01.28.09

Windows Botnets Go Out of Control, Obama Web Site Delivers Windows Malware

Posted in Microsoft, Security, Windows at 10:47 am by Dr. Roy Schestowitz

THERE ARE SO MANY MICROSOFT failure stories to share today that it’s hard to decide where to start.

Sites Hijacked

Microsoft’s security nightmares as of late [1, 2, 3, 4, 5, 6, 7] are where we begin by presenting the following report about a government site in Australia getting cracked and doing enough harm that it needed to be shut down.

Like you, I get masses of spam. I knew it wasn’t from jobs.nsw.gov.au no matter how much it pretended to be. I deleted it figuring it was “just another” bit of junk mail, although I was surprised to find one purporting to be from the NSW Government job board; that was definitely a new one on me!

Had I thought about it deeper I might have considered this was no ordinary spam. This time there was a direct relationship between how the spammers got my e-mail address and the organisation they purported to represent.

It turns out the Department of Commerce has taken this whole incident very seriously indeed, and far more than common garden-variety spam would necessitate.

If you visit the site jobs.nsw.gov.au you will see it is inaccessible, and in fact, has been for a week. A message advises that the system is down for “system maintenance.”

The site is powered by Microsoft IIS.

Moving on a little, it turns out that Obama’s Web site too is causing harm. Some pages in it are distributing Windows malware.

Web security firm Websense reports that malicious hackers have registered multiple bogus user accounts on My.BarackObama.com. The site allows legitimate punters to join groups, raise funds, or creates blogs. The griefers have established blogs with fake YouTube clips, ostensibly offering grumble flicks.

According to some new statistics, there is a sharp increase in distribution of Windows malware, with more malicious sites than one can practically keep track of:

AVG is seeing between 200,000 to 300,000 new Web sites per day hosting code that can in some cases result in a PC being infected with malware just by visiting the site, said Roger Thompson, AVG’s chief research officer.

Zombies/Botnets Explode

Conficker is still running wild and it’s draining resources along its path (human resources and Web resources).

The world’s top virus hunters are watching every move made by the attacker in control of a nasty new Internet worm — referred to as “downadup” or “conficker.”

The number of infected Windows PCs keeps growing fast.

A virulent computer virus has infected as many as 15 million computers around the world so far, according to various estimates.

The virus — a self-replicating computer worm known as Downadup, Conficker or Kido — spreads across computer networks using Microsoft Windows software which have not been patched or updated properly. Microsoft issued a patch that fixes the vulnerability the virus exploits last October.

This is also covered here.

Computer experts are preparing to respond to further virus outbreaks and security threats posed by the Windows worm, known as Conficker, Kido and Downadup, which has infected more than 15 million PCs worldwide.

Had Microsoft cared about security rather than premature announcements (vapourware) and irresponsible releases, the Internet would have been a better and safer place to travel.

“Our products just aren’t engineered for security.”

Brian Valentine, Microsoft executive

Broken glass

Share in other sites/networks: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Reddit
  • email

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

5 Comments

  1. Needs Sunlight said,

    January 28, 2009 at 12:12 pm

    Gravatar

    Over the years there have been various Internet milestones. e.g. www passing telnet, then passing ftp-data. ogg vorbis passing 12% of audio, etc. e-mail becoming 60% then 90% spam from windows botnets.

    At what point does (has) the point where the majority of traffic is windows malware get passed?

    Internet has been good, but is in terminal stage windows infestation. Internet2 died on the vine in part because of MS and probably in part because of Doug. How about Internet3, starting with a flat out ban on closed protocols *and* a prohibition against any Windows or MS products…

  2. Needs Sunlight said,

    January 28, 2009 at 12:15 pm

    Gravatar

    Both the UPI article and the USA Today article have major errors. Both misidentify the worm as an “Internet” worm or a “computer” worm. It is neither. It is a Windows worm.

    110 years of journalistic excellence my ass.

