Bonum Certa Men Certa

All Versions of Windows Vulnerable, Under Attack, So Microsoft Gets Botnets

Water



Summary: A US court gives Microsoft botnets-operating domains after Windows failed to stay in the users' hands (due to faulty design of Windows, lack of disclosure, and lack of urgent patches)

DUE TO Microsoft's insistence on silent patching, it is impossible to know just how many flaws in Windows require fixing (Microsoft is ranked worst for patching). Microsoft says that 13 more are coming, but the real number might be far higher because the company patches without disclosing (for secrecy/vanity purposes).



According to the company’s advance notification for this month’s Patch Tuesday, there will be a total of 9 bulletins (four rated critical) addressing flaws in all versions of Windows, including Windows 7 and Windows Server 2008.


Yes, the 'legendary' Vista 7 too is a block of Swiss cheese. Is anyone surprised? Now that Windows XP is being pulled (SJVN gave some dates and there is corroboration)), some of the world is left to rely on some 'newer' versions of Windows which are not necessarily more secure.

“[W]hen nobody is using Windows, there will be no botnets”
      --Eben Moglen
Professor Eben Moglen said quite recently that "when nobody is using Windows, there will be no botnets" (watch the video where he has even harsher words for Windows).

How about this new report from Ryan Naraine? All versions of Windows appear to be affected by a new worm and OpenBytes says that "victims include Disney, Nasa AIG and others," at least based on the sources Tim read.

Windows is reported to be yet again under attack and as usual it is the end-user who suffers. The BBC is reporting that a worm, spread by unsuspecting souls opening a PDF attached to an email, see’s their Outlook address book hijacked with the worm sending itself out to everyone contained therein.


Those E-mails are sent through botnets, which are of course zombie PCs running Windows. It's a brute force- and remote access-reliant cyber crime. Symantec is concerned:

A fast-moving email worm that began spreading on Thursday has been able to affect hundreds of thousands of computers worldwide, anti-virus provider Symantec warned.

The email arrives with the subject “Here you have.” An executable screensaver that's disguised as a PDF document then tries to send the same message to everyone listed in the recipient's address book. The .scr file is a variation of the W32.Imsolk.A@mm worm Symantec discovered last month.


Watch Microsoft responding. It "Acquired its Own Botnet," said Pogson, pointing to this new report. [via]

CONTROL OVER 275 DOMAINS that are used by operators of the malware botnet Waledac has been given to Microsoft by a US court.

Microsoft can now shut down the sites and the company does not expect an appeal against the judgment. It said that the botnet's operators have objected to the move in other ways, such as launching a denial-of-service attack on its legal team.


This is becoming an embarrassment. Microsoft is getting possession of botnets, which are still being created by the hundreds of millions (in terms of node count), so it's really just a futile attempt to correct the uncorrectable (unless Windows gets abandoned by everyone).

Recent Techrights' Posts

The Myth of an Aging (or Dying) GNU/Linux Leadership
Self-fulfilling prophecies as a tactic?
There's Nothing "Funny" About Attacking Free Speech and Software Freedom
persistent focus on the principal issues is very important
GNU/Linux Adoption in Africa, a Passageway Towards Freedom From Neo-Colonialism
Digi(tal)-Colonialism and/or Techolonialism are a thing. Can Africa flee the trap?
 
Shooting the Messenger Using Bribes and Secrecy Bonds
We seem to live in a world where accountability for the rich and well-connected barely exists anymore
Links 06/12/2023: Many More December Layoffs
Links for the day
IRC Proceedings: Tuesday, December 05, 2023
IRC logs for Tuesday, December 05, 2023
PipeWire 1.0: Linux audio comes of age
Once upon a time, serious audio users like musicians and audio engineers had real trouble with Linux
This is How 'Linux' Foundation Presents Linux to the World
Right now it even picks Windows over Linux in some cases
Links 05/12/2023: Microsoft's Chatbot as Health Hazard
Links for the day
Professor Eben Moglen Explained How Software Patent Threats Had Changed Around 2014 (Alice Case) and What Would Happen Till 2025
clip aged reasonably well
CNN Contributes to Demolition of the Open Web
Reprinted with permission from Ryan Farmer
Eben Moglen on Encryption and Anonymity
The alternate net we need, and how we can build it ourselves
Yet More Microsofters Inside the Board of Mozilla (Which Has Just Outsourced Firefox Development to Microsoft's Proprietary Prison)
Do you want a browser controlled (and spied on) by such a company?
IRC Proceedings: Monday, December 04, 2023
IRC logs for Monday, December 04, 2023
GNU/Linux Now Exceeds 3.6% Market Share on Desktops/Laptops, According to statCounter
things have changed for Windows in China
Over at Tux Machines...
GNU/Linux news
Links 05/12/2023: Debt Brake in Germany and Layoffs at Condé Nast (Reddit, Wired, Ars Technica and More)
Links for the day
[Meme] Social Control Media Giants Shaping Debates on BSDs and GNU/Linux
listening to random people in Social Control Media
Reddit (Condé Nast), Which Has Another Round of Layoffs This Month, Incited People Against GNU/Linux Users (Divide and Rule, It's 2003 All Over Again!)
Does somebody (perhaps a third party) fan the flames?
Who Will Hold the Open Source Initiative (OSI) Accountable for Taking Bribes From Microsoft and Selling Out to Enable/Endorse Massive Copyright Infringement?
it does Microsoft advocacy
Using Gemini to Moan About Linux and Spread .NET
Toxic, acidic post in Gemini
Web Monopolist, Google, 'Pulls a Microsoft' by Hijacking/Overriding the Name of Competitor and Alternative to the Web
Gulag 'hijacking' 'Gemini'
Links 04/12/2023: Mass Layoffs at Spotify (Debt, Losses, Bubble) Once Again
Links for the day
ChatGPT Hype/Vapourware (and 'Bing') Has Failed, Google Maintains Dominance in Search
a growing mountain of debt and crises
[Meme] Every Real Paralegal Knows This
how copyright law works
Forging IRC Logs and Impersonating Professors: the Lengths to Which Anti-Free Software Militants Would Go
Impersonating people in IRC, too
IRC Proceedings: Sunday, December 03, 2023
IRC logs for Sunday, December 03, 2023
GNU/Linux Popularity Surging, So Why Did MakeUseOf Quit Covering It About 10 Days Ago?
It's particularly sad because some of the best articles about GNU/Linux came from that site, both technical articles and advocacy-centric pieces
Links 04/12/2023: COVID-19 Data Misused Again, Anti-Consumerism Activism
Links for the day