02.18.10

Gemini version available ♊︎

Here Come Many More Microsoft Windows Attacks

Posted in Microsoft, Security, Windows at 6:01 pm by Dr. Roy Schestowitz

Computer danger

Summary: A lot of security headaches caused to lot of people, all due to Microsoft Windows being so vulnerable

Yesterday we wrote about Microsoft's risk that impacts people's lives. Blame Microsoft’s utter negligence [1, 2, 3] for it. Where there is deliberate negligence there is also liability and responsibility.

It has been surprising to some network experts that the Internet has yet not come under an attack that fragments or altogether suspends it at root level [1, 2]. It’s not as though it is impossible; it’s just that nobody has dared to trigger it just yet and the United States considers bombing (in the physical sense) any botmaster who may attempt this. According to this latest report, the United States is not prepared for an attack from Windows botnets.

During the simulated cyber attack that took place yesterday in Washington and was recorded by the CNN, one thing became clear: the US are still not ready to deflect or mitigate such an attack to an extent that would not affect considerably the everyday life of its citizens.

Already, there are some notable attacks that show up in the news. Here is an article that will appear in the New York Times tomorrow:

A malicious software program has infected the computers of more than 2,500 corporations around the world, according to NetWitness, a computer network security firm.

It’s a John Markoff article, so neither Microsoft nor Windows are mentioned, as usual. Under some pressure he once made an exception. Here is a similar report from Reuters:

Virus has breached 75,000 computers: study

A new type of computer virus is known to have breached almost 75,000 computers in 2,500 organizations around the world, including user accounts of popular social network websites, according Internet security firm NetWitness.

Here is another Windows disaster unfolding:

City of Norfolk hit with code that takes out nearly 800 PCs

Malicious code that mysteriously found its way onto an internal virtual print server took out nearly 800 computers used by the city of Norfolk, Virginia, last week.

The code apparently was activated when workers shut down their computers, said Hap Cluff, IT director for the city of Norfolk. “It was triggered by the action of logging off,” he said. ”

The code nearly wiped out the C drives of the 784 affected computers and essentially deleted the Windows operating system. The contents of the system folders on those machines, normally about 1.5GB in size, shrunk to 500 MB, he said.

Yes, all the above indicates that it’s a Windows problem. More here:

Hap Cluff, director of the information technology department for the City of Norfolk, said the incident began on Feb. 9, and that the city has been working ever since to rebuild 784 PCs and laptops that were hit (the city manages roughly 4,500 systems total).

Wonderful, eh? Here is an article about source of vulnerabilities, based on data that we mentioned in yesterday's post about security.

Just as they did last year, over thirty international security organisations have come together, to publish a list of the 25 most dangerous programming errors leading to vulnerabilities that can be exploited for cybercrime and espionage. The 2010 CWE/SANS Top 25 Most Dangerous Programming Errors has been updated with a number of improvements to how the errors are graded, prioritised and categorised. For example, new “Focus Profiles” allow readers to quickly see the listed errors sorted for particular professionals’ interests.

As we pointed out yesterday, Microsoft is not well positioned here and its general programming practices and use cases (e.g. clicking attachment to execute) are part of the problem. One might add to this the fact that Microsoft’s patches vulnerabilities poorly and sloppily, often hiding known flaws until they are actively exploited.

“Our products just aren’t engineered for security.”

Brian Valentine, Microsoft executive

Share in other sites/networks: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Reddit
  • email

Decor ᶃ Gemini Space

Below is a Web proxy. We recommend getting a Gemini client/browser.

Black/white/grey bullet button This post is also available in Gemini over at this address (requires a Gemini client/browser to open).

Decor ✐ Cross-references

Black/white/grey bullet button Pages that cross-reference this one, if any exist, are listed below or will be listed below over time.

Decor ▢ Respond and Discuss

Black/white/grey bullet button If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

3 Comments

  1. Needs Sunlight said,

    February 19, 2010 at 2:13 am

    Gravatar

    Hmm “Blame Microsoft’s utter negligence”? It’s no longer MIcrosoft’s fault at this point. The company’s complete product line is well known. Now it is the fault of the managers who allow Microsoft product in their work environment and the fault of the employees that roll out Microsoft products.

    Look at it this way. It’s perfectly fine to manufacture and sell lead salts. It’s not fine to use them as artificial sweeteners.

    Roy Schestowitz Reply:

    Blame false advertising then. I am going to have some posts on the subject shortly.

    Robotron 2084 Reply:

    It’s not the fault of any one group. Everyone is to blame to some extent, including users and the computer experts who try to help them. This article from Reuters talks about users who become so baffled by computer jargon that they become completely turned off to learning about security.

    http://www.reuters.com/article/idUSTRE61I2OB20100219

DecorWhat Else is New


  1. Links 06/06/2023: Angie 1.2.0, New EasyOS and EndeavourOS Released

    Links for the day



  2. Gemini Links 06/06/2023: OpenKuBSD, GrapheneOS, and More

    Links for the day



  3. Links 06/06/2023: OpenSUSE Plans for Leap

    Links for the day



  4. Gemini Links 06/06/2023: Bubble 4.0, Neutral News, and Older Bits

    Links for the day



  5. IBM's War on Open (Look at the Pattern of Layoffs at Red Hat)

    By abandoning OpenSource.com and OpenOffice.org/LibreOffice IBM sends out a clear signal that it doesn’t understand or simply does not care about the community of Free software users; its siege against the FSF and other institutions never ended and today we look at who’s being laid off or shown the door (the work environment is intentionally being made worse)



  6. Links 06/06/2023: IceWM 3.4.0 and Liveslak 1.7.0

    Links for the day



  7. Gemini Links 06/06/2023: Apple Might Kill VR, Tea Tea Deluxe 1.2.7 and Tea Land

    Links for the day



  8. IRC Proceedings: Monday, June 05, 2023

    IRC logs for Monday, June 05, 2023



  9. Links 05/06/2023: Debian 12 Almost Ready, Hong Kong 'Cannot' Remember Tiananmen Massacre

    Links for the day



  10. Gemini Links 05/06/2023: New Ship in Cosmic Voyage, Stack Overflow Moderator Strike

    Links for the day



  11. IRC Proceedings: Sunday, June 04, 2023

    IRC logs for Sunday, June 04, 2023



  12. Links 04/06/2023: Unifont 15.0.05 and PCLinuxOS Stuff

    Links for the day



  13. Gemini Links 04/06/2023: Wayland and the Old Computer Challenge

    Links for the day



  14. StatCounter: GNU/Linux (Including ChromeOS) Grows to 8% Market Share Worldwide

    This month’s numbers from StatCounter are good for GNU/Linux (including ChromeOS, which technically has both GNU and Linux); the firm assesses logs from 3 million sites and shows Windows down to 66% in desktops/laptops (a decade ago it was above 90%) with modest growth for GNU/Linux, which is at an all-time high, even if one does not count ChromeOS that isn’t freedom- or privacy-respecting



  15. Journalism Cannot and Quite Likely Won't Survive on the World Wide Web

    We’re reaching the point where the overwhelming majority of new pages on the Web (the World Wide Web) are basically junk, sometimes crafted not by humans; how to cope with this rapid deterioration is still an unknown — an enigma that demands hard answers or technical workarounds



  16. Do Not Assume Pensions Are Safe, Especially When Managed by Mr. EPOTIF Benoît Battistelli and António Campinos

    With the "hoax" that is the financial assessment by António Campinos (who is deliriously celebrating the inauguration of illegal and unconstitutional kangaroo courts) we urge EPO workers to check carefully the integrity of their pensions, seeing that pension promises have been broken for years already



  17. Links 04/06/2023: Why Flatpak and Wealth of Devices With GNU/Linux

    Links for the day



  18. Gemini Links 04/06/2023: Rosy Crow 1.1.3 and NearlyFreeSpeech.NET

    Links for the day



  19. IRC Proceedings: Saturday, June 03, 2023

    IRC logs for Saturday, June 03, 2023



  20. Links 04/06/2023: Azure Outage Again (So Many!) and Tiananmen Massacre Censored

    Links for the day



  21. Links 03/06/2023: Qubes OS 4.2.0 RC1 and elementaryOS Updates for May

    Links for the day



  22. Gemini Links 03/06/2023: Hidden Communities and Exam Prep is Not Education

    Links for the day



  23. Links 03/06/2023: IBM Betraying LibreOffice Some More (After Laying off LibreOffice Developers)

    Links for the day



  24. Gemini Links 03/06/2023: Bubble Woes and Zond Updates

    Links for the day



  25. Links 03/06/2023: Apache NetBeans 18 and ArcaOS 5.0.8

    Links for the day



  26. IRC Proceedings: Friday, June 02, 2023

    IRC logs for Friday, June 02, 2023



  27. The Developing World Abandons Microsoft Windows, GNU/Linux at All-Time Highs on Desktops/Laptops

    Microsoft, with 80 billion dollars in longterm debt and endless layoffs, is losing the monopolies; the media doesn’t mention this, but some publicly-accessible data helps demonstrate that



  28. Links 02/06/2023: Elive ‘Retrowave’ Stable and Microsoft's Half a Billion Dollar Fine for LinkeIn Surveillance in Europe

    Links for the day



  29. Linux Foundation 'Research' Has a New Report and Of Course It Uses Only Proprietary Software

    The Linux Foundation has a new report, promoted by Clickfraud Spamnil and others; of course they’re rejecting Free software, they’re just riding the “Linux” brand and speak of “Open Source” (which they reject themselves)



  30. Links 02/06/2023: Arti 1.1.5 and SQL:2023

    Links for the day


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts