EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

08.10.10

Microsoft Leaves Windows XP SP2 Users Open to Attacks, ZeuS Exploits Windows Flaws, and 4Chan Becomes Unsafe to Windows Users

Posted in Apple, GNU/Linux, Microsoft, Security, Windows at 7:27 pm by Dr. Roy Schestowitz

4chan front page in 2009

Summary: Grouping of security news from this week

“Has anybody seen the news about Microsoft not supporting the link vulnerability patch in XP SP2?”

That question was asked by Chips B Malroy earlier today. He cited the following two posts:

i. Registry hack used by gamers allows security for Windows XP SP2

If you use Windows XP SP2, then by now you are well aware that it has come to its end of life. This means no security updates, no software updates, no support. However, an interesting blog post from F-Secure explains how to install security updates on the aging operating system, if a user is willing to assume the risk.

ii. Windows XP SP2: Hack Allows ‘Shortcut Patch’ To Be Installed

PC users who are still using Windows XP SP2, even after the service pack was retired on July 13 can still receive security updates thanks to a trick found by editing the registry.

Had Windows been Free software, no “hack” around the Registry would be needed.

At the moment, all versions of Windows are still open for attacker to exploit. The press doesn’t call out Windows when it reports on the ZeuS Trojan:

Security vendor M86 Security says it’s discovered that a U.K.-based bank has suffered almost $900,000 (675,000 Euros) in fraudulent bank-funds transfers due to the ZeuS Trojan malware that has been targeting the institution.

More here:

A banking Trojan attack has led to the fraudulent withdrawal of more than $1m from online banking accounts maintained with a UK bank since the start of July, according to security researchers.

Web-based malware based on the infamous Zeus cybercrime toolkit is being used to steal money via the unnamed bank’s online banking system. Researchers at the M86′s Security Labs came across the attack after discovering the botnet’s command & control centre, which is hosted in Moldova.

What about Microsoft and Windows? Here is another IDG article whose headline says “Malware Circulating on 4Chan Forums” (it does not say “Windows malware”).

The important point to take away from this is that HTA files are programs, just like EXEs and can do dangerous things.

Here is a funny one:

INSECURITY OUTFIT McAfee has decided it’s time to get tough on cybercrime.

We’re not sure how McAfee was tackling cybercrime before the publication of its report, “Security Takes the Offensive”. Whatever it was doing obviously wasn’t enough, given the malware threats out in the wilds of the Internet.

Security would be simplified if Windows was removed from this equation. Earlier today we posted several links to new articles that claim GNU/Linux/Android superiority over Apple when it comes to security. Apple — like Microsoft — is being negligent again.

Apple sits on a patch for a critical flaw

PEDDLER OF BROKEN DREAMS Apple has apparently come up with a patch for a critical flaw in the Iphone OS that gives a hacker so much control over the device that they might as well be Steve Jobs.

Just because this operating system is proprietary doesn’t mean it’s harder to decipher and thus more secure. Fast patching is key.

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

What Else is New


  1. Links 24/5/2013: Fedora ‘Pidora’, CIvil Rights Debated in the US

    Links for the day



  2. Bill Gates Still Getting Richer Through For-Profit Investments, Now Wants to Brainwash Children in Schools in Favour of His Investments

    Some of the latest strategies used by the world's richest man to protect his investments and amass yet more money, adding to an ever-growing wealth while pretending it's a charity



  3. Microsoft Entryism and Its Effects on Corporate and Public Policy

    An aspect of Microsoft culture that ought not be overlooked because of its profound effect on society (private and public)



  4. Red Hat Should Follow Google's and Twitter's Footsteps on Patents to Avoid Becoming the Next Novell

    Red Hat continues to ignore my plea to defang the software patents it is applying for, potentially making them weaponised like Novell's and Sun's patents (e.g. Java at Oracle) upon buyout or another major event



  5. CAFC Decision Still Overridden by Overzealous Patent Lawyers in the Press, The Guardian and Other Corporate Press (CBS and AFP Included) Still Guard the Establishment

    Analysis of a sceptical kind of corporate press coverage regarding software patents in the US; great examples of how Microsoft- and Gates-funded press outlets tend to get it all wrong on the facts, smearing digital freedom fighters



  6. Software Patents Debate Still Open in New Zealand and the US

    In spite of distraction attempts, the debate over software patents continues to stress that there is a real danger



  7. WebM is No Ogg, It is Not Freedom-Respecting Anymore, Even in Countries That Have No Software Patents

    Why Google needs to fix the licence of VP9, or simply stop pretending that it should be the only de facto standard for multimedia



  8. Microsoft Violates Google Licences

    The champion of 'IP' and licensing (extortion) is not much of a champion after all, based on new reports, not just a lot of old ones



  9. Skype Teaches Us That All Microsoft Software Should be Assumed Spyware Unless Proven Otherwise

    The broader implications of Microsoft adding spying 'features' to Skype



  10. Links 23/5/2013: Threat to Civil Rights in UK, KDE 4.11 LTS

    Links for the day



  11. Links 22/5/2013: Debian GNU/Hurd, New Go Language Release

    Links for the day



  12. The FRAND Apple-Microsoft Conspiracy Attempts to Destroy Android/Linux, Ban Imports

    How Microsoft and Apple are using patents in bulk (sometimes acquired in unison, e.g. from Novell and Nortel) to artificially lower market saturation of the Android operating system or drive costs up



  13. Gates Foundation: Buying Influence for Bill's Ego and Bill's Profit

    New examples of power being acquired and investments (i.e. for profit) being funnelled into the beneficiaries



  14. Bill Gates Enters Financial Centres With His Goons Becoming US Budget Chief, Top Bankers

    How Bill Gates' staff is entering positions of financial power, indirectly giving Gates power over US (national and international) finance



  15. IBM Ignores Small Companies' Interests, Denies Patent Scope is a Problem, Focusing on Its Own Problems (Trolls) Instead

    How David Kappos and IBM (his longtime employer) continue to ignore the obvious problem which kills small businesses and everyone is complaining about



  16. The New York Times Publishes Factually-Flawed Patent Propaganda Benefiting Microsoft and Apple

    Eamonn Fingleton is rewriting history in the US' top newspaper, insinuating that patents contributed to the rise of software duopolists



  17. Software Patents Eligibility Likely to be Decided by SCOTUS

    Analyses suggest that an escalation by appeal to SCOTUS is likely to be the next stage in 'Bilski 2.0'



  18. Does Bill Gates Try to Flush GNU/Linux Down the Toilet in Kerala?

    Renting Microsoft software rather than using Free (as in freedom, or libre) software?



  19. Links 21/5/2013: Handbrake Turns 0.9.9, NetBSD 6.1

    Links for the day



  20. Links 20/5/2013: First Salifish Smartphone, Mageia 3 Released

    Links for the day



  21. Microsoft Corruption (Illegal Tenders) Stopped by European Court

    Microsoft cannot bypass public tenders, based on a ruling from a court of law in Europe



  22. Not Satire: Microsoft Wants to Show the World How Security is Done

    Software security 'standard' to be led by the company which made insecurity an acceptable engineering practice?



  23. Microsoft is Struggling to Maintain Industry 'Standards'

    With Microsoft's common carrier and browser share down considerably Microsoft finds itself increasingly irrelevant and it tries subversive means of making another comeback



  24. Microsoft Entryism and Bribery Get the Microsoft Way Implemented

    A recollection of very dirty tactics from Microsoft, which uses money to oppress, overthrow, and even hijack its opposition



  25. Patent Policy Laundering in the European Union and New Zealand

    How the so-called 'free' trade agreements help spread patent policy which favours software patents



  26. Ongoing Focus on Patent Litigation and Patent Trolls Reduces Focus on Software Patents

    The problem with increased focus on the players that use software patents litigiously and the litigation itself



  27. Andrew Y. Schroeder Shows That Patent Lawyers Are Sociopaths

    Bully and law misuser is trying to get his way with foul language, intimidation, and sheer lack of professionalism



  28. IBM-backed Book on 'Open Innovation'

    OpenForum Europe (OFE), which helps IBM's turf wars in Europe, releases a new book filled with its talking point



  29. Joseph E. Stiglitz Criticises the Patent System

    More critical words about the patent system and the way it is harming lives



  30. Senator Schumer Should Focus on Software Patents, Leaving Patent Trolls (Side Effect) Aside

    Reform in the USPTO and the US courts should focus on patent scope and not patent holders


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts