EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

01.28.09

Windows Botnets Go Out of Control, Obama Web Site Delivers Windows Malware

Posted in Microsoft, Security, Windows at 10:47 am by Dr. Roy Schestowitz

THERE ARE SO MANY MICROSOFT failure stories to share today that it’s hard to decide where to start.

Sites Hijacked

Microsoft’s security nightmares as of late [1, 2, 3, 4, 5, 6, 7] are where we begin by presenting the following report about a government site in Australia getting cracked and doing enough harm that it needed to be shut down.

Like you, I get masses of spam. I knew it wasn’t from jobs.nsw.gov.au no matter how much it pretended to be. I deleted it figuring it was “just another” bit of junk mail, although I was surprised to find one purporting to be from the NSW Government job board; that was definitely a new one on me!

Had I thought about it deeper I might have considered this was no ordinary spam. This time there was a direct relationship between how the spammers got my e-mail address and the organisation they purported to represent.

It turns out the Department of Commerce has taken this whole incident very seriously indeed, and far more than common garden-variety spam would necessitate.

If you visit the site jobs.nsw.gov.au you will see it is inaccessible, and in fact, has been for a week. A message advises that the system is down for “system maintenance.”

The site is powered by Microsoft IIS.

Moving on a little, it turns out that Obama’s Web site too is causing harm. Some pages in it are distributing Windows malware.

Web security firm Websense reports that malicious hackers have registered multiple bogus user accounts on My.BarackObama.com. The site allows legitimate punters to join groups, raise funds, or creates blogs. The griefers have established blogs with fake YouTube clips, ostensibly offering grumble flicks.

According to some new statistics, there is a sharp increase in distribution of Windows malware, with more malicious sites than one can practically keep track of:

AVG is seeing between 200,000 to 300,000 new Web sites per day hosting code that can in some cases result in a PC being infected with malware just by visiting the site, said Roger Thompson, AVG’s chief research officer.

Zombies/Botnets Explode

Conficker is still running wild and it’s draining resources along its path (human resources and Web resources).

The world’s top virus hunters are watching every move made by the attacker in control of a nasty new Internet worm — referred to as “downadup” or “conficker.”

The number of infected Windows PCs keeps growing fast.

A virulent computer virus has infected as many as 15 million computers around the world so far, according to various estimates.

The virus — a self-replicating computer worm known as Downadup, Conficker or Kido — spreads across computer networks using Microsoft Windows software which have not been patched or updated properly. Microsoft issued a patch that fixes the vulnerability the virus exploits last October.

This is also covered here.

Computer experts are preparing to respond to further virus outbreaks and security threats posed by the Windows worm, known as Conficker, Kido and Downadup, which has infected more than 15 million PCs worldwide.

Had Microsoft cared about security rather than premature announcements (vapourware) and irresponsible releases, the Internet would have been a better and safer place to travel.

“Our products just aren’t engineered for security.”

Brian Valentine, Microsoft executive

Broken glass

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

5 Comments

  1. Needs Sunlight said,

    January 28, 2009 at 12:12 pm

    Gravatar

    Over the years there have been various Internet milestones. e.g. www passing telnet, then passing ftp-data. ogg vorbis passing 12% of audio, etc. e-mail becoming 60% then 90% spam from windows botnets.

    At what point does (has) the point where the majority of traffic is windows malware get passed?

    Internet has been good, but is in terminal stage windows infestation. Internet2 died on the vine in part because of MS and probably in part because of Doug. How about Internet3, starting with a flat out ban on closed protocols *and* a prohibition against any Windows or MS products…

  2. Needs Sunlight said,

    January 28, 2009 at 12:15 pm

    Gravatar

    Both the UPI article and the USA Today article have major errors. Both misidentify the worm as an “Internet” worm or a “computer” worm. It is neither. It is a Windows worm.

    110 years of journalistic excellence my ass.

  3. Roy Schestowitz said,

    January 28, 2009 at 12:19 pm

    Gravatar

    This is a very important point that Carla wrote about. I mentioned her 2 writings on this subject and gave a new example of Microsoft pressure groups muscling journalists.

  4. twitter said,

    January 28, 2009 at 12:47 pm

    Gravatar

    Messing with the president’s website make a serious federal reaction for these idiots. It will be interesting to watch GWB’s wiretap program turned around to track the spammer’s network. (Who knows, Obama might even get the propper search warrants.) My prediction is that the botnet trail will lead back to WE and other corporate proxies and Obama will dig as deep as he can to find it and any other pieces of Republican guilt. Even if he can’t find that, the M$ cesspool is sure to have dire consequences for M$. We’ve already seen stories about him grumbling about White House computer backwardness and being forced to use a Winblows Mobile handset. Silly stories about iPods and Zunes must also chafe, who would not resent being used as an endorsement for something as rotten as Zune? Porn spam on his website might move Obama’s M$ relationship from disdain to hatred.

  5. Gentoo User said,

    January 28, 2009 at 1:49 pm

    Gravatar

    Apparently you forgot to write up a nasty condemnation of all those PHP/Apache-based sites that were hacked to serve off malware a while ago. They targeted a vulnerability that had a readily-available patch weeks before the exploit was seen in the wild. And then they used Google bombs to draw traffic to the pages, if I recall.

    Oh no, wait. You didn’t forget, of course.

What Else is New


  1. The Australian Productivity Commission Shows the Correct Approach to Setting Patent Laws and Scope

    Australia views patents on software as undesirable and acts accordingly, making nobody angry except a bunch of law firms that profited from litigation and patent maximalism



  2. EPO 'Business' From the United States Has Nosedived and UPC is on Its Death Throes

    Benoît Battistelli and Elodie Bergot further accelerate the ultimate demise of the EPO (getting rid of experienced and thus 'expensive' staff), for which there is no replacement because there is a monopoly (which means Europe will suffer severely)



  3. Links 17/11/2017: KDE Applications 17.12, Akademy 2018 Plans

    Links for the day



  4. Today's EPO and Team UPC Do Not Work for Europe But Actively Work Against Europe

    The tough reality that some Europeans actively work to undermine science and technology in Europe because they personally profit from it and how this relates to the Unitary Patent (UPC), which is still aggressively lobbied for, sometimes by bribing/manipulating the media, academia, and public servants



  5. Links 16/11/2017: WordPress 4.9 and GhostBSD 11.1 Released

    Links for the day



  6. The Staff Union of the EPO (SUEPO) is Rightly Upset If Not Shocked at What Battistelli and Bergot Are Doing to the Office

    The EPO's dictatorial management is destroying everything that's left (of value) at the Office while corrupting academia and censoring discussion by threatening those who publish comments (gagging its own staff even when that staff posts anonymously)



  7. EPO Continues to Disobey the Law on Software Patents in Europe

    Using the same old euphemisms, e.g. "computer-implemented inventions" (or "CII"), the EPO continues to grant patents which are clearly and strictly out of scope



  8. Links 16/11/2017: Tails 3.3, Deepin 15.5 Beta

    Links for the day



  9. Benoît Battistelli and Elodie Bergot Have Just Ensured That EPO Will Get Even More Corrupt

    Revolving door-type tactics will become more widespread at the EPO now that the management (Battistelli and his cronies) hires for low cost rather than skills/quality and minimises staff retention; this is yet another reason to dread anything like the UPC, which prioritises litigation over examination



  10. Australia is Banning Software Patents and Shelston IP is Complaining as Usual

    The Australian Productivity Commission, which defies copyright and patent bullies, is finally having policies put in place that better serve the interests of Australians, but the legal 'industry' is unhappy (as expected)



  11. Patent Trial and Appeal Board (PTAB) Defended by Technology Giants, by Small Companies, by US Congress and by Judges, So Why Does USPTO Make It Less Accessible?

    In spite of the popularity of PTAB and the growing need/demand for it, the US patent system is apparently determined to help it discriminate against poor petitioners (who probably need PTAB the most)



  12. Declines in Patent Quality at the EPO and 'Independent' Judges Can No Longer Say a Thing

    The EPO's troubling race to the bottom (of patent quality) concerns the staff examiners and the judges, but they cannot speak about it without facing rather severe consequences



  13. The EPO is Now Corrupting Academia, Wasting Stakeholders' Money Lying to Stakeholders About the Unitary Patent (UPC)

    The Unified Patent Court/Unitary Patent (UPC) is a dying project and the EPO, seeing that it is going nowhere fast, has resorted to new tactics and these tactics cost a lot of money (at the expense of those who are being lied to)



  14. Links 15/11/2017: Fedora 27 Released, Linux Mint Has New Betas

    Links for the day



  15. Patents Roundup: Packet Intelligence, B.E. Technology, Violin, and Square

    The latest stories and warnings about software patents in the United States



  16. Decline of Skills Level of Staff Like Examiners and Impartiality (Independence) of Judges at the EPO Should Cause Concern, Alarm

    Access to justice is severely compromised at the EPO as staff is led to rely on deficient tools for determining novelty while judges are kept out of the way or ill-chosen for an agenda other than justice



  17. Links 14/11/2017: GNU/Linux at Samsung, Firefox 57 Quantum

    Links for the day



  18. Microsoft: Sheltering Oneself From Patent Litigation While Passing Patents for Trolls to Attack GNU/Linux

    Another closer look at Provenance Asset Holdings and what exactly it is (connection to AST, part of the cartel Microsoft subsidises to shield itself)



  19. The Patent Trolls' Lobby is Losing the Battle for Europe

    The situation in Europe is looking grim for patent trolls, for their policies and the envisioned system (which they lobbied for) isn't coming to fruition and their main casualty is the old (and functioning) EPO



  20. Unitary Patent (UPC) is Dead to the EPO and ANSERA is Not the Answer as Patent Quality Declines and Talented Staff Leaves

    EPOPIC comes to an end and the EPO does not mention the UPC 'content' in it; ANSERA, in the meantime, raises more questions than it answers and IP Kat makes a formal query



  21. Why Honest Journalism on Patent Matters Barely Exists

    Media coverage in the area of patent law is still appalling as it's dominated if not monopolised by those who benefit from patent maximalism



  22. Patent Maximalism Around the World

    A roundup of stories or spin observed over the past week, mostly favouring those who profit from patents rather than creation of anything



  23. Links 13/11/2017: Samsung’s DeX Revisited, Linux Kernel 4.14 Released

    Links for the day



  24. Time for the Court of Appeals for the Federal Circuit (CAFC) to Disregard Rulings From the Eastern District of Texas

    A look at the latest developments at the Federal Circuit and some bits about Microsoft's extortion using software patents (even after Alice)



  25. Alice (De Facto Ban on Software Patents) Remains Untouched in 2017 and Likely in 2018 As Well

    The patent microcosm (people like Dennis Crouch) is trying to find cases that can contradict Alice (at the higher levels, especially the US Supreme Court) but is unable to find them; as things stand, suing anyone with a software patent seems like a losing/high-risk strategy



  26. The USPTO's Joe Matal (Interim Director) Sounds Serious About Improving the Patent Quality and Services

    An expressed desire to improve the US patent system rather than treat is like a money-making machine, as illuminated in recent days by Patently-O



  27. Patent Trial and Appeal Board (PTAB) Defends Firms From Bogus Patents and US Congress Hears About How PTAB Dodgers Misuse Immunity

    The debate about PTAB is being lost by the patent microcosm, whose attempt to dodge and demonise PTAB merely serves to reinforce PTAB's importance and continued success



  28. Links 11/11/2017: Mesa 17.2.5 and Wine 2.21 Released

    Links for the day



  29. Benoît Battistelli Gives Power to Željko Topić, Not Just to António Campinos

    Topić still derives power from Battistelli, who treats him like his right-hand man



  30. Next EPO President Will Continue a Cooperation Which Does Not Exist

    Kluwer Patent Blog is nitpicking the words of António Campinos and expressing scepticism about progress to be made by Campinos


CoPilotCo

RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

CoPilotCo

Recent Posts