  3. Roy Schestowitz said,

    January 28, 2009 at 12:19 pm

    Gravatar

    This is a very important point that Carla wrote about. I mentioned her 2 writings on this subject and gave a new example of Microsoft pressure groups muscling journalists.

  4. twitter said,

    January 28, 2009 at 12:47 pm

    Gravatar

    Messing with the president’s website make a serious federal reaction for these idiots. It will be interesting to watch GWB’s wiretap program turned around to track the spammer’s network. (Who knows, Obama might even get the propper search warrants.) My prediction is that the botnet trail will lead back to WE and other corporate proxies and Obama will dig as deep as he can to find it and any other pieces of Republican guilt. Even if he can’t find that, the M$ cesspool is sure to have dire consequences for M$. We’ve already seen stories about him grumbling about White House computer backwardness and being forced to use a Winblows Mobile handset. Silly stories about iPods and Zunes must also chafe, who would not resent being used as an endorsement for something as rotten as Zune? Porn spam on his website might move Obama’s M$ relationship from disdain to hatred.

  5. Gentoo User said,

    January 28, 2009 at 1:49 pm

    Gravatar

    Apparently you forgot to write up a nasty condemnation of all those PHP/Apache-based sites that were hacked to serve off malware a while ago. They targeted a vulnerability that had a readily-available patch weeks before the exploit was seen in the wild. And then they used Google bombs to draw traffic to the pages, if I recall.

    Oh no, wait. You didn’t forget, of course.

What Else is New


  1. Cartoon: After Gambling With Workers' Savings the EPO Can Do Real Estate

    New EPO cartoon from EPO insiders (the one on the right certainly looks a lot like António Campinos and the one on the left can be his EUIPO ‘import’ or Benoît Battistelli‘s INPI ‘import’)



  2. Free as in Freedom Should Not be Associated With Cost

    It's important to remind people that so-called 'free' services (Clown Computing, centralised spaces that 'farm' their so-called 'users') aren't really free; we need to advocate freedom or free-as-in-freedom alternatives



  3. [Meme] UPC's Pyrrhic Victory

    Contrary to what Team UPC says, what happened earlier today is hardly a breakthrough



  4. Many Thanks to Free Software, the Demise of Software Patents (in Europe and the US), and So Much More

    On a positive note we're heading into the end of November, one month before Boxing Day; we take stock of patent affairs that impact software developers



  5. Links 26/11/2020: PHP 8.0, Proxmox VE 6.3, UNIGINE 2.13

    Links for the day



  6. 29,000 Blog Posts and Recent Site Improvements

    Over 29,000 blog posts have been posted here, but more importantly we've made the site a lot more robust and resilient, accessible in more formats and protocols (while improving transparency, too)



  7. [Meme] Trump is Out. Now It's Time to Pressure the Biden Administration/Transition Team on Software Freedom Issues.

    The Biden transition is in motion and tentative appointments are underway, based on news reports (see our Daily Links); now is the time to put pressure, e.g. in the form of public backlash, to ensure it's not just another corporate presidency



  8. Boycott ZDNet Unless You Fancy Being Lied to

    ZDNet's Catalin Cimpanu continues to lead the way with misinformation and lies, basically doing whatever he was doing to land that job at ZDNet (after he had done the same elsewhere)



  9. The UPC and Unitary Patent Song

    On goes the UPC symphony, as the Unified Patent Court (UPC) is almost here, always coming "real soon!"



  10. Open Letter to the German Greens on UPC and Software Patents: Don’t Betray Your Voters and Your Promises, or You Will Regret it

    Dear Members of the German Greens in the Bundestag. By Benjamin HENRION.



  11. [Meme] One Step Away From Replacing Patent Examiners With 'Hey Hi' (AI)

    If it's not legal for 'Hey Hi' (AI) to get a patent, why should it be legal for patents to be granted by those who are invisible (and sometimes in de facto house arrest)?



  12. European Patent Office (EPO) Reduced to 'Justice Over the Telephone' and Decree by E-mail

    The EPO is trashing the EPC and everything that the Office was supposed to stand for, as it wrongly assumes demand for monopolies (typically from foreign corporations) comes before the rule of law and Europe's public interest



  13. Making Free Software Work for Users

    The latest reply to a non-developer concerned about software freedom; guest post by figosdev



  14. IRC Proceedings: Wednesday, November 25, 2020

    IRC logs for Wednesday, November 25, 2020



  15. Links 26/11/2020: AV Linux 2020.11.23 and Blender 2.91 Release

    Links for the day



  16. Links 25/11/2020: GamerOS and Biden Transition in Motion

    Links for the day



  17. An Orwellian December

    With December around the corner and states tightening the screws on the population (or employers on employees) at least we can look forward to spring



  18. The Non-Technical (or Lesser Technical) Software User That Wants Software Freedom

    Assuming that Free software should care about what users — not only developers — really want (and need) it’s important to understand how they view the current situation (with growing waves of corporate takeover and compromises, even expulsions)



  19. The European Patent Office Should be Run by Patent Examiners (Scientists), Not Politicians

    Europe would be better off (and patent quality much improved) had people with an actual grasp of science and reality were in charge of the EPO, not a money-chasing kakistocracy (which is what we have now)



  20. Member of the EPO's Boards of Appeal Explains Why VICOs (or ViCo/Video Conferences/Virtual 'Hearings') Are Not Suitable for Justice

    It's interesting to hear (or see/read) what people inside the EPO have to say about the "new normal" when they enjoy a certain level of anonymity (to avert retribution)



  21. Open Source Initiative (OSI) Co-founder Bruce Perens: Open Invention Network (OIN) is Protecting the Software Patent System From Reform and OSI Approves Faux 'Open' Licences (Openwashing)

    Richard Stallman was right about the OSI and the fake 'movement' that claims to have 'coined' the term "Open Source" (it wasn't a new term at all; it had been used in another context and the Free software community spoke of things like "Open Hardware" years earlier)



  22. IRC Proceedings: Tuesday, November 24, 2020

    IRC logs for Tuesday, November 24, 2020



  23. Making JavaScript Suck Less

    "Other than that, the first rule of JavaScript is: Do not use JavaScript. But this article is for people who break the first rule."



  24. Microsoft 'Moles' Inside WINE Project? WINE Should Bring Windows Users to GNU/Linux, Not the Other Way Around.

    The press release above (link omitted, it was pinned in several sites) is a cause for concern; after Microsoft infiltrated OSI and the Linux Foundation (both are now GitHub boosters, in effect diverting projects to Microsoft’s proprietary monopoly) it’ll be important to watch this space



  25. Links 25/11/2020: Raspberry Pi 400 With Touchscreens, Animation Framework in GTK/GNOME

    Links for the day



  26. [Meme] Things Will Get Amusing When/If EPO Proceedings Are Cancelled Due to Patent Trolls Suing the Platforms Using Software Patents (Granted by the EPO)

    The management of the EPO is so proud to be granting illegal software patents in Europe; this clear abuse of authority can come back to bite it in the rear



  27. Dr. Bausch Questions the Merits and Claims of EPO Management Regarding ViCo ('Skynet' Virtual 'Courts')

    Few courageous attorneys are willing to speak out about (and against) what EPO management is doing right now, in effect exploiting a public health crisis to override the law, spy on lots of people, outsource legal proceedings to the United States and so on



  28. Links 24/11/2020: Linux 5.9.11, Istio 1.6.14 and LibreOffice 7.1 Beta Released

    Links for the day



  29. Lots of Good News Today

    A quick roundup of news and key developments; most of them are positive and they give us hope



  30. Massive Collective Action Begins at the European Patent Office Today, Demanding Change and Forewarning the Management (Litigation)

    The financial "hoax" at the EPO (taking away money from staff to feed a gambling addiction of managers) needs to stop; staff has begun mass-mailing the management, threatening legal action


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts