EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

11.27.10

Windows Kernel Vulnerability for Thanksgiving, Insecurity Used for Surveillance Again

Posted in Microsoft, Security, Windows at 5:56 am by Dr. Roy Schestowitz

Oppression and proprietary software are a pair

Guard with machine gun

Summary: Another major security problem in Windows, new destinations for Stuxnet, and new excuses for tracking one’s Web trails

IT IS not uncommon for Microsoft to leave systems administrators rather restless over the holidays, most typically over Christmas. Users too are left paranoid. This holiday season (US in particular) was no exception as a new Windows kernel vulnerability bypasses UAC, says Slashdot, citing Sophos:

“A new vulnerability in the Windows kernel was disclosed Wednesday that could allow malware to attain administrative privileges by bypassing User Account Control (UAC). Combined with the unpatched Internet Explorer vulnerability in the wild this could be a very bad omen for Windows users.”

From the original source rather than Slashdot‘s summary:

A new zero-day exploit in Microsoft Windows was disclosed today. The exploit allows an application to elevate privilege to “system,” and in Vista and Windows 7 also bypass User Account Control (UAC). The flaw was posted briefly on a programming education site and has since been removed.

According to another report, Stuxnet is still out there and now it is sold on the black market.

According to a report from Sky News, the Stuxnet worm has already been traded on the black market. The report does not clarify whether this refers to the source code or to binary samples. British security specialists now fear that terrorists could use the worm to attack critical infrastructure. The report quotes an IT security consultant to the UK government as claiming, “You could shut down power stations, you could shut down the transport network across the United Kingdom”.

We wrote about Stuxnet many times before and it is interesting because some say it was engineered in order to spy on or to sabotage nuclear facilities in so-called ‘rogue’ nations. See for example:

  1. Ralph Langner Says Windows Malware Possibly Designed to Derail Iran’s Nuclear Programme
  2. Windows Viruses Can be Politically Motivated Sometimes
  3. Who Needs Windows Back Doors When It’s So Insecure?
  4. Windows Insecurity Becomes a Political Issue
  5. Windows, Stuxnet, and Public Stoning
  6. Stuxnet Grows Beyond Siemens-Windows Infections
  7. Has BP Already Abandoned Windows?
  8. Reports: Apple to Charge for (Security) Updates
  9. Windows Viruses Can be Politically Motivated Sometimes
  10. New Flaw in Windows Facilitates More DDOS Attacks
  11. Siemens is Bad for Industry, Partly Due to Microsoft
  12. Microsoft Security Issues in The British Press, Vista and Vista 7 No Panacea
  13. Microsoft’s Negligence in Patching (Worst Amongst All Companies) to Blame for Stuxnet
  14. Microsoft Software: a Darwin Test for Incompetence
  15. Bad September for Microsoft Security, Symantec Buyout Rumours
  16. Microsoft Claims Credit for Failing in Security
  17. Many Windows Servers Being Abandoned; Minnesota Goes the Opposite Direction by Giving Microsoft Its Data
  18. Windows Users Still Under Attack From Stuxnet, Halo, and Zeus
  19. Security Propaganda From Microsoft: Villains Become Heroes
  20. Security Problems in iOS and Windows
  21. Eye on Security: BBC Propaganda, Rootkits, and Stuxnet in Iran’s Nuclear Facilities
  22. Eye on Security: ClamAV Says Windows is a Virus, Microsoft Compromises Mac OS X, and Stuxnet Runs Wild

A few days ago we mentioned MSBBC articles which clearly neglected to mention Windows in stories that were about Windows-exclusive problems.

“ANOTHER Windows only story from the #BBC not mentioning Windows,” wrote Gordon, “they send people to jail for not paying for this s**t,” he added” (the MSBBC is funded by British taxpayers).

Gordon is right because Windows malware is the central issue discussed in the article (although it avoids mentioning Microsoft or Windows). For example:

He was caught installing password-capturing software by computer staff examining network problems.

This is a form of surveillance by a criminal. But we previously explained how surveillance uses security as a pretext (sometimes targeted marketing is the preferred excuse) and this includes security problems in software. On that issue, Gordon shares another MSBBC article . It talks about “virus alert system” (not mentioning Windows of course) and Gordon says one “gotta love the ISPs who spy on their customers connections #TalkTalk… this excuse is “malware protection” [still Windows of course]“:

Talk Talk is launching trials of a controversial anti-malware system following intervention by the Information Commissioner (ICO).

The Virus Alert system keeps an eye on the websites customers visit to stop them accidentally going to places riddled with viruses.

More here in The Inquirer:

BROADBAND PROVIDER Talk Talk has announced it will continue rolling out a traffic monitoring system that it claims will protect its customers.

The opt-in Virus Alerts Service (VAS) was recently likened to the now banned traffic snuffling operation Phorm by the UK Information Commissioner’s Office. It claims to track URLs visited by Talk Talk customers and warn them if a website harbours malware.

The problem here is proprietary software and also this illusion of needing government help (with Phorm that’s harboured by it) to simply navigate through some Web pages.

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

What Else is New


  1. Links 29/7/2016: More Microsoft Problems and Layoffs, Bodhi Linux 4.0.0 Alpha Released

    Links for the day



  2. Links 28/7/2016: CORD as Linux Foundation Project, Wine 1.9.15 Released

    Links for the day



  3. EPO Loses More Than 80% of Cases at the International Labour Organisation (ILO)

    The International Labour Organisation (or Organization) helps show just to what degree the European Patent Office (EPO) violates the rights of workers



  4. To Understand What Battistelli Has Turned the EPO Into Look at Turkey and China

    Battistelli and his notorious Vice-President from SIPO (Croatia) turn the European Patent Office, once the pride of Europe, into a human rights cesspool with SIPO (China) connections



  5. Patent Lawyers Move Closer to Battistelli's Rubber-stamping Office While the Appeal Boards Pushed Away as Collective Punishment Which Masks Decline in Patent Quality

    Urgently sending appeal boards away and urgently granting applicants patents without proper examination will be Battistelli's sorrow legacy at the European Patent Office



  6. Software Patents a Dying Breed, But Patent Lawyers in Denial Over it and Notorious Judge Rodney Gilstrap Ignores Alice (Supreme Court)

    A look at what law and practice are saying about software patents, contrasted or contradicted by the patent industry and trolls-friendly courts (which make business out of or together with patent aggressors)



  7. CAFC Meddling in PTAB Affairs; Unified Patents Fights a Good Fight by Invalidating Software Patents

    A look at how the AIA's Patent Trial and Appeal Board is invalidating software patents post-Alice, with or without involvement of patent courts



  8. Early Certainty That Benoît Battistelli is Dangerously Clueless and a Major Risk to the EPO

    The chaos which Team Battistelli is assured to deliver if it doesn't treat scientists like scientists, instead viewing them as a production line with rubber-stamping duties



  9. OIN Makes Claims About “Open Source Innovation”, But It Produces Nothing and Protects Virtually Nobody

    The Open Invention Network (OIN) reports growth, but in practical terms it does little or nothing to help developers of Free/Open Source software



  10. Links 27/7/2016: New CrossOver, Blackmagic for GNU/Linux

    Links for the day



  11. The Death of Software Patents and Microsoft's Coup Against Yahoo! Made the Company Worthless

    A look at what happens to companies whose value is a house of software patents rather than code and a broad base of users/customers



  12. Munich Attack Mentioned by EPO But Not Ansbach

    The EPO does the usual right-wing thing (exploiting disaster/emergency for domestic crackdowns), but some bemoan the omission of the explosion at Ansbach (also in Germany)



  13. Kluwer Thinks People Are Clueless About the Unitary Patent System and Pretends It's Business as Usual

    Flogging the dead UPC horse at times of great uncertainty (enough to bring the UPC to a standstill)



  14. Almost Everything That the Government Accountability Office Says is Applicable to the EPO

    The Government Accountability Office in the United States produces reports which can serve as a timely warning sign to the European Patent Office, where patent quality is rapidly declining in order to meet 'production' goals



  15. Microsoft Says It Loves Linux, But Its Anti-Linux Patent Trolls Are Still Around and Active

    Highlighting just two of the many entities that Microsoft (and partners) use in order to induce additional costs on Free (as in freedom) software



  16. Links 26/7/2016: Microsoft Growing Desperate, Linux 4.8 Visions

    Links for the day



  17. Links 25/7/2016: Linux 4.7 Final, PostgreSQL 9.6 Beta 3

    Links for the day



  18. Leaked: Boards of Appeal Face 'Exile' or 'Extradition' in Haar After Standing up to Battistelli

    A look at some of the latest moves at the European Patent Office (EPO), following Battistelli's successful coup d’état which brought the EPO into a perpetual state of emergency that perpetuates Battistelli's totalitarian powers



  19. The US Government Accountability Office (GAO) Comes Across as Against Software Patents, Relates to the EPO as Well

    Some analysis of the input from the Government Accountability Office (GAO) with focus on the EPO and software patents



  20. In the US, Patent Trolls Engage in Patent Wars and Shakedowns, Whereas in China/Korea Large Android OEMs Sue One Another

    Highlighting some of the differences between the US patent system and other patent systems



  21. Links 24/7/2016: Elive 2.7.1 Beta, New Flatpaks and Snaps

    Links for the day



  22. Links 23/7/2016: Leo Laporte on GNU/Linux, Dolphin Emulator’s Vulkan Completion

    Links for the day



  23. Links 22/7/2016: Wine 1.9.15, KaOS 2016.07 ISO

    Links for the day



  24. Haar Mentioned as Likely Site of Appeal Boards as Their Eradication or Marginalisation Envisioned by UPC Proponent Benoît Battistelli

    Not only the Staff Union of the European Patent Office (SUEPO) is under severe attack and possibly in mortal danger; the increasingly understaffed Boards of Appeal too are coming under attack and may (according to rumours) be sent to Haar, a good distance away from Munich and the airport (half an hour drive), not to mention lack of facilities for visitors from overseas



  25. EPO Attaché Albert Keyack Viewed as Somewhat of a Mole, Reporting From the US Embassy in Brazil Until Shortly Before the Temer Coup

    Public responses to the role played by Albert Keyack on behalf of the United States inside the European [sic] Patent Office



  26. EPO Insiders Explain Why the EPO's Examination Quality Rapidly Declines and Will Get Even Worse Because of Willy Minnoye

    Public comments from anonymous insiders serve to highlight a growing crisis inside the European Patent Office (EPO), where experienced/senior examiners are walking away and leaving an irreplaceable bunch of seats (due to high experience demands)



  27. Patents Roundup: BlackBerry, Huawei, PTAB, GAO, Aggressive Universities With Patents, and Software Patents in Europe

    Various bits and pieces of news regarding patents and their fast-changing nature in the United States nowadays



  28. Glimpse at Patent Systems Across the World: Better Quality Control at the USPTO Post-America Invents Act (2011), Unlike the EPO Post-Battistelli (2010)

    While the EPO reportedly strives to eliminate pendency and appeal windows altogether (rubberstamping being optimal performance as per the yardstick du jour), the USPTO introduces changes that would strengthen the system and shield innovation, not protect the business model of serial litigants



  29. Blockstream Has No Patents, But Pledges Not to Sue Using Patents

    Blockstream says that it comes in peace when it comes to software patents, which triggers speculations about coming Blockchain patent wars



  30. Links 21/7/2016: Ubuntu 16.04.1 LTS, Linux Mint 18 “Sarah” Xfce Beta

    Links for the day


CoPilotCo

RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

CoPilotCo

Recent Posts