EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

07.27.10

New Flaw in Windows Facilitates More DDOS Attacks

Posted in Microsoft, Security, Windows at 5:03 pm by Dr. Roy Schestowitz

Stachledraht DDOS attack

Summary: Shoddy Microsoft software continues to provide opportunities for disgruntled people to attack and take down servers they dislike

ANY Windows botnet which is enabled by “Zeus” (Zeus is known to be a cause of DDOS attacks) is already taking advantage of Microsoft’s latest severe flaw which affects even fully patched Windows:

Miscreants behind the Zeus cybercrime toolkit and other strains of malware have begun taking advantage of an unpatched shortcut handling flaws in Windows. It was first used by a sophisticated worm to target SCADA-based industrial control and power plant systems.

No patch is available yet:

Security researchers have found more malware exploiting an unpatched Windows vulnerability via .LNK shortcut files.

According to Sophos blog July 23, two other pieces of malware have been observed targeting the bug. One is a keylogging Trojan the company is calling Chymin-A that is “designed to steal information from infected computers.” The other is Dulkis-A, a “worm written in obfuscated Visual Basic” that contains several subcomponents.

More here:

Slovakian security firm Eset reports the appearance of two malware strains that exploit security vulnerabilities in the way Windows handles .lnk (shortcut) files, first used by Stuxnet to swipe information from Windows-based SCADA systems from Siemens.

We covered those SCADA incidents earlier today. This has a serious impact on the world’s energy, not to mention those BP BSODs which we’ve already covered in [1, 2, 3].

The damage costs a lot of money and time (which can be equated to money) and the security world is “ill-equipped to solve digital whodunnits,” reports The Register.

“A lot of those efforts are very unqualified and pedestrian,” said Parker, who is director of security consulting services at Washington, DC-based Securicon. “There’s really not any science behind the efforts that many people have been making recently that have resulted in stories like China is attacking us, Russia is attacking us, Korea is attacking us.”

It is really hard to know where DDOS attacks come from these days. People don’t control their Windows PCs, which can be hijacked and chained back to some botmasters whose interests are not known.

Georgia has an unfortunate DDOS story to tell about its national infrastructure; after years of investigation it is still not perfectly clear if the Russian government had something to do with it or not. One youngster claims responsibility, but can he be believed? It can be hard to verify. And if one youngster can paralyse an entire nation, what does that teach us about those Windows zombies he used?

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

What Else is New


  1. Links 25/1/2015: Android Wear 5.0, Tizen in Bangladesh

    Links for the day



  2. IRC Proceedings: January 11th, 2015 – January 24th, 2015

    Many IRC logs



  3. Links 24/1/2015: Zenwalk Linux Reviewed, Netrunner 14.1 Released

    Links for the day



  4. The Latest 'Microsoft is Open Source' Propaganda a Parade of Lies

    Microsoft myth makers continue their assault on what is objectively true and try to tell the public that Microsoft is a friend of "Open Source"



  5. Apple -- Like Microsoft -- Not Interested in the Security of Its Operating Systems

    Apple neglected to patch known security flaws in Mac OS X for no less than three months and only did something about that vector of intrusion when the public found out about it



  6. As Battistelli Breaks the Rules and Topić Silences Staff, New European Parliament Petition for Tackling the EPO's Abuses is Needed

    The neglected (by EPO) Article 4a of the European Patent Convention (EPC) and the European Parliament petition/complaint against the EPO's crooked management



  7. Links 23/1/2015: Red Hat on IBM Power, Meizu Leaks With Ubuntu

    Links for the day



  8. Links 23/1/2015: Plasma 5.2, Manjaro 0.9-pre1

    Links for the day



  9. Microsoft is Dying Due to Free Software, Tries to Infect GNU/Linux With .NET and to Infect Moodle in Schools With Microsoft Office and OOXML Lock-in

    'Free' drugs (a proprietary software analogy) the new strategy of Microsoft in its latest battle against Free software, especially in schools where choice is a rarity (if not an impossibility), with the premeditated intention of forming dependency/addiction among young people



  10. Microsoft Symptoms of a Dying Company: More Boosters Depart, Back Doors Revealed, Microsoft's Outlook Cracked

    Bad news for Microsoft shortly before the marketing extravaganza served to cover much of it up



  11. The Collapse of European Patent Office Management Culminates With Resignations

    No blood is spilled, but even the management of the EPO is falling apart as the Director of Internal Communication is said to have just resigned



  12. New LCA Talk: Open Invention Network's Deb Nicholson on Software Patents and Patent Trolls

    Deb Nicholson's LCA talk is now publicly accessible



  13. Links 22/1/2015: GNU/Linux Sysadmin Opportunities, TraceFS Introduced

    Links for the day



  14. Links 21/1/2015: Andrew Tridgell, Torvalds Being Baited

    Links for the day



  15. Vesna Stilin Renews Her Fight for Justice in Željko Topić Case (EPO VP)

    Željko Topić's abuses continue to cloud the legitimacy of the European Patent Office, in which he is a Vice-President



  16. Failure of the EPO Can Derail the Trojan Horse of Software Patents and Patent Trolls

    Dazzled by his endless pursuit of infinite money and power, Battistelli pushes for expansion of patent scope (geographically too), but he won't have it without a challenge



  17. Links 20/1/2015: Linux 3.19 RC5, 30 Years of FSF

    Links for the day



  18. Translations of Member of the European Parliament Complaining About European Patent Office (EPO)

    French, German, Dutch, and English translations of the article from Dennis De Jong



  19. Microsoft, the Back Doors Company, is Gradually Dying and Trying to Embrace the Competition

    The world is leaving Microsoft's common carrier (Windows) behind, so Microsoft, which is shrinking, tries to conquer Free software and GNU/Linux



  20. Battistelli's Latest Propaganda War Tries to Convince EPO Staff That Željko Topić's Many Criminal Charges Don't Exist

    Battistelli's right-hand man, Željko Topić, is now facing real danger of prosecution and possibly arrest in his home country, so Battistelli rushes to defend this thug's reputation



  21. Links 18/1/2015: Sailfish OS RoadMap, ownCloud Turns 5

    Links for the day



  22. Strategy of Litigation With Patents Has Collapsed Since SCOTUS Ruling in Alice v. CLS Bank

    The latest figures from Lex Machina show a massive decrease (-18%) in patent litigation last month; lawyers look for ways to spin the data in their favour



  23. Patent Lawyers Can't Help Rewriting Alice v. CLS Bank History

    The league of patent lawyers -- people who profit at the expense of software producers -- keeps brainwashing the public about the patentability of software (both the rationale and the potential)



  24. Myths and Hype About Patents

    Distortion of history and fabricated reports about patents in the corporate media leave many people confused and ultimately unable to make rational judgment



  25. Large Corporations, Including Microsoft Allies, Call for Abolition of Software Patents

    The calls for ending all patents on software are getting louder and patents as a whole are de-emphasised as a business strategy



  26. Links 17/1/2015: Lennart Poettering in Headlines, Mageia 5 Beta 2

    Links for the day



  27. Links 16/1/2015: Chapeau 21, Tails 1.2.3

    Links for the day



  28. Links 15/1/2015: KDE Releases, Ubuntu Phone Delays

    Links for the day



  29. Links 15/1/2015: KDE Plasma 5.2 Beta, Elive 2.5.2 Beta

    Links for the day



  30. Google Has Eliminated Microsoft's Dominance in Operating Systems, Microsoft Resorts to Propaganda, Child Exploitation, and EEE

    As Linux becomes the dominant kernel at Windows' expense Microsoft pulls old tricks including media manipulation, AstroTurfing, co-opting schools (making Windows obligatory for future generations), and EEE (embrace, extend, and extinguish)


CoPilotCo

RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

CoPilotCo

Recent Posts