EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

01.14.10

Chinese Google ‘Attack’ Involves Microsoft Windows Flaws

Posted in GNU/Linux, Google, Microsoft, Security, Windows at 8:21 pm by Dr. Roy Schestowitz

China satellite image

Summary: It is not Google’s fault but Microsoft’s fault that China managed to compromise accounts not just of Google but of over 20 other companies, by Microsoft’s own admission

YESTERDAY we mentioned Google’s reaction to attacks from China, which are now confirmed to be targeting different companies. It was not something against Google as Google is one among several victims and some people doubt there will be an exit from the largest Internet market.

How would leaving the Chinese market actually prevent Chinese crackers from connecting to Google servers? It would not.

Hacking Risks Persist Even If Companies Withdraw From China

Google and other enterprises still face a bleak computer security landscape that makes their companies vulnerable to hackers, whether they do business in China or not, analysts say.

Perhaps the most interesting revelation, which was found buried deep inside reports, is the role of Windows in these attacks on Google. Check this one out for example: (the emphasis in red is ours)

More sources are now claiming the Chinese government is behind the recent cyberattacks against Google and 33 other Silicon Valley companies, reports security firm Verisign iDefense. The attacks, revealed yesterday via a posting on Google’s official blog, were hacking attempts on the technology infrastructure of Google and other major corporations in sectors that included finance, technology, media and chemical, said Dave Girouard, president of Google Enterprise.

[...]

While July’s attacks were detected early and were largely uneventful, December’s attacks did find some success. In addition, these same sources claim that the files in both cases share similar characteristics. For example, both attacks used a backdoor Trojan in the form of a Windows DLL, and both share two similar hosts for the command-and-control (C&C) communication. In layman’s terms, if the cyberattack was a ground assault during a war, the C&C would be the general barking out the orders. Also in both incidents, the IP addresses used for C&C are in the same subnet and only six addresses apart from each other. That means both attacks are likely to have been instigated by the same entity and may imply that the recent victims’ technology infrastructure has been compromised since July.

When one in two Windows PCs is said to be a zombie PC, the above should not be surprising. This was a targeted attack which must have relied on China activists’ use of Microsoft Windows.

As the name suggests, the carefully crafted assaults differ from the net-cast-wide malware most often seen. A targeted attack specifically selects its victim and generally sends an e-mail using that person’s name and perhaps business title. The body of the message might reference an attached list of business contacts, or describe it as an invoice, or use any other hook that would allay suspicion and convince the victim to double-click the attachment.

Real activists do not use Windows and should use GNU/Linux. A few moments ago, our reader Jose added information that confirms the above. It’s an AP article titled “Microsoft’s browser flaw exposed Google to hackers” and it says (in the opening): “Microsoft says a security flaw in its Internet Explorer browser played a role in the recent computer attacks against Google and at least 20 other companies.”

In other news, a bank server has just been compromised and Baidu got hit by the same group that exploited Windows botnets to take down Twitter [1, 2, 3, 4, 5, 6]. We mentioned this story here and there’s more from The Register:

The same group that used a DNS attack to hijack Twitter last month has defaced the home page of Chinese search engine Baidu.

Surfers visiting Baidu site on Monday night were confronted by the message “This site has been hacked by Iranian Cyber Army”, together with an image of the Iranian flag. Early speculation suggests the attack involved changing Baidu’s DNS records rather than a direct attack on the site itself, but this remains unconfirmed.

Baidu — unlike Google — was not a victim of customers who use Windows. Google should tell customers that it’s not Google that’s vulnerable; it’s Windows. Customers should therefore rethink their platform preferences. The same already goes for banks, for similar reasons.

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

13 Comments

  1. Yuhong Bao said,

    January 14, 2010 at 8:50 pm

    Gravatar

    “Check this one out for example: (the emphasis in red is ours)”
    That is not enough evidence, as it do not say anything about security holes in Windows being used.
    But turned out that flaws in IE was indeed used in the attacks, again by MS’s own admission:
    http://arstechnica.com/microsoft/news/2010/01/microsoft-warns-of-ie-security-flaw-used-in-google-attacks.ars
    And technically IE is indeed part of Windows, though other web browsers work on Windows too that do not have the flaw.
    But Adobe was partly to blame too:
    http://www.computerworld.com/s/article/9144378/Hackers_used_rigged_PDFs_to_hit_Google_and_Adobe_says_researcher

    Roy Schestowitz Reply:

    It seems like a case of “double-click to execute” in Windows, invoking proprietary software that’s vulnerable (opening of a file leading to system compromise).

    Yuhong Bao Reply:

    Nope, it did turned out to depend on a real security vulnerability, but if that was true, it would not be MS’s fault at all (unless a stupid feature like AutoPlay was used), and that is my point.

    your_friend Reply:

    Not a Microsoft flaw? Was it a Mac Botnet? A GNU/Linux botnet? An OpenSolaris or BSD botnet? How about a botnet within Google’s own servers? I don’t think win32.dll will run in any of those others. Only Microsoft computers have this kind of problem. Nailing down the exact causes of these massive attacks will be like naming ants, there are too many security problems in Windows to begin to make sense of it and the botnet masters use them all.

    Windows needs to be taken off the web before it ruins the web for everyone.

    Yuhong Bao Reply:

    Indeed, I was not claiming that the botnet runs on anything other than Windows, I was trying to say that just because that it runs on Windows doesn’t mean MS is to blame. Now it did turned out MS is indeed partly to blame, I was just saying that the cited evidence was not enough.

    Yuhong Bao Reply:

    “Was it a Mac Botnet? A GNU/Linux botnet? An OpenSolaris or BSD botnet? How about a botnet within Google’s own servers?”
    Yes, these are all in theory possible, which is why assigning blame properly is so important.

    Yuhong Bao Reply:

    Now, whether this flaw warrant a switch away from Windows would be a different matter, but I will say that it would warrant a switch away from IE, not Windows. After all, IE gets security flaws almost all the time, and do people switch away from Windows because of it? No, of course not, since you can run other browsers on Windows.

    Roy Schestowitz Reply:

    I have an update on this:

    Adobe Flaw Wasn’t Part of Attack on Google

    http://www.pcworld.com/article/187043/adobe_flaw_wasnt_part_of_attack_on_google.html?tk=rss_news

  2. NotZed said,

    January 15, 2010 at 6:51 am

    Gravatar

    I’d like to see google show some real nuts and ban microsoft products from their services, if they are the real basis of the problem.

    (TBH, I don’t have much sympathy with anyone using Microsoft Windows and being taken advantage of – in an informed world they have some responsibility for their dumb decisions too.)

    Needs Sunlight Reply:

    Ten and eleven years ago, there were quite a few university IT departments which started to ban Microsoft products. You can see now how technical decisions were overridden with organized crime-like methods.

    Microsofters were complaining that University educated engineers and technical staff, ” someone on team fresh out of college”, knew better than to run Microsoft products. See slide 2:
    http://groklaw.net/staticpages/index.php?page=ComesExhN04#E9346

    Roy Schestowitz Reply:

    This reminds me that we ought to do more Comes-derived posts pretty soon. I’ve been sent some pointers to yet-undiscovered smoking guns.

    Yuhong Bao Reply:

    In this case, it is an IE flaw, and Google is already encouraging a switch away from IE.

    Roy Schestowitz Reply:

    Thanks. I shall do a followup post.

What Else is New


  1. SIPO (China's Patent Office) Taken Over by Patent Maximalists

    A look at China's race to the bottom (decline in quality) when it comes to patents, assuming quite wrongly that quantity is more important than quality and severe penalties for perceived infringement will spur innovation



  2. The Alice Case Continues to Smash Software Patents (This Time OpenTV's); Will the EPO Ever Pay Attention?

    The potency or the grip of software patents in the United States is quickly eroding, but the EPO continues to act as though software patents are legitimate



  3. EPO Staff Responds to Team Battistelli's Expansion to Include French Economic Propagandist on the Payroll

    With strings attached (like string puppets of Battistelli in various units including the Investigative Unit), can the new Chief Economist, who is French and paid by Battistelli, ever be trusted?



  4. UPC: To Understand Who Would Benefit From It Just Look at Who's Promoting It (Like TPP)

    The UPC, which is designed to aid patent trolls and aggressors (and their lawyers), is still being advanced by the EPO and some misinformed (but loyal to these former groups) politicians



  5. Trolls Molestos: Rovi (del famoso Angry Birds) Ayuda al Más Largo Troll de Patentes de Microsoft Intellectual Ventures (Corregido)

    Alguna vez conocido como hacedor de juegos y más tarde como vigilancia en masa en jugadores, Rovi ahora se ESTA ALIANDO CON EL MÁS GRANDE TROLL DE PATENTES



  6. Estadísticas de Invalidación de Patentes y Costos de Litigación de Patentes (incluso si son falsas) Muestran que la Esfera de Patentes y los Estándares de Examinación son un Probleman, No Sólo en Los Estados Unidos

    Demasiadas falsas patentes que no deberían haber sido otorgadas en primer lugar y fraudulentes jucios de patentes que terminan en favor del acusado sirve para mostrar el costo externo (o externalidad) cuando set trata de un bajisímo sistema de patentes que se esfuerza en otorgar muchas patentes irrespectivamente de su mérito.



  7. The 'Offenses' of EPO Staff Representatives Boil Down to Truth-Telling

    Dutch television examined the documents of the mock 'trials' against SUEPO leaders and concluded that whistle-blowing (i.e. exposing abuses by EPO management), not misconduct, is the reason for overzealous dismissals



  8. Rumours About Dismissal of Benoît Battistelli and New Letter From Union Syndicale Federale Blasting Battistelli's Behaviour

    hings have been heating up since the dismissal of staff representatives at the European Patent Office (EPO) and some even spread rumours about withdrawal/dismissal of the EPO's President



  9. VirnetX Case Against Apple Shows Not the Problem With Patent Trolls But With Software Patents

    What the media really ought to be talking about after the high-profile VirnetX case, rather than obsess about the status of Apple or patent trolls in the Eastern District of Texas



  10. Diápositivas de Nueva Charla Explican la Connección Entre la Corte De Patentes Unitarias (UPC) y Patentes de Software

    Benjamín Henrion habló el pasado Domingo acerca de las patentes de software europeas -una presentación que habla de la Corte Unitaria de Patentes, por la que la OEP aboga sin cesar y que es lo que significa para las patentes de software.



