12.25.08

Gemini version available ♊︎

The (Microsoft) Nightmare Before Christmas

Posted in Microsoft, Security, Servers, Windows at 11:28 am by Dr. Roy Schestowitz

No, not the film

THIS TYPE OF THING happens almost every year. It’s another familiar ‘emergency Christmas’ that may lead to higher blood pressure.

Data in Microsoft Databases Under Threat

Just before the holiday, Microsoft decided to give people fewer reasons to rest well, having recently patched half a dozen critical flaws.

Desktop users running the Microsoft SQL Server 2000 Desktop Engine or SQL Server 2005 Express could be at risk in some circumstances, Microsoft said.

They have been negligent enough not to fix this in 8 months. Microsoft keeps known flaws to itself until it's too late and damage is being done.

Microsoft Corp. today confirmed that it has been working on a critical vulnerability in SQL Server for more than eight months, but declined to say whether it has had a patch ready since September, as an Austrian security researcher has alleged.

Another emergency patch (almost the third in a month [1, 2, 3]) is likely on its way. Microsoft Fanalysts [sic] are explaining the severity of this as well.

News Analysis. Microsoft has warned of a zero-day vulnerability affecting SQL Server. Do take Microsoft’s security advisory seriously.

Remember SQL Server slammer, which struck nearly six years ago? IT administrators were lucky the worm spread a month after Christmas. The new SQL Server vulnerability could bring coal to your Christmas stocking, if left untended.

Scareware and Fakes

There are other new attacks that piggyback on Microsoft.com.

Miscreants are exploiting weaknesses in more than one million webpages operated by the federal government, media companies, and even Microsoft to trick unwitting visitors into installing harmful software that takes over their computers.

More here:

Fake Antivirus Peddlers Helped by Microsoft, IRS

Just weeks after the U.S. Federal Trade Commission shut down two companies accused of selling fake antivirus software, a new player has moved into the market, aided by glitches in the Microsoft and U.S. Internal Revenue Service Web sites.

As always, there are fake greeting cards too, whose harm is only Windows compatible (where “clicking” translates to “executing”, frequently with full system privileges).

A new worm has emerged that could be much worse than the notorious Storm worm, which ruled the botnet world for nearly two years.

Zombies on the Cloud

We wrote extensively about the threat of zombie PCs. Botnets seem to have recruited almost one in two Windows PCs although most nodes in this network remain unused, so the seriousness remains mostly uncovered — for now. 98% of the Windows PCs out there are potentially ripe for hijacking, according to Secunia, so it’s down to the mercy — or wrath — of botmasters.

This has serious ramifications when it comes to security and the United States too can be crushed by botnets, according to this new simulated attack.

US cybersecurity defences fail to thwart mock cyberattack

The basic scenario involved exercises in electronic disruption accompanying a national emergency, a sequence of events played out in Estonia last year and more recently in Georgia. Defenders drew on established defence procedures but these turned out to be inadequate, for reasons not explained in any detail by participants.

Speaking of security, problems may also be introduced by Microsoft’s so-called ‘cloud’ (Azure), which we remarked on in [1, 2, 3, 4].

Amitabh: Microsoft provides a computing infrastructure on which developers can build applications. It is the responsibility of the developer to ensure that their applications, content and services comply with applicable laws and do not engage in malicious conduct. For more information refer to http://www.microsoft.com/azure/termswindowsazure.mspx

Looking at that URL:

# Indemnification.

[...]

You agree to indemnify, pay the defense costs of, and hold Microsoft and its successors, officers, directors and employees harmless from and against any and all claims, demands, costs, liabilities, judgments, losses, expenses and damages (including attorneys’ fees)

[...]

# Modifying the Terms.

[...]

Microsoft may at its sole discretion modify this agreement at any time. You can access the most current version of the agreement via the link

That’s not so reassuring. For similar reasons, we constantly warn about Microsoft's so-called "open source" licences. Microsoft totally controls the way they evolve.

International database

Share in other sites/networks: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Reddit
  • email

Decor ᶃ Gemini Space

Below is a Web proxy. We recommend getting a Gemini client/browser.

Black/white/grey bullet button This post is also available in Gemini over at this address (requires a Gemini client/browser to open).

Decor ✐ Cross-references

Black/white/grey bullet button Pages that cross-reference this one, if any exist, are listed below or will be listed below over time.

Decor ▢ Respond and Discuss

Black/white/grey bullet button If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

7 Comments

  1. Bryant said,

    December 25, 2008 at 11:39 am

    Gravatar

    “You agree to indemnify, pay the defense costs of, and hold Microsoft and its successors, officers, directors and employees harmless from and against any and all claims, demands, costs, liabilities, judgments, losses, expenses and damages (including attorneys’ fees)”

    That passage is standard issue in all Terms of Service. The whole point is that if you’re doing something that gets Microsoft sued, Microsoft should have the right to sue you for the legal woes you imposed on them.

    Amazon Web Services has a similar clause:
    http://aws.amazon.com/agreement/#12

  2. Roy Schestowitz said,

    December 25, 2008 at 11:43 am

    Gravatar

    Thank you. I did not know this and it’s valuable to bear in mind.

  3. amd-linux said,

    December 25, 2008 at 12:24 pm

    Gravatar

    Hey Roy,

    guess you are aware that MS is sponsoring your site? :-)

    I get a large banner ad for MS Office when I view this page – and of course, I HAD to check out what MS office has to offer for a Linux user (just to find out that it still is not much, compared to OO.org and the price tag…) and clicked on it….

    Merry Christmas to verybody, and thanks to MS for sponsoring :-)

  4. Roy Schestowitz said,

    December 25, 2008 at 12:36 pm

    Gravatar

    We’re blocking Microsoft and Novell domains, but this doesn’t prevent their channel partners from penetrating through Google. What was the site’s domain? Let us know so that Shane can add it to the blocklist.

  5. Shane Coyle said,

    December 25, 2008 at 12:38 pm

    Gravatar

    Yup, we’re fully aware – we even have reports of Novell ads here from time to time.

    As evidenced by the comments here, we have a regular community of folks from all sides of the Microsoft-Novell deal – supporters, haters, and some who are indifferent or have not yet made up their mind. If Microsoft and Novell wish to try and make their case, they can feel free.

    Please, as always – do not commit click fraud, if you are genuinely interested in an ad, great. If not, (depending on your browser) you may consider an ad blocker or proxy filter setup in order to avoid the ads altogether – that’s what I do.

    Ads are a necessary evil here, we’ve discussed it before and I still can’t see a way around it, we get alot of traffic, and sometimes we melt the servers with some of the stories that get Dugg or Slashdotted.

    Just recently, technocrat.net fell by the wayside due to similar pressures and inviability, and while we are not in danger of that presently, I was close to broke not long ago and may be once again…

  6. Shane Coyle said,

    December 25, 2008 at 12:44 pm

    Gravatar

    For the record, novell.com microsoft.com and moreinterop.com should not come through. After that, it became too tedious to filter in Adsense…

  7. Roy Schestowitz said,

    December 25, 2008 at 12:49 pm

    Gravatar

    I didn’t realise that MoreInterop used to sneak in. Heh. “More Interop”… kind of like “More dead” of “F-” (as though standards are a relative thing)

DecorWhat Else is New


  1. Unlawful Regimes Even Hungary and Poland Would Envy

    There’s plenty of news reports about Polish and Hungarian heads of states violating human rights, but never can one find criticism of the EPO’s management doing the same (the mainstream avoids this subject altogether); today we examine how that area of Europe voted on the illegal "Strike Regulations" of Benoît Battistelli



  2. The EPO’s Overseer/Overseen Collusion — Part XX: The Visegrád Group

    The EPO‘s unlawful “Strike Regulations” (which helped Benoît Battistelli and António Campinos illegally crush or repress EPO stuff) were supported by only one among 4 Visegrád delegates



  3. [Meme] IBM Has Paid ZDNet to Troll the Community

    Over the past few weeks ZDNet has constantly published courses with the word "master" in their headlines (we caught several examples; a few are shown above); years ago this was common, also in relation to IBM itself; clearly IBM thinks that the word is racially sensitive and offensive only when it's not IBM using the word and nowadays IBM pays ZDNet — sometimes proxying through the Linux Foundation — to relay this self-contradictory message whose objective is to shame programmers, Free software communities etc. (through guilt they can leverage more power and resort to projection tactics, sometimes outright slander which distracts)



  4. [Meme] ILO Designed to Fail: EPO Presidents Cannot be Held Accountable If ILOAT Takes Almost a Decade to Issue a Simple Ruling

    The recent ILOAT ruling (a trivial no-brainer) inadvertently reminds one of the severe weaknesses of ILOAT; what good is a system of accountability that issues rulings on decisions that are barely relevant anymore (or too late to correct)?



  5. Links 22/10/2021: Trump's AGPL Violations and Chrome 95 Released

    Links for the day



  6. [Meme] How Corporate Monopolies Demonise Critics of Their Technically and Legally Problematic 'Products'

    When the technical substance of some criticism stands (defensible based upon evidence), and is increasingly difficult to refute based on facts, make up some fictional issue — a straw man argument — and then respond to that phony issue based on no facts at all



  7. Links 22/10/2021: Global Encryption Day

    Links for the day



  8. [Meme] Speaking the Same Language

    Language inside the EPO is misleading. Francophones Benoît Battistelli and António Campinos casually misuse the word “social”.



  9. António Campinos Thinks Salary Reductions Months Before He Leaves is “Exceptional Social Gesture”

    Just as Benoît Battistelli had a profound misunderstanding of the concept of “social democracy” his mate seems to completely misunderstand what a “social gesture” is (should have asked his father)



  10. IRC Proceedings: Thursday, October 21, 2021

    IRC logs for Thursday, October 21, 2021



  11. Links 21/10/2021: MX Linux 21 and Git Contributors’ Summit in a Nutshell

    Links for the day



  12. [Meme] [Teaser] Miguel de Icaza on CEO of Microsoft GitHub

    Our ongoing series, which is very long, will shed much-needed light on GitHub and its goals (the dark side is a lot darker than people care to realise)



  13. Gemini Protocol and Gemini Space Are Not a Niche; for Techrights, Gemini Means Half a Million Page Requests a Month

    Techrights on gemini:// has become very big and we’ll soon regenerate all the pages (about 37,500 of them) to improve clarity, consistency, and general integrity



  14. 'Satellite States' of EPO Autocrats

    Today we look more closely at how Baltic states were rendered 'voting fodder' by large European states, looking to rubber-stamp new and oppressive measures which disempower the masses



  15. [Meme] Don't Mention 'Brexit' to Team UPC

    It seems perfectly clear that UPC cannot start, contrary to what the EPO‘s António Campinos told the Council last week (lying, as usual) and what the EPO insinuates in Twitter; in fact, a legal challenge to this should be almost trivial



  16. The EPO’s Overseer/Overseen Collusion — Part IXX: The Baltic States

    How unlawful EPO rules were unsurprisingly supported by Benoît Battistelli‘s friends in Baltic states; António Campinos maintained those same unlawful rules and Baltic connections, in effect liaising with offices known for their corruption (convicted officials, too; they did not have diplomatic immunity, unlike Battistelli and Campinos)



  17. Links 21/10/2021: GIMP 2.99.8 Released, Hardware Shortages, Mozilla Crisis

    Links for the day



  18. How Oppressive Governments and Web Monopolists Might Try to Discourage Adoption of Internet Protocols Like Gemini

    Popular movements and even some courageous publications have long been subverted by demonisation tactics, splits along unrelated grounds (such as controversial politics) and — failing that — technical sabotage and censorship; one must familiarise oneself with commonly-recurring themes of social control by altercation



  19. [Meme] Strike Triangulations, Reception Issues

    Financial strangulations for Benoît Battistelli‘s unlawful “Strike Regulations”? The EPO will come to regret 2013…



  20. [Meme] Is Saying “No!” to Unlawful Proposals Considered “Impolite”?

    A ‘toxic mix’ of enablers and cowards (who won’t vote negatively on EPO proposals which they know to be unlawful) can serve to show that the EPO isn’t a “social democracy” as Benoît Battistelli liked to call it; it’s just a dictatorship, currently run by the son of a person who actually fought dictatorship



  21. IRC Proceedings: Wednesday, October 20, 2021

    IRC logs for Wednesday, October 20, 2021



  22. [Meme] EPO Legal Sophistry and Double Dipping

    An imaginary EPO intercept of Administrative Council discussions in June 2013...



  23. Links 21/10/2021: PostgreSQL JDBC 42.3.0 and Maui Report

    Links for the day



  24. [Meme] [Teaser] “Judge a Person Both by His Friends and Enemies”

    Fervent supporters of Team Battistelli or Team Campinos (a dark EPO era) are showing their allegiances; WIPO and EPO have abused staff similarly over the past decade or so



  25. 'Cluster-Voting' in the European Patent Office/Organisation (When a Country With 1.9 Million Citizens Has the Same Voting Power as a Country With 83.1 Million Citizens)

    Today we examine who has been running the Finnish patent office and has moreover voted in the EPO during the ballot on unlawful "Strike Regulations"; they voted in favour of manifestly illegal rules and for 8.5 years after that (including last Wednesday) they continued to back a shady regime which undermines the EPO's mission statement



  26. The EPO’s Overseer/Overseen Collusion — Part XVIII: Helsinki's Accord

    The Finnish outpost has long been strategic to the EPO because it can help control the vote of four or more nations; evidence suggests this has not changed



  27. [Meme] Living as a Human Resource, Working for Despots

    The EPO has become a truly awful place/employer to work for; salary is 2,000 euros for some (despite workplace stress, sometimes relocation to a foreign country)



  28. Links 20/10/2021: New Redcore Linux and Hospital Adoption of GNU Health

    Links for the day



  29. IRC Proceedings: Tuesday, October 19, 2021

    IRC logs for Tuesday, October 19, 2021



  30. Links 19/10/2021: Karanbir Singh Leaves CentOS Board, GPL Violations at Vizio

    Links for the day


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts