Eye on Security: Internet Still Threatened by Microsoft Windows
- Dr. Roy Schestowitz
- 2010-07-20 10:49:10 UTC
- Modified: 2010-07-20 10:49:10 UTC
Summary: New Windows Trojans, malware, and the likes of that
●
Can Windows kill the Internet?
I've long thought that someday Windows' security problems could foul up the Internet for everyone. That day may be arriving.
It's not just me being paranoid about Windows. It's the ISC (Internet Storm Center), the group that tracks the overall health of the Internet. They're wondering whether the newly discovered "LNK" exploit might be used to slam the brakes on the Internet's high-speed traffic.
According to Lenny Zeltser, an ISC security consultant, the ISC has
decided to raise the Infocon level to Yellow to increase awareness of the recent LNK vulnerability and to help preempt a major issue resulting from its exploitation. Although we have not observed the vulnerability exploited beyond the original targeted attacks, we believe wide-scale exploitation is only a matter of time. The proof-of-concept exploit is publicly available, and the issue is not easy to fix until Microsoft issues a patch. Furthermore, anti-virus tools' ability to detect generic versions of the exploit have not been very effective so far.
●
New Menace in the War Against Online Crime
Avoiding Web-borne infections is increasingly difficult, because many malicious sites are legitimate sites that have been hacked. But here are four steps to take to protect your computer:
1) Use the latest version of your favorite Web browser, because most have important anti-malware technologies not available in the older models. Consider using Google Chrome, which uses so-called sandboxing technology to stop drive-by downloads.
●
Microsoft initiates zero-day vulnerability probe
Microsoft is investigating reports of ongoing "targeted attacks" that reportedly exploit a serious Windows Shell vulnerability.
●
Zeus baddies unleash nasty new bank Trojan
Hackers have created a new version of the Zeus crimeware toolkit that's designed to swipe bank login details of Spanish, German, UK and US banks.
The malware payload, described by CA as Zeus version 3, is far more selective in the banks it targets. Previous versions targeted financial institutions around the world while the latest variant comes in two flavours: one that only target banks in Spain and Germany, and a second that only targets financial institutions in the UK and US.
●
MS Patch Tuesday: Googler zero-day fixed in 33 days
●
You Have to Wait a Month for Reinforcements
Folks who have migrated to GNU/Linux may have to work hard to make the transition but they can relax a lot afterwards. That other OS and its apps will be around for years drawing attention from malware and GNU/Linux will just keep growing staying small and modular with lots of immunity built in. The cost of fighting malware is almost entirely born by users of that other OS and GNU/Linux gets a free ride. I like that. The cost of monopoly is compounding itself and the price of Freedom declines.
Recent Techrights' Posts
- Why We Publish Information About the SLAPPs (But Not About the Legal Process), an Abuse of Process by Americans Trying to Silence Critics of Their Employer, Microsoft
- It doesn't take thousands of pages to explain something simple
-
- The Register MS Says "AI Web Crawlers Are Destroying Websites", So Why Does The Register MS Help 'AI' Companies? (Spoiler: Money)
- People need to call out The Register MS on its hypocrisy
- Slopfarms Already Peaked, They Will Die When Slop Companies Run Out of Money to Borrow
- slopfarms will lack an actual "engine"
- Links 02/09/2025: Attacks on Unions, Microsoft TCO, and DDoSing a Growing Problem
- Links for the day
- Internet Relay Chat Didn't Fall Off a Cliff
- IRC will turn 40 in less than 3 years from now
- The UEFI 9/11 - Part V - This is Not a Drill (Disable "SecureBoot" Now)
- A "9/11" Coming
- There's No Obligation to Speak to Anybody
- The very fact that "bkuhn" is till spending time in social control media says a lot about his poor judgment
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Monday, September 01, 2025
- IRC logs for Monday, September 01, 2025
- Microsoft Trying to Force People to Resign (Amid Mass Layoffs) a Strategy That Takes Its Toll
- Microsoft seems to be circling down the drain and the "final flush" will be the moment the "hey hi" (AI) bubble implodes completely
- Google Simply Cannot Be Trusted
- Only fools would trust GAFAM
- Admission That a Third Party (or Parties) Funds the SLAPPs Against Techrights
- This can end up costing them over a million dollars
- Modifying and Writing One's Own Computer Programs is Not a Crime (or: Google Proves That Stallman Was Right)
- We're generally gratified to see so many positive mentions of him
- Why We Stopped Publishing Videos (for Now)
- We'll probably get back to videos one day, but it's hard to say when or to what extent
- What Animal Rights Activism Teaches Us About Sympathy and Focus
- It's possible to believe that the planet is warming, that we must do something about it, and still eat eggs and butter
- When You Turn Web Sites About Tech Into Political Sites
- A lot of people fall into the trap of catering only for particular groups
- Gemini Links 02/09/2025: ROOPHLOCH 2025 and Lagrange 1.19 Released
- Links for the day
- Gemini Links 01/09/2025: News Corp. WSJ and A Month With NixOS
- Links for the day
- “Sideloading” Never Killed Anybody
- There are many online discussions this week about the misnomer "sideloading"
- Slopwatch: Google News as FUD Vector Against Linux and Plagiarism Enhancer, Serial Slopper (SS) Uses LLMs to Googlebomb "Linux"
- Slop destroys the Web not just by screwing with search engines and helping plagiarists. It's also responsible for de facto DDoS attacks...
- Links 01/09/2025: "Attacks on Science" and China's "Soft Power" Grows
- Links for the day
- Links 01/09/2025: Fresh Backlash Against Slop and "Norway’s Electricity Crisis is About to Hit Britain"
- Links for the day
- Writing and Coding Isn't Always Enough
- Last year we had to assume a role we didn't have before: litigants
- Links 01/09/2025: Catching Up (Mostly via Deutsche Welle), "Windows TCO" Effect in UK
- Links for the day
- Gemini Links 01/09/2025: Linguistic Barriers and "Web 1.0 Hosting"
- Links for the day
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Sunday, August 31, 2025
- IRC logs for Sunday, August 31, 2025
- Autumn Has Come
- Autumn should be exciting in all sorts of ways; it'll also mark our anniversary
- The UEFI 9/11 - Part IV - External Interference
- They all seem to be playing a role in crushing Software Freedom and self-determination for users
- Links 31/08/2025: Baggage Claim Scams, an Insurrectionist’s War on Culture, and a Sudden Robotics Hype
- Links for the day
- Gemini Links 31/08/2025: Reviewing Netsurf and Slightly Less Historic Ada Design
- Links for the day
- IBM Has Taken Control of GNOME
- Don't expect a successor to be found any time soon
- Links 31/08/2025: Google Gmail Data Breach and LF Puff Pieces for Pay
- Links for the day
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Saturday, August 30, 2025
- IRC logs for Saturday, August 30, 2025
- This is What Google News Has Become
- Moments ago