08.16.10

Gemini version available ♊︎

Microsoft Security Issues in The British Press, Vista and Vista 7 No Panacea

Posted in Microsoft, Security, Vista, Vista 7, Windows at 4:10 am by Dr. Roy Schestowitz

Summary: Security news from the British press and IDG (gathered in recent weeks), affecting all versions of Windows

THE MSBBC (mentioned in the previous post) continues calling a criminal “hacker”, which deceives British readers.

Another report, specifically this one from The Inquirer (there are more such reports outside the UK), says that “[a] scary number of security suites fail on Windows Vista” and this potentially contradicts that story Microsoft had printed in IDG the other day.

Doomed from the start probably because they were tested on Windows Vista Business Edition SP2, the tests found a marked inability of some software to cope with heavy attacks. As opposed to Windows Vista’s inability to cope, full stop. Virus Bulletin’s crack squad also noted that false positive rates were very high, with legitimate files from Corel, Roxio and Adobe having been falsely identified as being infected.

Yesterday I went over to good friend of mine who has been stuck with Vista for a few years and hates it (I showed him KDE and GNOME, then set it up for his brother in law). Vista is in many ways a mess and the fonts are ugly on some screens (BSODs are an occasional problem too); Vista 7 is more of the same but somewhat improved. According to this new eWEEK readers survey, there are more GNU/Linux users there than Vista 7 users. No surprise.

Windows XP scored nearly 44 percent in a poll of which desktops eWEEK readers use to run their business. Microsoft’s Windows 7 came in behind Linux, while Vista languished with a handful of votes in the “other” category.

In other security news from this month, let’s look at The Register (UK):

Hoax Facebook virus makes more trouble than a real virus

Blackhole your malware

Anti-virus defences even shakier than feared

A study by web intelligence firm Cyveillance found that, on average, vendors detect less than 19 per cent of malware attacks on the first day malware appears in the wild. Even after 30 days, detection rates improved to just 61.7 per cent, on average.

Waledac zombie attacks rise from the grave

However, over recent weeks, the botnet is making a comeback of sorts. Spammed messages containing malicious attachment harbouring Waladec agents and disguised as tax invoices or job offers and the like have begun appearing, Trend Micro warns.

The same run of spam messages is also being used to spread fake anti-virus and other scams unrelated to Waledac, and there’s no sign that a new command and control structure, much less a fresh round of spamming, has begun.

Scotland Yard cuffs six in megaquid phish ring probe

Botnet that pwned 100,000 UK PCs taken out

Click fraud botnet unpicked

Cybercrooks use of botnets to make money by sending spam or launching denial of service attacks has become a well-understood business model.

But the controllers of networks of compromised PCs have other ways of turning an illicit profit, including using rogue traffic brokers to defraud reputable brands. Trend Micro’s write-up of a click fraud scam sheds light onto this less well-known but highly lucrative cyberscam.

“Malware Reaches An All-Time High,” claims this report.

McAfee found 6 million malicious files in the second quarter, compared to 4 million in the first quarter.

This was also covered by IDG, which published “Malware Call to Arms: Threat at All-Time High and Rising”

Going as far back as last month in IDG, we also have:

Atlanta Has Dubious Honor of Highest Malware Infection Rate

Natural Disasters and Global Warming Fuel the Malware Flames

After worm, Siemens says don’t change passwords

Trusteer Finds 100,000 UK Computers Infected With Zeus

We wrote about Zeus in [1, 2, 3] and about Stuxnet/Siemens in [1, 2, 3, 4, 5, 6]. “Stuxnet Industrial Worm Was Written Over a Year Ago,” claims IDG.

A sophisticated worm designed to steal industrial secrets has been around for much longer than previously thought, according to security experts investigating the malicious software.

Called Stuxnet, the worm was unknown until mid-July, when it was identified by investigators with VirusBlockAda, a security vendor based in Minsk, Belarus. The worm is notable not only for its technical sophistication, but also for the fact that it targets the industrial control system computers designed to run factories and power plants.

From CNET: “Stuxnet could hijack power plants, refineries”

“For example, at an energy production plant, the attacker would be able to download the plans for how the physical machinery in the plant is operated and analyze them to see how they want to change how the plant operates, and then they could inject their own code into the machinery to change how it works,” he said.

The Stuxnet worm propagates by exploiting a hole in all versions of Windows in the code that processes shortcut files ending in “.lnk.” It infects machines via USB drives but can also be embedded in a Web site, remote network share, or Microsoft Word document, Microsoft said.

Microsoft issued an emergency patch for the Windows Shortcut hole last week, but just installing the patch is not enough to protect systems running the Siemens program because the malware is capable of hiding code in the system that could allow a remote attacker to interfere with plant operations without anyone at the company knowing, according to O’Murchu.

That’s truly a national security issue. Watch this news from Japan: [via]

Computer criminal blows probation

Tokyo police said Wednesday they have arrested a 27-year-old man in Osaka on suspicion of using a computer virus to destroy stored data.

Unless or until Windows is removed, systems that affect many people’s lives will continue to be at risk.

Share in other sites/networks: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Reddit
  • email

Decor ᶃ Gemini Space

Below is a Web proxy. We recommend getting a Gemini client/browser.

Black/white/grey bullet button This post is also available in Gemini over at this address (requires a Gemini client/browser to open).

Decor ✐ Cross-references

Black/white/grey bullet button Pages that cross-reference this one, if any exist, are listed below or will be listed below over time.

Decor ▢ Respond and Discuss

Black/white/grey bullet button If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

DecorWhat Else is New


  1. Links 31/05/2023: Librem Server v2, curl 8.1.2, and Kali Linux 2023.2 Release

    Links for the day



  2. Gemini Links 31/05/2023: Bayes Filter and Programming Wordle

    Links for the day



  3. [Meme] Makes No Sense for EPO (Now Connected to the EU) and Staff Pensions to be Tied to the UK After Brexit

    It seems like EPO staff is starting to have doubts about the safety of EPO pensions after Benoît Battistelli sent money to reckless gambling (EPOTIF) — a plot that’s 100% supported by António Campinos and his enablers in the Council, not to mention the European Union



  4. Working Conditions at EPO Deteriorate and Staff Inquires About Pension Rights

    Work is becoming a lot worse (not even compliant with the law!) and promises are constantly being broken, so staff is starting to chase management for answers and assurances pertaining to finances



  5. Links 30/05/2023: Orc 0.4.34 and Another Rust Crisis

    Links for the day



  6. Links 30/05/2023: Nitrux 2.8.1 and HypoPG 1.4.0

    Links for the day



  7. Gemini Links 30/05/2023: Bubble Version 3.0

    Links for the day



  8. Links 30/05/2023: LibreOffice 7.6 in Review and More Digital Restrictions (DRM) From HP

    Links for the day



  9. Gemini Links 30/05/2023: Curl Still Missing the Point?

    Links for the day



  10. IRC Proceedings: Monday, May 29, 2023

    IRC logs for Monday, May 29, 2023



  11. MS (Mark Shuttleworth) as a Microsoft Salesperson

    Canonical isn’t working for GNU/Linux or for Ubuntu; it’s working for “business partners” (WSL was all along about promoting Windows)



  12. First Speaker in Event for GNU at 40 Called for Resignation/Removal of GNU's Founder

    It’s good that the FSF prepares an event to celebrate GNU’s 40th anniversary, but readers told us that the speakers list is unsavoury, especially the first one (a key participant in the relentless campaign of defamation against the person who started both GNU and the FSF; the "FSFE" isn't even permitted to use that name)



  13. When Jokes Became 'Rude' (or Disingenuously Misinterpreted by the 'Cancel Mob')

    A new and more detailed explanation of what the wordplay around "pleasure card" actually meant



  14. Site Updates and Plans Ahead

    A quick look at or a roundup of what we've been up to, what we plan to publish in the future, what topics we shall focus on very soon, and progress moving to Alpine Linux



  15. Links 29/05/2023: Snap and PipeWire Plans as Vendor Lock-in

    Links for the day



  16. Gemini Links 29/05/2023: GNU/Linux Pains and More

    Links for the day



  17. Links 29/05/2023: Election in Fedora, Unifont 15.0.04

    Links for the day



  18. Gemini Links 29/05/2023: Rosy Crow 1.1.1 and Smolver 1.2.1 Released

    Links for the day



  19. IRC Proceedings: Sunday, May 28, 2023

    IRC logs for Sunday, May 28, 2023



  20. Daniel Stenberg Knows Almost Nothing About Gemini and He's Likely Just Protecting His Turf (HTTP/S)

    The man behind Curl, Daniel Stenberg, criticises Gemini; but it's not clear if he even bothered trying it (except very briefly) or just read some inaccurate, one-sided blurbs about it



  21. Links 29/05/2023: Videos Catchup and Gemini FUD

    Links for the day



  22. Links 28/05/2023: Linux 6.4 RC4 and MX Linux 23 Beta

    Links for the day



  23. Gemini Links 28/05/2023: Itanium Day, GNUnet DHT, and More

    Links for the day



  24. Links 28/05/2023: eGates System Collapses, More High TCO Stories (Microsoft Windows)

    Links for the day



  25. IRC Proceedings: Saturday, May 27, 2023

    IRC logs for Saturday, May 27, 2023



  26. No More Twitter, Mastodon, and Diaspora for Tux Machines (Goodbye to Social Control Media)

    People would benefit from mass abandonment of such pseudo-social pseudo-media.



  27. Links 28/05/2023: New Wine and More

    Links for the day



  28. Links 27/05/2023: Plans Made for GNU's 40th Anniversary

    Links for the day



  29. Social Control Media Needs to be Purged and We Need to Convince Others to Quit It Too (to Protect Ourselves as Individuals and as a Society)

    With the Tux Machines anniversary (19 years) just days away we seriously consider abandoning all social control media accounts of that site, including Mastodon and Diaspora; social control networks do far more harm than good and they’ve gotten a lot worse over time



  30. Anonymously Travelling: Still Feasible?

    The short story is that in the UK it's still possible to travel anonymously by bus, tram, and train (even with shades, hat and mask/s on), but how long for? Or how much longer have we got before this too gets banned under the false guise of "protecting us" (or "smart"/"modern")?


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts