05.05.10

Eye on Security: Windows 2003 Web Sites Defaced, SharePoint 2007 Suffers Zero-Day Vulnerability

Posted in Australia, Finance, Microsoft, Security, Vista, Vista 7, Windows at 2:22 pm by Dr. Roy Schestowitz

Secure OS

Summary: IDG report about mass defacements of Windows sites in Australia and other security problems that are new

HAVING just taken a glance at the past week’s news from IDG*, we found:

i. Australian Cereal Hacker on Defacement Rampage

The ANZAC Day attacks were conducted by a single hacker, or hacking group, and affected Windows 2003 operating systems.

ii. Microsoft Investigates SharePoint 2007 Zero Day

Microsoft is scrambling to fix a bug in its SharePoint 2007 groupware after a Swiss firm abruptly released code that could be used in an attack.

The proof-of-concept code was released Wednesday, just over two weeks after security consultancy High-Tech Bridge says it disclosed the issue to Microsoft on April 12.

iii. Texas Man to Plead Guilty to Building Botnet-for-hire

A Mesquite, Texas, man is set to plead guilty to training his 22,000-PC botnet on a local ISP — just to show off its firepower to a potential customer.

The third article ought to call out Windows, which is responsible for hundreds of millions of zombie PCs

Microsoft views vulnerabilities also as an opportunity. Here is the latest propaganda whose purpose is apparently to sell Vista 7 using ‘security’ as an excuse (Microsoft is hiding flaws without ever reporting them, probably in order to distort statistics). As we showed before, Vista 7 is not secure. To name some older posts on the subject:

Ian Paul from IDG has just written about Vista 7′s “worst features”:

Windows 7 fixed many of Vista’s ills, but it also introduced a few of its own.

IDG also has this new article about the LoveBug worm, which is estimated to have cost $5-8 billion in damages (for one worm alone). Needless to say, Microsoft did not carry the burden of these damages.

When the LoveBug worm hit 10 years ago, it was a different time when people believed admirers were really reaching out to say “I love you”, personal firewalls were turned off by default and executable attachments weren’t blocked at e-mail gateways.

Those circumstances allowed the Love Letter worm — the first Visual Basic script worm — to infect more than 50 million computers worldwide within a week, causing estimated $5 billion to $8 billion in damages, bringing down networks by maxing out their ability to fire off e-mails and causing painstaking disinfection of affected machines.

Here we are a decade later and Microsoft never resolved those issues which it continually promises to address.

“Our products just aren’t engineered for security.”

Brian Valentine, Microsoft executive

___
* We chose IDG so as not to be accused of choosing a Microsoft-hostile source.

Share in other sites/networks: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Reddit
  • email
  • Slashdot

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

What Else is New


  1. Links 27/10/2020: FuguIta 6.8, Fedora 33, Red Hat Satellite 6.8, KDE Plasma 5.20.2 and GStreamer 1.18.1

    Links for the day



  2. Site Changes Ahead of Anniversary

    We’re making some changes to the presentation and function of the site — changes that will become more prominent over the coming days



  3. IRC Proceedings: Monday, October 26, 2020

    IRC logs for Monday, October 26, 2020



  4. Links 26/10/2020: rpminspect 1.2, Open Source Hardware Certification and LibreOffice Conference

    Links for the day



  5. Links 26/10/2020: Debian "Bullseye" Artwork, Fwupd 1.5 Released

    Links for the day



  6. [Meme] Satya Na-DL

    Microsoft has shown its real priorities (just before the weekend when many people might not notice)



  7. Jonathan Wiltshire and Debian, Falsified Harassment Claims, Tiger Computing and GCHQ

    Reprinted with permission from Debian Community News



  8. Links 26/10/2020: Linux 5.10 RC1 and Loongsoon Laptops

    Links for the day



  9. The Downfall of Free Software Leaders (and Their Projects or Missions)

    "Cancel George Orwell, and happy hacking."



  10. IRC Proceedings: Sunday, October 25, 2020

    IRC logs for Sunday, October 25, 2020



  11. Links 25/10/2020: Kodi 18.9, ScummVM Android Love, Cutelyst 2.13

    Links for the day



  12. [Meme] Captain Zemlin and Neil McGovern's Ugly Legacy in GNOME (His Predecessors Work for Microsoft Directly Now)

    The Linux Foundation is already ‘sold’ and Microsoft Tim‘s interview with Neil McGovern, published a few days ago, was rather revealing (comments on the article/interview were also harsh)



  13. How Microsoft is Still Worse Than Google

    "I have decided that we should not publish these extensions. We should wait until we have a way to do a high level of integration that will be harder for the likes of Notes, Wordperfect to achieve, and which will give Office a real advantage."



  14. 'President Bill Gates' Wants to Punish Not Only Google After Using “Extensions” to the Web to Reinforce Microsoft's Monopoly (Antitrust Violations Are a Microsoft Thing)

    In gross distortion of facts and of history and in a rather incredible fashion (very shameless and insulting) the corporate media tries to paint Bill Gates as an antitrust hero that will save the world from monopolies



  15. Donald Trump Helped Bill Gates Increase His Wealth by More Than 50%, Especially During the Pandemic

    Contrary to ridiculous narratives disseminated by nutty accounts all around the Web, Gates and Trump are no foes but 'partners in crime'



  16. Our 14th Birthday is Coming

    We're turning 14 shortly and we need ideas from readers (things that can be done to mark the event and celebrate 'on-line')



  17. In Spite of IBM's Difficult Past and Particularly Dark History, Under Arvind Krishna’s Leadership It Has Only Shown Signs of Improving

    This winter, 6 months after Arvind Krishna’s tenure as CEO began, we can generally say that things seem to have improved and we look forward to further improvements



  18. Links 25/10/2020: GNU Taler's IETF Milestone, RISC OS 5.28 and New Ubuntu Community Council

    Links for the day



  19. IRC Proceedings: Saturday, October 24, 2020

    IRC logs for Saturday, October 24, 2020



  20. Links 24/10/2020: GDB 10.1, Kodachi 7.4, Wine 5.20

    Links for the day



  21. Celebrating Code of Conduct Violations

    Reprinted with permission from Daniel Pocock



  22. The Militarised Elephant in the Room Still Commands a Lot of Free Software Development

    We take a difficult (albeit in-depth and perfectly factual) look at IBM's past and present; considering this is the company that controls Red Hat (which in turn controls many key projects in GNU/Linux) we need a better understanding of the real context, not PR fluff and marketing



  23. Juve Patent's Love of Patent Trolls and Their Misinformation

    The press 'gutter' known as Juve (basically propaganda disguised as 'news' since years ago) has gotten to the point where the publisher is just an extension of lawyers and liars



  24. IRC Proceedings: Friday, October 23, 2020

    IRC logs for Friday, October 23, 2020



  25. Look How Many Tux I Give!

    "Long live rms, long live (Hyperbola) GNU/BSD, and happy hacking."



  26. Embrace, Extend, and Extensions: Two New Reasons to Delete GitHub, Which Microsoft Ruined for Everyone (Except the Copyright Cartel and Other Censors)

    GitHub is being turned into a garbage dump with malicious masters (or monsters, or mobsters); many people are denied access for using the 'wrong' browser and developers/projects are being censored (not for doing anything wrong or illegal, either)



  27. [Meme] When EPO Staff Claims to be 'Ill' or 'Sick'... During a Pandemic's European Peak

    Gotta check and verify that those 'lazy' EPO examiners aren't just faking being ill (in order to not meet "production" targets)



  28. The EPO Has Relegated or Lowered Itself to Extremely Poor Standards

    Today's EPO continues to reaffirm the image of global weakness; having failed to improve the working conditions and quality of the work (its actions did the exact opposite), it's nowadays begging China to send over lots of workload irrespective of quality or merit and it is outsourcing the functions of the Office to the United States



  29. Links 23/10/2020: Turing Pi 2, GNU Parallel 20201022

    Links for the day



  30. IRC Proceedings: Thursday, October 22, 2020

    IRC logs for Thursday, October 22, 2020


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts