07.26.10
Eye on Security: Windows Perils
Summary: Windows continues to be inherently insecure and Microsoft is not helping
● Microsoft Windows Security Advisory Flawed, Pros Say
Security researchers are expressing concern that Microsoft’s security advisory about a Windows vulnerability is misleading, as users do not need to click on malicious icons in order to trigger malware exploiting the flaw, which, according to all sides, has already been the subject of attacks.
● Experts predict extensive attacks of Windows zero-day
Security organizations today raised Internet threat levels to warn users that they expect widespread attacks using exploits of a just-acknowledged critical bug in all versions of Windows.
● Kaspersky blocks BBC News over false phishing fears
● New Virus Targets Industrial Secrets
Techrights is still sporadically bombarded by Windows zombies today. Apart from limited availability to visitors, this has caused the distressing loss of several hours of work.
Yuhong Bao said,
July 26, 2010 at 1:08 pm
On the matter of Windows zombies, is MS really to blame? The security vulnerabilities maybe, but did MS patch in time?
Dr. Roy Schestowitz Reply:
July 26th, 2010 at 1:44 pm
The bots identify themselves as Microsoft search (may be spoofed).
Yuhong Bao Reply:
July 26th, 2010 at 6:51 pm
Is it just HTTP traffic or something else?
Dr. Roy Schestowitz Reply:
July 26th, 2010 at 7:00 pm
Just HTTP.
Yuhong Bao Reply:
July 26th, 2010 at 7:02 pm
How often, and have you traced the source of the IP address?
Dr. Roy Schestowitz Reply:
July 26th, 2010 at 7:15 pm
Sometimes there are cessations. The user-agents seem to be forged.
Dr. Roy Schestowitz Reply:
July 26th, 2010 at 7:16 pm
About IP addresses, I can’t see them because there’s a cache/proxy server which channels all the traffic for speedup.