08.07.09

Gemini version available ♊︎

Microsoft Windows Zombies Also Knocked Facebook and Gawker Offline, More “Critical” Microsoft Flaws Discovered

Posted in Microsoft, Security, Windows at 9:41 am by Dr. Roy Schestowitz

Summary: More victims of Windows botnets abound; Microsoft discloses 5 new remotely-exploitable vulnerabilities

LAST NIGHT we wrote about Twitter's injury from Windows zombies. Twitter was not alone however; now that the Web is saturated with Windows botnets, anyone with an axe to grind can take Web sites of choice offline. A decade or so ago even Yahoo! was a victim, so our own suffering is very minor in comparison (but increasingly common). According to the BBC, Facebook is another new victim.

Denial-of-service (DOS) attacks take various forms but often involve a company’s servers being flooded with data in an effort to disable them.

The Register reports that Gawker too is a victim.

New York-based media news and gossip blog network Gawker is recovering from a debilitating denial of service attack.

SJVN wrote a good essay on how Twitter was killed by Windows botnets.

DDoS attacks are hard to beat. While some Twitter fans are claiming that this is the biggest DDoS attack ever, I’m inclined to doubt it. Twitter, even though its performance has gotten much better, has often teetered on the edge of collapse due to the enormous load its users put on its social network infrastructure. No, the DDoS attack on Google earlier this year was probably still the worst attack on record.

How is this happening? Well, let me tell you. Today’s DDoS attacks are made by Windows-powered botnets. They’re not terribly sophisticated about these attacks. The last major one, which may or may not have come from North Korea, was driven by MyDoom, Windows malware from 2004.

[...]

Russians already successfully attacked Estonia’s Internet infrastructure in 2007. With Windows botnets growing by leaps and bounds, it’s easier than ever for governments or even just a handful of people to knock out major Web sites like Twitter.

I’ve said it before, I’ll say it again. Thanks to Windows’ security weaknesses, botnets are now commonplace and we can only expect to see more DDoS attacks in the future.

One person believes that he knows who was behind the attack (and its motives), being the botmaster or the leader of several.

As Twitter struggled to return to normal Wednesday evening, a trickle of details suggested that the outage that left 30 million users unable to use the micro-blogging service for several hours – at least in part – may have been the result of a spam campaign that targeted a single user who vocally supports the Republic of Georgia.

Windows has become an expensive and dangerous political tool. Based on this new report from Heise, change is nowhere near.

Microsoft to patch nine security vulnerabilities on Patch Tuesday

Five of the security updates reportedly patch critical vulnerabilities that could lead to remote code execution in Windows and a variety of other software.

Here is a couple more that are new.

“It is no exaggeration to say that the national security is also implicated by the efforts of hackers to break into computing networks. Computers, including many running Windows operating systems, are used throughout the United States Department of Defense and by the armed forces of the United States in Afghanistan and elsewhere.”

Jim Allchin, Microsoft

Share in other sites/networks: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Reddit
  • email

Decor ᶃ Gemini Space

Below is a Web proxy. We recommend getting a Gemini client/browser.

Black/white/grey bullet button This post is also available in Gemini over at this address (requires a Gemini client/browser to open).

Decor ✐ Cross-references

Black/white/grey bullet button Pages that cross-reference this one, if any exist, are listed below or will be listed below over time.

Decor ▢ Respond and Discuss

Black/white/grey bullet button If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

DecorWhat Else is New


  1. IRC Proceedings: Sunday, May 28, 2023

    IRC logs for Sunday, May 28, 2023



  2. Daniel Stenberg Knows Almost Nothing About Gemini and He's Likely Just Protecting His Turf (HTTP/S)

    The man behind Curl, Daniel Stenberg, criticises Gemini; but it's not clear if he even bothered trying it (except very briefly) or just read some inaccurate, one-sided blurbs about it



  3. Links 29/05/2023: Videos Catchup and Gemini FUD

    Links for the day



  4. Links 28/05/2023: Linux 6.4 RC4 and MX Linux 23 Beta

    Links for the day



  5. Gemini Links 28/05/2023: Itanium Day, GNUnet DHT, and More

    Links for the day



  6. Links 28/05/2023: eGates System Collapses, More High TCO Stories (Microsoft Windows)

    Links for the day



  7. IRC Proceedings: Saturday, May 27, 2023

    IRC logs for Saturday, May 27, 2023



  8. No More Twitter, Mastodon, and Diaspora for Tux Machines (Goodbye to Social Control Media)

    People would benefit from mass abandonment of such pseudo-social pseudo-media.



  9. Links 28/05/2023: New Wine and More

    Links for the day



  10. Links 27/05/2023: Plans Made for GNU's 40th Anniversary

    Links for the day



  11. Social Control Media Needs to be Purged and We Need to Convince Others to Quit It Too (to Protect Ourselves as Individuals and as a Society)

    With the Tux Machines anniversary (19 years) just days away we seriously consider abandoning all social control media accounts of that site, including Mastodon and Diaspora; social control networks do far more harm than good and they’ve gotten a lot worse over time



  12. Anonymously Travelling: Still Feasible?

    The short story is that in the UK it's still possible to travel anonymously by bus, tram, and train (even with shades, hat and mask/s on), but how long for? Or how much longer have we got before this too gets banned under the false guise of "protecting us" (or "smart"/"modern")?



  13. With EUIPO in Focus, and Even an EU Kangaroo Tribunal, EPO Corruption (and Cross-Pollination With This EU Agency) Becomes a Major Liability/Risk to the EU

    With the UPC days away (an illegal and unconstitutional kangaroo court system, tied to the European Union in spite of critical deficiencies) it’s curious to see EPO scandals of corruption spilling over to the European Union already



  14. European Patent Office (EPO) Management Not Supported by the EPO's Applicants, So Why Is It Still There?

    This third translation in the batch is an article similar to the prior one, but the text is a bit different (“Patente ohne Wert”)



  15. EPO Applicants Complain That Patent Quality Sank and EPO Management Isn't Listening (Nor Caring)

    SUEPO has just released 3 translations of new articles in German (here is the first of the batch); the following is the second of the three (“Kritik am Europäischen Patentamt – Patente ohne Wert?”)



  16. German Media About Industry Patent Quality Charter (IPQC) and the European Patent Office (EPO)

    SUEPO has just released 3 translations of new articles in German; this is the first of the three (“Industrie kritisiert Europäisches Patentamt”)



  17. Geminispace Continues to Grow Even If (or When) Stéphane Bortzmeyer Stops Measuring Its Growth

    A Gemini crawler called Lupa (Free/libre software) has been used for years by Stéphane Bortzmeyer to study Gemini and report on how the community was evolving, especially from a technical perspective; but his own instance of Lupa has produced no up-to-date results for several weeks



  18. Links 27/05/2023: Goodbyes to Tina Turner

    Links for the day



  19. HMRC: You Can Click and Type to Report Crime, But No Feedback or Reference Number Given

    The crimes of Sirius ‘Open Source’ were reported 7 days ago to HMRC (equivalent to the IRS in the US, more or less); but there has been no visible progress and no tracking reference is given to identify the report



  20. IRC Proceedings: Friday, May 26, 2023

    IRC logs for Friday, May 26, 2023



  21. One Week After Sirius Open Source Was Reported to HM Revenue and Customs (HMRC) for Tax Fraud: No Response, No Action, Nothing...

    One week ago we reported tax abuses of Sirius ‘Open Source’ to HMRC; we still wait for any actual signs that HMRC is doing anything at all about the matter (Sirius has British government clients, so maybe they’d rather not look into that, in which case HMRC might be reported to the Ombudsman for malpractice)



  22. Links 26/05/2023: Weston 12.0 Highlights and US Debt Limit Panic

    Links for the day



  23. Gemini Links 26/05/2023: New People in Gemini

    Links for the day



  24. IRC Proceedings: Thursday, May 25, 2023

    IRC logs for Thursday, May 25, 2023



  25. Links 26/05/2023: Qt 6.5.1 and Subsystems in GNUnet

    Links for the day



  26. Links 25/05/2023: Mesa 23.1.1 and Debian Reunion

    Links for the day



  27. Links 25/05/2023: IBM as Leading Wayland Pusher

    Links for the day



  28. IRC Proceedings: Wednesday, May 24, 2023

    IRC logs for Wednesday, May 24, 2023



  29. Links 25/05/2023: Istio 1.16.5 and Curl 8.1.1

    Links for the day



  30. Gemini Links 25/05/2023: On Profit and Desire for Gemini

    Links for the day


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts