EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

03.08.10

Apache Shows Why GNU/Linux is Safer Than Microsoft Windows; Microsoft Makes Batteries Dangerous

Posted in Free/Libre Software, GNU/Linux, Microsoft, Security, Windows at 12:41 pm by Dr. Roy Schestowitz

Battery charger

Summary: Windows shows that it not only brings security problems to Apache but also to battery chargers

THE thing about Windows is, the underlying operating system is less secure than UNIX and Linux. Here is nice new proof of this, straight from the news. Our reader renamed it (the headline) “Windows bug prompts Apache update advice”

“The vulnerability means that you can take complete control of the web server remotely with system privileges — which is the highest privilege on Windows,” Edelstein told ZDNet.com.au. “An attacker could gain access to, modify and take away data.”

Edelstein advised users running Apache on Windows platforms to upgrade immediately as users have no way of knowing if their web servers have been compromised. The company’s security advisory can be accessed here.

[...]

“A proof of concept remote exploit has been written by Sense of Security, and it is feasible that others could write a similar exploit to completely compromise a Windows system,” said Brett Gervasoni.

As most Apache users run it on UNIX and Linux, the above is probably nothing to panic or worry about.

Charged With Malware

“Microsoft, the company that made battery chargers dangerous,” called it the reader who sent this next item from the news:

The United States Computer Emergency Response Team (US-CERT) has warned that the software included in the Energizer DUO USB battery charger contains a backdoor that allows unauthorized remote system access.

In an advisory, the US-CERT warned that he installer for the Energizer DUO software places the file UsbCharger.dll in the application’s directory and Arucer.dll in the Windows system32 directory.

When the Energizer UsbCharger software executes, it utilizes the UsbCharger.dll component for providing USB communication capabilities. UsbCharger.dll executes Arucer.dll via the Windows rundll32.exe mechanism, and it also configures Arucer.dll to execute automatically when Windows starts by creating an entry in the HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run registry key.

“The danger of Open Source software is that you don’t know if it contains malware,” jokingly said our reader.

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • StumbleUpon
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Propeller
  • Slashdot
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

3 Comments

  1. your_friend said,

    March 8, 2010 at 9:55 pm

    Gravatar

    Ha ha, it went undetected for three years. The Windows version of that Energizer Bunny has been pulled from the market.

    Regardless of when it was created, its discovery prompted Energizer to announce March 5 that it was discontinuing the sale of the product and removing the site from which the software could be downloaded. In addition, the company is urging consumers who downloaded the Windows version of the software to uninstall it.

    It’s amazing how popular the wipe and reload becomes when Microsoft needs to sell a new version of Windows. Thanks for all the nice links.

  2. Needs Sunlight said,

    March 9, 2010 at 5:53 am

    Gravatar

    @your_friend : it did not go undetected for three years, Microsoft did not publicly acknowledge it for three years, or more. There is a lot of difference there.

    Wipe and reload becomes popular when Microsoft needs to sell new versions of Windows or when third party packages, of any kind, become too popular. Wipe and reload ensures that the 3rd party packages are knocked down at least a couple points in marketshare. It is to Microsoft’s advantage that they are so many decades behind Linux, OS X or even Solaris in regards to package management.

  3. uberVU - social comments said,

    March 11, 2010 at 5:51 pm

    Social comments and analytics for this post…

    This post was mentioned on Identica by schestowitz: #Apache Shows Why #GNU #Linux is Safer Than #Microsoft #Windows http://boycottnovell.com/2010/03/08/battery-chargers-and-malware/...

What Else is New


  1. Links 2/9/2010: New Survey Shows Red Hat GNU/Linux Increasingly Replacing Windows

    Links for the day



  2. Links 2/9/2010: Red Hat at Year Highs, Fake 'Open Source' Called Out

    Links for the day



  3. Microsoft Saved the Bush Family From Embarrassment

    A migration to Microsoft Exchange in the White House led to loss of crucial data which could help show how the United States entered wars and why



  4. Insanity of Microsoft Patents and the Insanity of 'Green' Patents

    Microsoft earns a patent monopoly on "[o]perating system shut down"; Patent monopolies prey on ideas that help preserve the planet



  5. Microsoft Looks to Communism for Answers

    Microsoft turns to China, hoping that therein exists some way to rescue Xbox 360; instead, China brings competition to Xbox 360, whose price is going up, not down



  6. "Novell Laboratories" and Patent Extortion Against Generic Drugs

    Notorious "death patents" are being used against Novell



  7. It's True, Android is Not Free (Because of Microsoft Patent Extortion)

    New FUD from Microsoft staff and a reminder of what it is that really puts a price tag on Android (and it's not Google)



  8. Bloomberg Gets the Facts Wrong (About SCO and Novell)

    Another example of Bloomberg publishing misinformation, which in this case serves SCO and thus harms Linux



  9. Red Hat Now Worth Almost 3.5 Times What Novell is Worth

    A look at Novell's decreasing relevance wrt to Red Hat and other companies that actually produce and distribute Free software, not proprietary software



  10. “Novell Inc (NOVL) Received an Offer in Early March and Has Yet to Announce a Deal.”

    Novell is still up for sale and the financial market expects some announcement to come sooner or later



  11. Microsoft Says Choose Microsoft to Avoid Lock-in

    Microsoft warns about VMware lock-in as it attempts to sell proprietary hype [sic] V



  12. IRC Proceedings: September 1st, 2010

    IRC logs for September 1st, 2010



  13. Links 1/9/2010: Linux in Ukraine, 'Green Party' of Belgium Moves to GNU/Linux Desktops

    Links for the day



  14. Microsoft Boosters of Software Patents in Linux/UNIX Sued for Patent Violation

    Centrify and Likewise get sued, having attempted to outdo Free software by faking it and adding software patents to it



  15. Microsoft Lobbyists Continue to Push for Software Patents in Europe (Transforming Government) to Tax Linux

    Microsoft wants European GNU/Linux users to pay through the nose, but first it needs to use lobbyists like Zuck to change the law in Europe, by pretending to speak for small businesses



  16. Microsoft Uses Linux to 'Succeed'

    Microsoft uses Linux-powered phones not just to make income (patent tax) but also to spread Microsoft propaganda, which includes Linux insults



  17. Links 1/9/2010: Chakra 0.2.0, Ksplice Free for Fedora

    Links for the day



  18. Apple's Co-founder Steve Wozniak a Patent Trolls' Apologist, Apple is Patenting DRM Ideas

    Wozniak helps prove that also departing co-establishers of proprietary predators defend patent trolling



  19. Microsoft is Said to Have Had an Anti-OpenOffice.org Seminar on Monday (Updated)

    The Microsoft camp is attacking Oracle's OpenOffice.org (OOOo) while pretending that Oracle is an "evil empire" (whereas Microsoft "loves" open source)



  20. Software Patents and Microsoft Hurt Korea as Country Tries to Escape Microsoft Monopoly and Market Abuses

    Microsoft dependencies, Ballnux in Korea, and the ill effects of software patents there



  21. Correcting Common Case of Misreporting: Novell is Not an Open Source Company

    Novell is a semi-shut (or "mixed source") company, not "Open Source" as some Web sites falsely report



  22. Microsoft Florian Promotes MPEG-LA at the Expense of Free Software, Defends Intellectual Monopolies Too

    A fine new example of people who promote Microsoft agenda while pretending to be "FOSS" people



  23. Links 31/8/2010: KDE 4.5.1, Linux 2.6.36 RC3, ACTA Threat Looming

    Links for the day



  24. IRC Proceedings: August 31st, 2010

    IRC logs for August 31st, 2010



  25. Links 31/8/2010: Linux Developer Community From Wind River, Multitouch Tablet

    Links for the day



  26. Patents Roundup: OIN, Patent Attorney Ignorance, “Ultimate Patent Troll”, the Rambus Submarine Patent, Death Patents, MPEG-LA, and i4i/Microsoft

    An overview of patent news from the past few days, ranging from issues that directly affect GNU/Linux to issues that simply show how amoral and dysfunctional the patent systems have become



  27. Why Paul Allen (Interval Patent Troll) Targets Companies That Do Not Cross-license With (or Pay) Microsoft

    A patchy pattern is spotted by Techrights -- a pattern wherein companies that are trolled for big cash by Microsoft's co-founder are actually not paying Microsoft for patents



  28. USPTO is Imperialistic

    Another new set of examples where the USPTO hijacks other countries' policies and threatens businesses overseas using the ITC



  29. IRC Proceedings: August 30th, 2010

    IRC logs for August 30th, 2010



  30. Oracle Promotes hypePod/hypeTunes Just Weeks After Suing Android, Java's Founder Has Message for Ellison

    Oracle is promoting Apple's products and Mister Java himself creates t-shirt designs to protest against Ellison's decision to sue Google with his own patents


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts