EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

01.28.09

Windows Botnets Go Out of Control, Obama Web Site Delivers Windows Malware

Posted in Microsoft, Security, Windows at 10:47 am by Dr. Roy Schestowitz

THERE ARE SO MANY MICROSOFT failure stories to share today that it’s hard to decide where to start.

Sites Hijacked

Microsoft’s security nightmares as of late [1, 2, 3, 4, 5, 6, 7] are where we begin by presenting the following report about a government site in Australia getting cracked and doing enough harm that it needed to be shut down.

Like you, I get masses of spam. I knew it wasn’t from jobs.nsw.gov.au no matter how much it pretended to be. I deleted it figuring it was “just another” bit of junk mail, although I was surprised to find one purporting to be from the NSW Government job board; that was definitely a new one on me!

Had I thought about it deeper I might have considered this was no ordinary spam. This time there was a direct relationship between how the spammers got my e-mail address and the organisation they purported to represent.

It turns out the Department of Commerce has taken this whole incident very seriously indeed, and far more than common garden-variety spam would necessitate.

If you visit the site jobs.nsw.gov.au you will see it is inaccessible, and in fact, has been for a week. A message advises that the system is down for “system maintenance.”

The site is powered by Microsoft IIS.

Moving on a little, it turns out that Obama’s Web site too is causing harm. Some pages in it are distributing Windows malware.

Web security firm Websense reports that malicious hackers have registered multiple bogus user accounts on My.BarackObama.com. The site allows legitimate punters to join groups, raise funds, or creates blogs. The griefers have established blogs with fake YouTube clips, ostensibly offering grumble flicks.

According to some new statistics, there is a sharp increase in distribution of Windows malware, with more malicious sites than one can practically keep track of:

AVG is seeing between 200,000 to 300,000 new Web sites per day hosting code that can in some cases result in a PC being infected with malware just by visiting the site, said Roger Thompson, AVG’s chief research officer.

Zombies/Botnets Explode

Conficker is still running wild and it’s draining resources along its path (human resources and Web resources).

The world’s top virus hunters are watching every move made by the attacker in control of a nasty new Internet worm — referred to as “downadup” or “conficker.”

The number of infected Windows PCs keeps growing fast.

A virulent computer virus has infected as many as 15 million computers around the world so far, according to various estimates.

The virus — a self-replicating computer worm known as Downadup, Conficker or Kido — spreads across computer networks using Microsoft Windows software which have not been patched or updated properly. Microsoft issued a patch that fixes the vulnerability the virus exploits last October.

This is also covered here.

Computer experts are preparing to respond to further virus outbreaks and security threats posed by the Windows worm, known as Conficker, Kido and Downadup, which has infected more than 15 million PCs worldwide.

Had Microsoft cared about security rather than premature announcements (vapourware) and irresponsible releases, the Internet would have been a better and safer place to travel.

“Our products just aren’t engineered for security.”

Brian Valentine, Microsoft executive

Broken glass

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

5 Comments

  1. Needs Sunlight said,

    January 28, 2009 at 12:12 pm

    Gravatar

    Over the years there have been various Internet milestones. e.g. www passing telnet, then passing ftp-data. ogg vorbis passing 12% of audio, etc. e-mail becoming 60% then 90% spam from windows botnets.

    At what point does (has) the point where the majority of traffic is windows malware get passed?

    Internet has been good, but is in terminal stage windows infestation. Internet2 died on the vine in part because of MS and probably in part because of Doug. How about Internet3, starting with a flat out ban on closed protocols *and* a prohibition against any Windows or MS products…

  2. Needs Sunlight said,

    January 28, 2009 at 12:15 pm

    Gravatar

    Both the UPI article and the USA Today article have major errors. Both misidentify the worm as an “Internet” worm or a “computer” worm. It is neither. It is a Windows worm.

    110 years of journalistic excellence my ass.

  3. Roy Schestowitz said,

    January 28, 2009 at 12:19 pm

    Gravatar

    This is a very important point that Carla wrote about. I mentioned her 2 writings on this subject and gave a new example of Microsoft pressure groups muscling journalists.

  4. twitter said,

    January 28, 2009 at 12:47 pm

    Gravatar

    Messing with the president’s website make a serious federal reaction for these idiots. It will be interesting to watch GWB’s wiretap program turned around to track the spammer’s network. (Who knows, Obama might even get the propper search warrants.) My prediction is that the botnet trail will lead back to WE and other corporate proxies and Obama will dig as deep as he can to find it and any other pieces of Republican guilt. Even if he can’t find that, the M$ cesspool is sure to have dire consequences for M$. We’ve already seen stories about him grumbling about White House computer backwardness and being forced to use a Winblows Mobile handset. Silly stories about iPods and Zunes must also chafe, who would not resent being used as an endorsement for something as rotten as Zune? Porn spam on his website might move Obama’s M$ relationship from disdain to hatred.

  5. Gentoo User said,

    January 28, 2009 at 1:49 pm

    Gravatar

    Apparently you forgot to write up a nasty condemnation of all those PHP/Apache-based sites that were hacked to serve off malware a while ago. They targeted a vulnerability that had a readily-available patch weeks before the exploit was seen in the wild. And then they used Google bombs to draw traffic to the pages, if I recall.

    Oh no, wait. You didn’t forget, of course.

What Else is New


  1. In an Effort to Push the Unitary Patent (UPC), EPO and the Liar in Chief Spread the Famous Lie About SMEs

    The EPO wants people to hear just a bunch of lies rather than the simple truth, courtesy of the people whom the EPO proclaims it represents



  2. Links 21/9/2017: Red Hat's Open Source Patent Promise; Qt 5.6.3, Kali Linux 2017.2 Release

    Links for the day



  3. East Asia's Patent Peril and the Curse of Patent Trolls

    The high cost of China's new obsession with patents and the never-ending saga of Samsung (Korea), which gets dragged into courts not only in the US but also in China



  4. USPTO Starts Discriminating Against Poor People, and Does So Even When They Rightly Point Out Errors

    Even though the burden of proof ought to be on one who grants a monopoly, the legal costs are being offloaded onto those who challenge an erroneously-granted monopoly (even if the court sides with the challenger)



  5. Ambrose Chan Enters Document Security Systems (DSS), a Partly Patent Troll Entity

    The Board of Directors of DSS enlists a man from Singapore, whose lack of technical background suggests that the company is still more of a bully than an innovator



  6. UPC Threatens to Weaponise Software Patents in Countries That Forbade These

    The reality of software patents in Europe and what a Unified Patent Court (UPC) would mean for these if it ever became a reality



  7. The Latest Lies About the Unitary Patent (UPC) and CIPO's Participation in Those

    Team UPC continues to overplay its chances, conveniently ignoring simple facts as well as the Rule of Law



  8. The Patents Policy of Facebook is Causing an Exodus

    Yet another major player walks away from Facebook's code because of software patents



  9. Links 20/9/2017: Wine Staging 2.17, Randa 2017, Redox OS 0.3.3

    Links for the day



  10. When Google Used Alex Converse to Raid the Public Domain With Software Patents

    In its overzealous pursuit of software patents, Google is now turning public domain methods into private 'property' (in defiance of critics)



  11. Mark Kokes, the Man Behind BlackBerry's Patent Aggression, Leaves the Company

    The man behind the patent troll-like behaviour of BlackBerry is leaving



  12. WordPress Demonstrates That Facebook's Patent Strategy is Deterring/Alienating Developers

    React is being dumped following Facebook's attempt to restrict distribution/derivatives using software patents



  13. Links 19/9/2017: Pipewire, Mir Support for Wayland, DRM in W3C

    Links for the day



  14. Links 18/9/2017: Linux 4.14 RC1, Mesa 17.2.1, and GNOME 3.26 on Ubuntu Artful

    Links for the day



  15. Patent Trolls Update: Eolas, Conversant (MOSAID), Leigh Rothschild, and Electronic Communication Technologies

    Patent trolls are still being watched -- as they ought to be -- even though some of them shy away, hide from the media, engage in dirty tricks, and file more lawsuits



  16. Microsoft is Promoting Software Patents in India in Another Effort to Undermine Free/Open Source Software, Microsoft-Connected Trolls Are Still Suing

    The ongoing patent threat to Free/libre Open Source software (FLOSS) and the role played by Microsoft in at least much of this threat



  17. Patent Trial and Appeal Board (PTAB) Under Attack by IBM and Other Patent Parasites Who Undermine Patent Quality

    The PTAB, which has thus far invalidated thousands of abstract/software patents, is under a coordinated attack not by those who produce things but those who produce a lot of lawsuit



  18. Why the Mohawk Tribe Should Fire Its Lawyers and Dump the Patents Which Now Tarnish Its Name

    In order to dodge the Patent Trial and Appeal Board (PTAB) with its Inter Partes Reviews (IPRs), the Mohawk tribe is being exploited -- very much in direct detriment to its reputation and status



  19. Amazon and Google Have Both Become Part of the Software Patents Problem

    The transition from so-called 'defensive' patents to offensive patents (ones that are used to suppress competition) as seen in Amazon and in Google, which is already suing rivals and is pursuing additional patents by acquisition



  20. Unless Physical, Inventions Are No Longer Patent-Eligible in US Courts, But USPTO Ignores Precedence

    Even though the ability to enforce software patents against a rival (or many targets, especially in the case of patent trolls) is vastly diminished, the US patent office continues to grant these



  21. Citing the European Patent Convention, Spanish Court Tosses Lawsuit With EPO-Granted European Patent

    The quality of European Patents (EPs) -- a subject of growing levels of scrutiny -- as demonstrated in Barcelona this summer



  22. Links 16/9/2017: More of “Public Money, Public Code”, Equifax Failed to Patch for Months

    Links for the day



  23. BlackBerry Has Turned Into a Patents and Licensing Company

    The Canadian company that made fairly reputable phones early in this century is left with nothing but the power to sue other companies -- a power to which it increasingly gravitates



  24. European Patent Office Continues to Paint a Rosy UPC Picture Even Though the UPC May Already be Dead

    The European Patent Office (EPO) doesn't let facts get in the way as another week passes with UPC promotion and further staff repressions



  25. Tax Evasion by Patent Boxes and Lies About Small Businesses (SMEs) in the Corporate Media

    The lobbying effort of the patent 'industry' -- and its largest beneficiaries -- paints its own perks as something that's intended for their small/minuscule competitors (whom they actually attempt to misrepresent and crush)



  26. Links 15/9/2017: Mesa 17.2.1 RC, Wine 2.17, WordPress to Ditch React Over Patents

    Links for the day



  27. The UPC Fantasy is Going Nowhere as Complaints and Paperwork Pile Up

    Many submissions and complaints about the Unitary Patent have time to arrive before the end of October as a decision on the matter seems as distant as 2018



  28. At Event of EPO SLAPP Firm, a Suggestion That the UPC Should be Scrapped Because It's Stuck

    Just like the TPP, the UPC is now in a potentially fatal deadlock, so people with a stake in the outcome consider starting again (almost from scratch)



  29. Watchtroll Helps the EPO Peddle Fake News About the Unitary Patent (UPC)

    The Unified Patent Court (UPC) isn't happening; the EPO, however, keeps on pretending that it can already operate as though the UPC got the green light



  30. Links 14/9/2017: Plasma 5.11 Beta, Q4OS 1.8.8, Orion

    Links for the day


CoPilotCo

RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

CoPilotCo

Recent Posts