Bonum Certa Men Certa

Windows Botnets Go Out of Control, Obama Web Site Delivers Windows Malware

THERE ARE SO MANY MICROSOFT failure stories to share today that it's hard to decide where to start.

Sites Hijacked



Microsoft's security nightmares as of late [1, 2, 3, 4, 5, 6, 7] are where we begin by presenting the following report about a government site in Australia getting cracked and doing enough harm that it needed to be shut down.

Like you, I get masses of spam. I knew it wasn't from jobs.nsw.gov.au no matter how much it pretended to be. I deleted it figuring it was “just another” bit of junk mail, although I was surprised to find one purporting to be from the NSW Government job board; that was definitely a new one on me!

Had I thought about it deeper I might have considered this was no ordinary spam. This time there was a direct relationship between how the spammers got my e-mail address and the organisation they purported to represent.

It turns out the Department of Commerce has taken this whole incident very seriously indeed, and far more than common garden-variety spam would necessitate.

If you visit the site jobs.nsw.gov.au you will see it is inaccessible, and in fact, has been for a week. A message advises that the system is down for “system maintenance.”


The site is powered by Microsoft IIS.

Moving on a little, it turns out that Obama's Web site too is causing harm. Some pages in it are distributing Windows malware.

Web security firm Websense reports that malicious hackers have registered multiple bogus user accounts on My.BarackObama.com. The site allows legitimate punters to join groups, raise funds, or creates blogs. The griefers have established blogs with fake YouTube clips, ostensibly offering grumble flicks.


According to some new statistics, there is a sharp increase in distribution of Windows malware, with more malicious sites than one can practically keep track of:

AVG is seeing between 200,000 to 300,000 new Web sites per day hosting code that can in some cases result in a PC being infected with malware just by visiting the site, said Roger Thompson, AVG's chief research officer.


Zombies/Botnets Explode



Conficker is still running wild and it's draining resources along its path (human resources and Web resources).

The world's top virus hunters are watching every move made by the attacker in control of a nasty new Internet worm — referred to as "downadup" or "conficker."


The number of infected Windows PCs keeps growing fast.

A virulent computer virus has infected as many as 15 million computers around the world so far, according to various estimates.

The virus -- a self-replicating computer worm known as Downadup, Conficker or Kido -- spreads across computer networks using Microsoft Windows software which have not been patched or updated properly. Microsoft issued a patch that fixes the vulnerability the virus exploits last October.


This is also covered here.

Computer experts are preparing to respond to further virus outbreaks and security threats posed by the Windows worm, known as Conficker, Kido and Downadup, which has infected more than 15 million PCs worldwide.


Had Microsoft cared about security rather than premature announcements (vapourware) and irresponsible releases, the Internet would have been a better and safer place to travel.

"Our products just aren't engineered for security."

--Brian Valentine, Microsoft executive



Broken glass

Comments

Recent Techrights' Posts

As Prices Soar and Services Shut Down (Even YouTube Starts Demanding Money for the Original or a Tolerable Experience) It's Time to Explore the Real Alternatives
https://inv.nadeko.net is the most viable instance of Invidious these days
Justice Will Find Its Way at the End
We deserve an award, not SLAPP, for what we've done
March Already, Rumours of IBM Layoffs in Brazil
Red Hat might be impacted too
 
Getting Serial Sloppers to Knock the Habit of Plagiarism by LLM Slop
All in all, the fewer the slop objects, the better
Gemini Links 01/03/2025: Amends and GNU/Linux
Links for the day
Links 01/03/2025: Scam Altman's Latest Excuse, Google Price Hikes
Links for the day
Links 01/03/2025: Squashing Software Patents, USPTO Facing Additional Cuts
Links for the day
Links 01/03/2025: UNM Gopher and Getting One's Pages on gemini://
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, February 28, 2025
IRC logs for Friday, February 28, 2025
Links 28/02/2025: Mass Layoffs at Autodesk, Employee Burnout, and Measles in Texas
Links for the day
Gemini Links 28/02/2025: offpunk, Lagrange, and More
Links for the day
When the Business Goal is to Protect the Image of Criminals From the Mainstream Media or Free/Independent Press (at Any Cost)
What ever happened to the concept of "ethics" in this "legal" occupation?
Skype is Dead, Microsoft Shuts It Down in a Few Months (for Good)
Many billions down the drain
It Has Been Over a Year Since Takedown Demands From Brett Wilson LLP, Nothing Has Been Taken Down
It backfired on the Serial Defamer
Links 28/02/2025: Domestic Violence Fatalities, Escalations Again Near Taiwan
Links for the day
IBM is Trading Employees for Revenue Acquired by Buying Companies and Growing the Debt
IBM's financial plan is corporate bulimia
[Video] Full Video of Richard Stallman's Talk Earlier This Month in Italy (Nexa, Turin)
We have a collection of them
Gemini Links 28/02/2025: Spring, cgi and inetd, Gemini Protocol FAQ
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, February 27, 2025
IRC logs for Thursday, February 27, 2025
What the LLM Scrapers Are Doing to Tux Machines
So far today it looks like we'll have served about 1.5 million requests at midnight. That's more than 50,000 per hour or 1,000 per minute.
Netcraft's New Web Server Survey Shows Microsoft Down in Every Category
That Microsoft is still visible in
Slopwatch: Anti-Linux Garbage and Fake 'Articles' About GNU and Linux, Courtesy of Serial Sloppers and Slopfarms
Today there is a frustrating amount of FUD online that wasn't published by humans but instead generated by LLMs
Links 27/02/2025: Google Clown Computing Layoffs and Slack Goes Down as Usual
Links for the day
Links 27/02/2025: The Engagement Rehab and Another New Zine
Links for the day
Links 27/02/2025: Microsoft Trying Ads as Sales Fall, Preserving Data From Social Control Media a Real Problem
Links for the day
Hiding Crimes Against Women (i.e. Reputation Laundering) by Misusing Inapplicable Privacy Laws From Another Continent
As it turns out, "privacy" does not cover hiding illegal activities and if public information exists to prove these illegal activities, then it's perfectly OK to share it
Zurich CEO suicide, Martin Senn proximity to Adrian and Diana von Bidder-Senn, Debian
Reprinted with permission from Daniel Pocock
Debian, CentOS, RHEL source code demise now linked, accelerated after invalid trademark judgment
Reprinted with permission from Daniel Pocock
Civil Society Should Demand Removal of People Who Sought Removal of Richard Stallman
Perhaps it's noteworthy that the FSF is now being attacked (again)
RTO for You, But Not for Me: How IBM's Managers Try to Disguise Layoffs as "Resignations" or "Retirements"
What ever happened to corporate ethics?
Links 27/02/2025: Conflict Updates, Hacks Caught Red-Handed Misusing Licence to Exercise Law to Submit LLM Slop to Courts
Links for the day
Gemini Links 27/02/2025: Fuzzy Frontiers and New Arrivals at Geminispace
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, February 26, 2025
IRC logs for Wednesday, February 26, 2025