  11. Las Políticas de Microsoft Alienan Incluso a los Hinchas Más Acérrimos de Microsoft, Incluyendo Pro-Microsoft Web Sites

    El agresivo comportamiento de Microsoft y su BAJA CALIDAD DE PRODUCTOS dejan algunos de sus últimos restos de ´hinchas´ descorazonados y molestos.



  12. Links 6/2/2016: CoreOS Rocket 1.0, Scientific Linux 7.2

    Links for the day



  13. Maybe It's Time for Class Action Lawsuits Against Microsoft for Forced Vista 10 'Upgrades', Which Were Definitely No Accident

    The sheer arrogance of Microsoft, which silently changes the operating system on people's computers (without their consent), makes lawsuits imperative, not just a possibility



  14. Readers' Article: A Strange Conspiracy of Silence in the German Media (Part II)

    Željko Topić's allegedly dark background, which includes a suicide, a retreat of potential witnesses, German funds in Topić's private bank account and several more interesting bits



  15. Links 5/2/2016: Wine 1.9.3, Slackware 14.2 Beta 2

    Links for the day



  16. Links 4/2/2016: Red Hat Upgraded, Ubuntu Tablet

    Links for the day



  17. The Siege Continues: Patent Lawyers Want More Patents, Including Software Patents, In Spite of Alice

    Lawyers who make money from patent disputes make rather apparent their aspirations, which include patent saturation even in domains that are patents-exempt



  18. European Patent Office Pretends It's Business as Usual and Prepares New Vanity Pieces

    The PR strategy of the EPO, whose destructive patent strategy continues unabated (for now), latches onto Colombia and strives to manufacture mythology wherein the public, patent examiners and patent applicants are all very happy with the EPO



  19. The 'International' Trade Commission Imposes/Reinforces Software Patents to Establish Another Embargo

    The International [sic] Trade Commission is meddling in competition and allowing a US giant, Cisco in this case, to potentially block rivals (no imports from abroad) using software patents



  20. Readers' Article: A Strange Conspiracy of Silence in the German Media (Part I)

    The views of some of our readers regarding reluctance in the German media to challenge the EPO's violations of German law, probably because Germany benefits from being a host nation of the EPO



  21. Benoît Battistelli's EPO: From Show Trials and Mock Trials to a Self-Aggrandising Propaganda Event Later Today in Rijswijk

    A headsup from a reader regarding today's highly misleading event in Rijswijk (e.g. to mislead the media or seed positive media coverage in the Netherlands) and how it was set up



  22. Caricature of the Day: EPO President

    New caricature about Benoît Battistelli, his bodyguards, and the assault on free speech at the European Patent Office



  23. Company Known as European Patent Office Provides Tips on How to Patent Software in Europe

    The European Patent Office (EPO) uses its attendance at CeBIT, which is a corporate expo, to promote software patents in spite of the European Patent Convention (EPC)



  24. Links 3/2/2016: Dell GNU/Linux Laptop, Wine 1.8.1

    Links for the day



  25. The Most Detailed Explanation (Yet) of What's Wrong With the EPO

    The EPO's insistence that it remains above the law is not only coming under fire by the media but is also being challenged based on people who are familiar with the applicability of law to international organisations



  26. Angry Trolls: Rovi (of Angry Birds Fame) Helps Microsoft's Largest Anti-Linux Patent Troll, Intellectual Ventures (Corrected)

    nce known as a game maker and later made notorious for mass surveillance on gamers, Rovi now liaises with the world's largest patent troll



  27. Patent Invalidation Statistics and Cost of Patent Litigation (Even If Bogus) Show That Patent Scope and Examination Standards a Problem in Europe, Not Just the US

    Far too many bogus patents (patents that should not be granted in the first place) and spurious patent lawsuits that end up in favour of the defendant serve to show the external cost (or externality) when it comes to low-quality patent systems that strive to grant a lot of patents irrespective of merit



  28. Es Oficial: Por Medio de Entrismo, Microsoft Ha Convertido a la Pro-Linux Nokia en un Parásito de Patentes Anti-Linux

    Microsoft ha convertido a Nokia en un troll de patentes que ahora ataca a Linux y Android.



  29. Richard Stallman: Patentes Europeas de Software Regresan con la Corte Unitaria de Patentes (UPC)

    Debates acerca de la UPC estan siendo peleados por profesionales de software (entidades prácticantes) y elementos PARÁSITICOS como los abogados de patentes.



  30. SUEPO (EPO Staff Union) Appears to Have Launched a New and Improved Web Site After Attempts to Crush ('Decapitate') SUEPO

    SUEPO, the largest staff union of the European Patent Office, shows signs of strength rather than signs of weakness amidst attacks on the staff and a lot of media coverage, political interventions, and much more


CoPilotCo

RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

CoPilotCo

Recent Posts