Eye on Security: Microsoft Windows Emergency Patch, Botnets Grab Data, Malware Scam Analysis
- Dr. Roy Schestowitz
- 2010-08-06 12:12:28 UTC
- Modified: 2010-08-06 12:12:28 UTC
Summary: An update on problems Windows users may be experiencing
●
Microsoft rushes out emergency fix for critical Windows bug (
more about this emergency)
Microsoft on Monday rushed out an emergency patch for a critical vulnerability that criminals are exploiting to install malware on all supported versions of the Windows operating system.
●
Botnet with 60GB of stolen data cracked wide open
Most botnet command-and-control channels run on compromised webservers or web-hosting services designed for criminals, making it possible to dismantle the network by taking down the central server. Mumba, by contrast, makes use of fast-flux technology, in which the operations are carried out on thousands of compromised PCs. That allows the IP address and host machine to change every few minutes, a measure that frequently foils takedown attempts by researchers and law enforcement.
●
Anatomy Of An Attempted Malware Scam
The display media segment is the newest target of malvertising, the latest trend in online criminal methodology. The problem has escalated in recent months and despite many suppliers' best efforts, it continues to grow. The culprits behind many of these attacks are based in foreign states leaving little course to take action. While the best defense against malvertising is to prevent it from happening in the first place, this has proven to be a challenge for even the most astute publishers, networks and the like.
We were recently the targets of one such attempt, and while it certainly wasn't the first "fake agency" we've been besieged by (and that we've successfully stopped), it is one of the most organized efforts we've encountered so far. Below we've outlined the approach that was used and the findings of our investigation as an FYI to others who may be on the target list.
Recent Techrights' Posts
- Sloppy Reporting About Slop, or How The Register MS Lowers Its Standards
- Maybe the management isn't even aware of this
- IBM's Strategy: Cull 'Expensive' Workers, Replace Them With Cheaper Ones
- So far we saw not even one rebuttal or challenge to the claim of Red Hat layoffs scheduled for tomorrow
- The Goal of Coopetition Assumes You're Friends
- it will never work with Microsoft
- Seductive Mirage or Allure of Complex, Proprietary Coffee Machines (or Similar White Elephants)
- Software is a lot like those things
- Hate Mail From Anonymous Cowards
- if this persists, we'll need to escalate
-
- Sometimes Newer is Worse
- We generally need to reject this dumb notion that "old" means bad
- The Code Used to Make Techrights Fits on a Seventh of a Floppy Disk (or 100KB When Compressed)
- For the sake of comparison I've just downloaded the latest version of WordPress. The ZIP file is 27.2MB in size, or ~27,200KB.
- What They Tell Young Programmers
- Coding in 2025
- Simpler is Better When Simple is Enough
- Over-complicating things to "sell" new versions is so 1990s
- Links 10/08/2025: From Social Control Media to Prison, New Examples of Windows TCO
- Links for the day
- If You Attack Somebody Too Much You Legitimise and Strengthen That Somebody
- at the end those attacks add up to a "martyr" status
- The Man Who Helped Microsoft Kill Linux is Trying to Delay Our Lawsuits Against Him
- By conservative estimates, and based on court documents submitted by them, they're prepared to spend over a million dollars on lawyers, fighting against me and my wife
- Gemini Links 10/08/2025: Gen Con 2025 and Framework Laptop
- Links for the day
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Saturday, August 09, 2025
- IRC logs for Saturday, August 09, 2025
- The Register MS (Microsoft) or The Register AI (Slop)?
- What a slopfest!
- Is Red Hat About to Give the Boot to GNOME People Who Helped Microsoft 'Secure' (Monopolised) Boot?
- It was always a dumb idea to play along with Microsoft's hardware mischief
- Sales of Windows on PCs (Windows Licences) Go Down
- Microsoft has a big problem in its hands
- The Hype That Microsoft and The Register MS (Among Others) Promote Helps Stage DDoS Attacks on Free Software Sites
- Microsoft is, to put it bluntly, pure evil
- Links 09/08/2025: Putin Allegedly to Visit Alaska (Which He Deems Part of Russia), Mike Tyson Sued for Copyright Infringement
- Links for the day
- Slopwatch: Linux Journal, LinuxSecurity, and Google News With Its Slopfarms of Choice
- SEO spam, made with LLMs
- Follow the Money: The Register MS Gets Paid to Promote "Hey Hi" Ponzi Scheme/Hype, Some Fake 'Articles' Might Be Composed by LLMs Already
- paid to promote slop
- Gemini Links 09/08/2025: Rethinking Aliases and Posting on Gopher vs. the Web
- Links for the day
- Links 09/08/2025: Apollo 13 Astronaut Jim Lovell Dies, Slop Future Bleak
- Links for the day
- After Shutting Down Studios, Divisions, Applications (e.g. Skype) Microsoft is Also Shutting Down 'Apps'
- Cuts all around as layoffs persist this month, Microsoft tries to get many people to resign, and debt skyrockets
- Most of Geminispace Can Probably Fit on a CD-ROM or a DVD (the Textual Part)
- If one excludes very large capsules and ones that contain non-textual contenty
- Eventually UEFI 'Secure Boot' Will be Dropped (Users Will Demand Its Removal and Boycott Its Pushers)
- we expect OEMs will just listen to users
- The Register MS: We Know Slop is a Bubble and Mindless Hype, But We Get Paid to Participate
- Call out the culprits
- There Are Probably Over a Million Pages in Geminispace
- there are two many limitations which merit a mention when it comes to assessing magnitude
- Informal Open Letter to the Lawyer of the Microsofters (on Who's Funding the SLAPPs Against Techrights)
- Whenever I ask about the funding they try to change the subject and act all aggressive
- Microsoft Lunduke is Just Provoking People for Provocation's Sake
- Be forewarned and remember where this guy came from: Microsoft
- Besieged by Plagiarists Who Play With LLMs and Image Fusions
- We really need to exercise or use our collective voice to oppose Serial Sloppers
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Friday, August 08, 2025
- IRC logs for Friday, August 08, 2025
- Gemini Links 09/08/2025: Water Painting and Political Violence
- Links for the day
- Slopwatch: LLM Sloppers in Google News, LinuxSecurity, and More
- they also perpetuate some falsehoods as the LLMs lack any comprehension
- Links 08/08/2025: China King of Plastics and US Dictator Plans to Meet Russian Dictator
- Links for the day
- Gemini Links 08/08/2025: Cracking a Family Member's Password and Overdose of Slop
- Links for the day
- Red Hat's Latest Talent Hunt, Day Ahead of Mass Layoffs, is Yet Another Microsoft Executive
- Red Hat will apparently commence mass layoffs early this coming Monday
- Links 08/08/2025: "Quit Facebook" and High Cost of Microsoft/Windows Shown Again ("BlackSuit")
- Links for the day
- Good Morning, Readers of The Register MS
- Things The Register MS could (but does not) cover this morning
- Why Gemini Protocol Has a Bright Future
- Maybe Gemini Protocol's promise becomes more appealing as the Web turns to slop and bloat
- It's a Lot Easier to Participate in the Unethical System Than to Oppose Injustices in It
- Going after powerful and high-budget interests is never easy
- Microsofters Filed Two SLAPPs Against Us, Now They Cannot Keep Up With Judges' Orders
- For over 4 months already their facilitator in London has been under investigation by British authorities because of what's being done to my wife and I
- Censorship Regarding Red Hat Layoffs
- Talk about this? They'd rather not.
- Struggling to Cut Costs, Microsoft Continues Shutting Down and Cancelling Stuff This Month
- There are August layoffs at Microsoft
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Thursday, August 07, 2025
- IRC logs for Thursday, August 07, 2025
- Fake 'Linux' Articles, Written by Bots to Take Traffic Away From Real Articles
- LLM slop helps replace information with junk or misinformation
- When Google's Googlebombing of "Gemini" Was Not Enough; They Now Also Googlebomb "Gemini Space"?
- We know GAFAM not only worries about Gemini Protocol but also attempts to 'infiltrate' Geminispace
- The Register MS Promotes Microsoft Slop, Assumes All Readers Use Microsoft Windows
- Microsoft really dominates the site
- Gemini Links 08/08/2025: KDE/Qt Development and What's Missing From "Retro"
- Links for the day