EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS


Microsoft Leaves Windows XP SP2 Users Open to Attacks, ZeuS Exploits Windows Flaws, and 4Chan Becomes Unsafe to Windows Users

Posted in Apple, GNU/Linux, Microsoft, Security, Windows at 7:27 pm by Dr. Roy Schestowitz

4chan front page in 2009

Summary: Grouping of security news from this week

“Has anybody seen the news about Microsoft not supporting the link vulnerability patch in XP SP2?”

That question was asked by Chips B Malroy earlier today. He cited the following two posts:

i. Registry hack used by gamers allows security for Windows XP SP2

If you use Windows XP SP2, then by now you are well aware that it has come to its end of life. This means no security updates, no software updates, no support. However, an interesting blog post from F-Secure explains how to install security updates on the aging operating system, if a user is willing to assume the risk.

ii. Windows XP SP2: Hack Allows ‘Shortcut Patch’ To Be Installed

PC users who are still using Windows XP SP2, even after the service pack was retired on July 13 can still receive security updates thanks to a trick found by editing the registry.

Had Windows been Free software, no “hack” around the Registry would be needed.

At the moment, all versions of Windows are still open for attacker to exploit. The press doesn’t call out Windows when it reports on the ZeuS Trojan:

Security vendor M86 Security says it’s discovered that a U.K.-based bank has suffered almost $900,000 (675,000 Euros) in fraudulent bank-funds transfers due to the ZeuS Trojan malware that has been targeting the institution.

More here:

A banking Trojan attack has led to the fraudulent withdrawal of more than $1m from online banking accounts maintained with a UK bank since the start of July, according to security researchers.

Web-based malware based on the infamous Zeus cybercrime toolkit is being used to steal money via the unnamed bank’s online banking system. Researchers at the M86′s Security Labs came across the attack after discovering the botnet’s command & control centre, which is hosted in Moldova.

What about Microsoft and Windows? Here is another IDG article whose headline says “Malware Circulating on 4Chan Forums” (it does not say “Windows malware”).

The important point to take away from this is that HTA files are programs, just like EXEs and can do dangerous things.

Here is a funny one:

INSECURITY OUTFIT McAfee has decided it’s time to get tough on cybercrime.

We’re not sure how McAfee was tackling cybercrime before the publication of its report, “Security Takes the Offensive”. Whatever it was doing obviously wasn’t enough, given the malware threats out in the wilds of the Internet.

Security would be simplified if Windows was removed from this equation. Earlier today we posted several links to new articles that claim GNU/Linux/Android superiority over Apple when it comes to security. Apple — like Microsoft — is being negligent again.

Apple sits on a patch for a critical flaw

PEDDLER OF BROKEN DREAMS Apple has apparently come up with a patch for a critical flaw in the Iphone OS that gives a hacker so much control over the device that they might as well be Steve Jobs.

Just because this operating system is proprietary doesn’t mean it’s harder to decipher and thus more secure. Fast patching is key.

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

What Else is New

  1. Puff Pieces of the EPO-IPO (EPO+EUIPO) Have Begun to Appear Amid New Evidence of Brain Drain, Lowered Standards

    The grim vision of the EPO which is losing all its talent (over time), becomes more like a production line (quality does not matter), and produces propaganda for "media positioning" (or "placements") -- all under the guise of 'studies'

  2. Leaked: Minutes From the Administrative Council of the EPO Regarding the 'Reform' (Exile) of the Boards of Appeal

    Details of the relatively secret proceedings back in June (belatedly released only a short while ago), carefully abbreviated to demonstrate which delegations helped Battistelli crush the Boards of Appeal and which ones insisted on maintaining the status quo, as per the EPC

  3. No Promising Future For the EPO Under Battistelli (If Any Future At All)

    Pessimism becomes realism at the European Patent Office as units are being torn apart, patent quality discarded, "unified" patent courts dreamed of (more patent lawsuits, higher damages), and EUIPO (EU-associated, unlike Eponia) gets closer to the EPO

  4. Leaked Minutes From the EPO Reveal That Battistelli is Detached From Reality and Blames Everything on “Union Officials”

    Minutes of the Administrative Council's meeting reveal some truly bizarre rants from Battistelli, who simply refuses to accept that the European Patent Office is burning (without a future direction, only burnout and brain drain) under his poor and abusive leadership

  5. Tata/TCS is Still Pushing for Software Patents in India

    The obnoxious company that is promoting Microsoft and software patents in a country that needs neither makes the headlines again (Financial Express)

  6. Links 25/10/2016: Rackspace's Praise of FOSS, Chain Chooses the GPL(v3)

    Links for the day

  7. Links 24/10/2016: Linux 4.9 RC2

    Links for the day

  8. Battistelli Plans to Expand the Social [sic] 'Study' (Then 'Conference') Propaganda Until Next Month, Under the 'Workshop' Umbrella

    Milking his shameless propaganda (paid-for 'studies'), Battistelli wants to rewrite the record by all means possible, then pretend that EPO staff participates in it

  9. EPO and EUIPO Join Hands to Release Propaganda (for European Media to Parrot) Some Time Tomorrow

    EPO and EUIPO in collaboration for the promotion of the notion that they are both necessary (and reinforced speculations about growing overlap between them)

  10. UPC Preparatory Committee Puts the Brakes on UPC Amid Brexit and Growing Uncertainty

    The Unified Patent Court (UPC) preparatory committee recognises that the UPC isn't going anywhere (any time soon) and false job advertisements -- or advertisements for jobs that will never exist -- are withdrawn

  11. Updates Regarding EPO and BoAC: Unrest and Injustice Carry on

    Some of the latest information which is publicly and privately available to us, in particular regarding the case of a suspended judge which represents unprecedented erosion of the appeal boards' independence (and hence lack of justice in the Organisation)

  12. EPO and the “Iberian Connection”: Patricia García-Escudero Márquez - Battistelli's Pet Chinchilla on the Boards of Appeal Committee?

    Why the Boards of Appeal Committee has begun showing prominent signs that it is anything but independent and capable of standing up to Battistelli (or his circle at the Office, which includes the “Iberian Connection")

  13. Links 23/10/2016: Alcatel's New Android Smartphones, Another Honorary Doctorate for Stallman

    Links for the day

  14. Open Letter Exposing the Farce Which Was Battistelli's 'Social Conference' Coinciding With Further (New) Attacks on EPO Staff Representatives

    A detailed letter reveals legitimate concerns expressed by staff representatives at the EPO ahead of the so-called Social Conference, in which we have highlighted severe factual flaws

  15. Translation of Latest Rant From French MP Philip Cordery About Benoît Battistelli's Abuses at the EPO

    Philip Cordery crosses horns with Benoît Battistelli, who has become a source of embarrassment for France with his autocratic tendencies and misguided policies that rapidly ruin the European Patent Office (EPO)

  16. Battistelli-Commissioned PwC ‘Study’: Leaked Document Shows PwC's Dishonesty and Misrepresentation of EPO Staff

    An in-depth analysis (but not comprehensive, just preliminary) of the so-called 'study' from PwC, which basically did what it was paid for (pay to say)

  17. Links 22/10/2016: Deus Ex for GNU/Linux, Global DDoS (DNS)

    Links for the day

  18. Battistelli-Commissioned PwC ‘Study’: Survey Comparison Shows Serious Deterioration and Efforts by PwC to Disguise the Truth

    The latest output from PwC turns out to be even worse than initially thought, indicating that not only did it find a degradation in the EPO but also attempted to hide/obscure it

  19. EPO Teaser - The "Iberian Connection" - Some Photos of García-Escudero and His Royal/Government Connections

    A look at the undeniably close connections between Mr. García-Escudero and the most powerful people in Spain

  20. Disruption to Site's Service

    A technical note about why Techrights has not been publishing many articles recently

  21. Links 21/10/2016: MPV 0.21, Mad Max for GNU/Linux

    Links for the day

  22. EPO Caricature: Battistelli's High Five

    Another cartoon about the sad state of the EPO

  23. Battistelli Ruins Not Only the EPO But Also the Whole of Europe By Ushering in Software Patents That Patent Trolls Love So Much

    Battistelli's bad leadership at the EPO threatens to bring to Europe all the ills and menaces of the patent system in the United States

  24. EPO Spokesman Lies to IP Watch in Order to Save Face and Save the King (Battistelli)

    Rewriting history (revisionism) regarding Battistelli and what was demanded amidst abusive behaviour from him

  25. Unitary Patent (UPC) is Dead, But 'Managing IP' and Selfish Patent Law Firms Still Try to Resurrect It

    The latest attempts to shore up the Unitary (or Unified) Patent Court and who's behind it other than the usual suspects

  26. Links 20/10/2016: Linux 4.10 Preview, ONF and ON.Labs to Merge

    Links for the day

  27. Battistelli-Commissioned PwC 'Study': The Raw Outcome Shows Distortion of the Facts at the EPO's Notorious 'Social Conference'

    Results of the Staff Survey carried out by PwC, in order to provide some propaganda for Battistelli's expensive Social Conference

  28. Addendum: EPO's Alberto Casado Cerviño, WIPO's Francis Gurry, and EUIPO's Archambeau

    Photos taken as part of an IP event which took place in Riga (Latvia) in March 2015

  29. Worrisome Connections Between EPO VP2 Alberto Casado Cerviño and Patricia García-Escudero Márquez

    Exploring the potential conflicts of interests implicating the EPO's Boards of Appeal Committee

  30. Site's Infrastructure Under Attack and Upgrades Ahead of Major New Publications

    Protections for the Web site have been improved and capacity increased in order to avoid or at least prepare for another week of abusive/spam traffic


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time


Recent Posts