EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

01.28.09

Windows Botnets Go Out of Control, Obama Web Site Delivers Windows Malware

Posted in Microsoft, Security, Windows at 10:47 am by Dr. Roy Schestowitz

THERE ARE SO MANY MICROSOFT failure stories to share today that it’s hard to decide where to start.

Sites Hijacked

Microsoft’s security nightmares as of late [1, 2, 3, 4, 5, 6, 7] are where we begin by presenting the following report about a government site in Australia getting cracked and doing enough harm that it needed to be shut down.

Like you, I get masses of spam. I knew it wasn’t from jobs.nsw.gov.au no matter how much it pretended to be. I deleted it figuring it was “just another” bit of junk mail, although I was surprised to find one purporting to be from the NSW Government job board; that was definitely a new one on me!

Had I thought about it deeper I might have considered this was no ordinary spam. This time there was a direct relationship between how the spammers got my e-mail address and the organisation they purported to represent.

It turns out the Department of Commerce has taken this whole incident very seriously indeed, and far more than common garden-variety spam would necessitate.

If you visit the site jobs.nsw.gov.au you will see it is inaccessible, and in fact, has been for a week. A message advises that the system is down for “system maintenance.”

The site is powered by Microsoft IIS.

Moving on a little, it turns out that Obama’s Web site too is causing harm. Some pages in it are distributing Windows malware.

Web security firm Websense reports that malicious hackers have registered multiple bogus user accounts on My.BarackObama.com. The site allows legitimate punters to join groups, raise funds, or creates blogs. The griefers have established blogs with fake YouTube clips, ostensibly offering grumble flicks.

According to some new statistics, there is a sharp increase in distribution of Windows malware, with more malicious sites than one can practically keep track of:

AVG is seeing between 200,000 to 300,000 new Web sites per day hosting code that can in some cases result in a PC being infected with malware just by visiting the site, said Roger Thompson, AVG’s chief research officer.

Zombies/Botnets Explode

Conficker is still running wild and it’s draining resources along its path (human resources and Web resources).

The world’s top virus hunters are watching every move made by the attacker in control of a nasty new Internet worm — referred to as “downadup” or “conficker.”

The number of infected Windows PCs keeps growing fast.

A virulent computer virus has infected as many as 15 million computers around the world so far, according to various estimates.

The virus — a self-replicating computer worm known as Downadup, Conficker or Kido — spreads across computer networks using Microsoft Windows software which have not been patched or updated properly. Microsoft issued a patch that fixes the vulnerability the virus exploits last October.

This is also covered here.

Computer experts are preparing to respond to further virus outbreaks and security threats posed by the Windows worm, known as Conficker, Kido and Downadup, which has infected more than 15 million PCs worldwide.

Had Microsoft cared about security rather than premature announcements (vapourware) and irresponsible releases, the Internet would have been a better and safer place to travel.

“Our products just aren’t engineered for security.”

Brian Valentine, Microsoft executive

Broken glass

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

5 Comments

  1. Needs Sunlight said,

    January 28, 2009 at 12:12 pm

    Gravatar

    Over the years there have been various Internet milestones. e.g. www passing telnet, then passing ftp-data. ogg vorbis passing 12% of audio, etc. e-mail becoming 60% then 90% spam from windows botnets.

    At what point does (has) the point where the majority of traffic is windows malware get passed?

    Internet has been good, but is in terminal stage windows infestation. Internet2 died on the vine in part because of MS and probably in part because of Doug. How about Internet3, starting with a flat out ban on closed protocols *and* a prohibition against any Windows or MS products…

  2. Needs Sunlight said,

    January 28, 2009 at 12:15 pm

    Gravatar

    Both the UPI article and the USA Today article have major errors. Both misidentify the worm as an “Internet” worm or a “computer” worm. It is neither. It is a Windows worm.

    110 years of journalistic excellence my ass.

  3. Roy Schestowitz said,

    January 28, 2009 at 12:19 pm

    Gravatar

    This is a very important point that Carla wrote about. I mentioned her 2 writings on this subject and gave a new example of Microsoft pressure groups muscling journalists.

  4. twitter said,

    January 28, 2009 at 12:47 pm

    Gravatar

    Messing with the president’s website make a serious federal reaction for these idiots. It will be interesting to watch GWB’s wiretap program turned around to track the spammer’s network. (Who knows, Obama might even get the propper search warrants.) My prediction is that the botnet trail will lead back to WE and other corporate proxies and Obama will dig as deep as he can to find it and any other pieces of Republican guilt. Even if he can’t find that, the M$ cesspool is sure to have dire consequences for M$. We’ve already seen stories about him grumbling about White House computer backwardness and being forced to use a Winblows Mobile handset. Silly stories about iPods and Zunes must also chafe, who would not resent being used as an endorsement for something as rotten as Zune? Porn spam on his website might move Obama’s M$ relationship from disdain to hatred.

  5. Gentoo User said,

    January 28, 2009 at 1:49 pm

    Gravatar

    Apparently you forgot to write up a nasty condemnation of all those PHP/Apache-based sites that were hacked to serve off malware a while ago. They targeted a vulnerability that had a readily-available patch weeks before the exploit was seen in the wild. And then they used Google bombs to draw traffic to the pages, if I recall.

    Oh no, wait. You didn’t forget, of course.

What Else is New


  1. Understanding Thierry Breton: Chirac's Entrepreneurial “Joker”

    Minister in charge of the public treasury was not a career politician but an “entrepreneur” with a proven track-record as a financial wizard and “cost-killer”



  2. Links 16/11/2019: New Debian Release, Wine staging 4.20

    Links for the day



  3. IRC Proceedings: Friday, November 15, 2019

    IRC logs for Friday, November 15, 2019



  4. Microsoft Doesn't Love Linux, It Just Buys Linux

    Microsoft's takeover or abduction of its opposition's voice isn't an act of love but an act of occupation, a hostile colonisation that enables digital pillage and plunder



  5. Koch's Reply to EPO Through ILO and Techrights' Interpretation of Koch v EPO Documents Help Show That ILO-AT is Played by EPO Management

    Sending cases back and forth, without the complainant being involved, means that justice is in eternal ‘limbo’ and thus the abusive management of the European Patent Office (EPO) — first Team Battistelli and now Team Campinos — can get away with anything the bullies do (no judgment of substance being delivered)



  6. EPO Running ILO's Tribunal (ILO-AT) 'in a Loop' to Perpetually Delay and Drain the EPO's Complainants (Aggrieved Staff) Out of Money

    ILO’s Administrative Tribunal — a court for aggrieved EPO staff and other international organisations’ staff (usually known as ILO-AT for short) — is a major farce; when “time is money” and lawyers charge as much as 400 euros an hour the EPO’s management can exploit/misuse its cash reserves to also game justice and buy legal outcomes



  7. ILO is Not Functioning and ILO-AT Helps the Abusive Management of the European Patent Office

    It is becoming increasingly clear, based for example on Koch v EPO, that ILO-AT is where a lot of money will be spent on lawyers and rarely will that result in real justice (but it certainly helps EPO management pretend that staff has safeguards)



  8. Links 16/11/2019: Wine 4.20, Picolibc 1.1

    Links for the day



  9. Understanding Thierry Breton: Moral Responsibility for “a Capitalism That Kills”?

    "...France Télécom which had previously been defined by an ethos of public service, by egalitarian working conditions and by a sense of universal mission, had now been transformed into a "cash machine” whose sole purpose was to generate shareholder value on international financial markets."



  10. FOSSPatents Conference is Against FOSS, Promoting the FOSS-Hostile Construct Known as RAND or FRAND

    Do not be misled by the term Free/Open Source software (FOSS) in the name FOSSPatents and whatever relates to it (e.g. FOSSPatents Conference); it's not about FOSS but against FOSS, or pro-FRAND



  11. Europe is Under Attack

    European politicians or political candidates pretend to be 'candid'; but they're agents of Power, or put another way, they're there to make the rich and powerful class even richer and more powerful by passing new, ruinous laws in the name of 'the people' or 'for SMEs'



  12. Links 15/11/2019: New Opera and Brave, GNU/Linux Flatpa(c)ked

    Links for the day



  13. IRC Proceedings: Thursday, November 14, 2019

    IRC logs for Thursday, November 14, 2019



  14. Understanding Thierry Breton: Toxic Management Goes on Trial in France

    "In each of these cases, the suicide served as a symbolic act of protest to denounce workplace conditions at France Télécom and attract public attention to its practices."



  15. Thierry Breton's Video/Live Grilling is Over, But the Grilling Continues Online

    Elite politicians aren't reluctant to give Thierry Breton the high seat (or throne); but everyone else realises that this resembles a corporate takeover more than anything



  16. The EPO's Low Patent Quality is Not Just Suicidal; It is Illegal

    With help from the besieged Boards of Appeal (BoAs), which complain that they can no longer judge cases (appeals/referrals) autonomously and independently, the Office in Munich continues to grossly violate the EPC and mimic China's ridiculously low patent bar, which even formally permits patents on algorithms



  17. Links 14/11/2019: Mesa 19.2.4 and GCC 7.5 Released

    Links for the day



  18. Microsoft is Not an Open Source Company But Microsoft Bribed and Took Over Many Open Source Authorities (Rivals' Voice Hijacked)

    Free/Open Source software (FOSS) and GNU/Linux are being taken over by Microsoft moles, bought by Microsoft Corporation, and the collective voice of the alternative to Microsoft and Windows is being muzzled (they tell us they "love" us while they're attacking us and sometimes suing us)



  19. Techrights' Interpretation of Koch v EPO: The EPO's Management Still Attacks Staff Representatives

    The EPO hopes to get its victims (of EPO abuse) to not only foot their own bills but also the EPO's



  20. Understanding Thierry Breton: “Mister Cash” Arrives at France Télécom

    The psychological harassment of the France Télécom workforce led the "suicide wave" after Breton had left France Télécom



  21. The Breton-Battistelli Relationship and Breton Hiding His Employment Record at Rothschild & Cie Banque

    EPO scoundrels such as Battistelli are closer to Breton than most people care to realise; Breton is hiding part of his career ahead of today's grilling



  22. A Lot of EPO Staff on Dutch Land Protested (Despite Abusive Threats From Management) and a Strike is Reportedly Next

    EPO management in Rijswijk tried hard to prevent workers from protesting on their free time (lunch break), reaffirming that same old belief that nothing is changing at the EPO and nothing will change without truly disruptive action



  23. IRC Proceedings: Wednesday, November 13, 2019

    IRC logs for Wednesday, November 13, 2019



  24. Links 13/11/2019: Docker Enterprise Bought, WordPress 5.3, Qt 5.12.6 Released

    Links for the day



  25. Rebranding Malware and Spyware as 'Linux' to Dilute the Brand (and the News)

    Signal-to-noise ratio continues to be reduced, as a lot of "Linux" news has nothing to do with GNU/Linux or even with Free software



  26. Understanding Thierry Breton: In the Beginning...

    Career roundup of Thierry Breton, possibly the next EU Commissioner



  27. Startpage Has Been Delisted, But it Ought to be Blacklisted

    Startpage has just warned its fans (I am a former fan) of what Startpage itself covertly became months back



  28. IRC Proceedings: Tuesday, November 12, 2019

    IRC logs for Tuesday, November 12, 2019



  29. Links 12/11/2019: Plasma 5.17.3, More Intel Defects, Bytecode Alliance

    Links for the day



  30. You've Gotta Go When You've Gotta Go

    How most staff of the European Patent Office (EPO) feels these days


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts