Itself From US, Environment at Risk, Mass Layoffs at Zendesk
Links for the day
[Meme] It's Over, Microsoft
an obligatory meme
Even Worse Than LLM Slop and Linkspam From UNIXMen
UNIXMen is basically a defunct spamfarm at this point (the author is "sarwarSEO")
Gemini Links 24/02/2025: Osiris 0.1.0 Release (File Sharing in Gemini Protocol), NetBSD 10.1 on the Pi
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, February 23, 2025
IRC logs for Sunday, February 23, 2025
Links 23/02/2025: Democracy Backsliding and German Election
Links for the day
Joining APRIL(.org), AGM weekend, Paris, 15-16 March 2025
Reprinted with permission from Daniel Pocock
Links 23/02/2025: Zuckerberg Despised, US Government Does Not Obey Judges, France Grapples With Terrorism
Links for the day
Links 23/02/2025: Apple Back Doors, Ukraine Updates, and Gemini Leftovers
Links for the day
Recent Improvements in Techrights
minimalism works fine when the main goal is to relay information
Slopwatch: Brian Fagioli, Brittany Day (linuxsecurity.com), and Microsoft Misinformation, False Marketing
Serial Sloppers
Censored: Debian Zizian transgender vigilante comparisons in open source Linux communities
Reprinted with permission from Daniel Pocock
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, February 22, 2025
IRC logs for Saturday, February 22, 2025
Links 22/02/2025: OpenAI Plans to Possibly Abandon Microsoft, Facebook Doubles Execs' Bonuses While Sacking Thousands
Links for the day
Gemini Links 22/02/2025: Weekend Chill and Programming Thoughts
Links for the day
Good Explanation of Why IBM Has Chosen to Conceal Mass Layoffs (of 'Expensive' Staff) as "R.T.O." (Even For People Who Never Worked at the Office to Which They're Ordered to "Return")
Many remaining IBM (or Red Hat) workers in Europe are in "cheaper" places such as Brno
Microsoft's Serial Strangler and Matthew J. Garrett Join Forces in Trying to Gag Techrights (for Exposing Microsoft Corruption and Crimes Against Women)
Whose terrible idea was it?
Links 22/02/2025: Labour Department Investigates Microsoft Infosys Amid Mass Layoffs, Large Law Firms Caught Red Handed With LLM Slop (Defrauding Clients and Courts)
Links for the day
Gemini Links 22/02/2025: Analog Stuff, Sigil, and SSGs
Links for the day
Microsoft's Market Share in Cameroon Falls to New Lows
This means a lot of Android users (iOS is about 4 times smaller), but Android does not mean freedom
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, February 21, 2025
IRC logs for Friday, February 21, 2025
The Streisand Effect is Real
So don't be evil. Also, don't strangle women.