Eye on Security: Internet Still Threatened by Microsoft Windows
- Dr. Roy Schestowitz
- 2010-07-20 10:49:10 UTC
- Modified: 2010-07-20 10:49:10 UTC
Summary: New Windows Trojans, malware, and the likes of that
●
Can Windows kill the Internet?
I've long thought that someday Windows' security problems could foul up the Internet for everyone. That day may be arriving.
It's not just me being paranoid about Windows. It's the ISC (Internet Storm Center), the group that tracks the overall health of the Internet. They're wondering whether the newly discovered "LNK" exploit might be used to slam the brakes on the Internet's high-speed traffic.
According to Lenny Zeltser, an ISC security consultant, the ISC has
decided to raise the Infocon level to Yellow to increase awareness of the recent LNK vulnerability and to help preempt a major issue resulting from its exploitation. Although we have not observed the vulnerability exploited beyond the original targeted attacks, we believe wide-scale exploitation is only a matter of time. The proof-of-concept exploit is publicly available, and the issue is not easy to fix until Microsoft issues a patch. Furthermore, anti-virus tools' ability to detect generic versions of the exploit have not been very effective so far.
●
New Menace in the War Against Online Crime
Avoiding Web-borne infections is increasingly difficult, because many malicious sites are legitimate sites that have been hacked. But here are four steps to take to protect your computer:
1) Use the latest version of your favorite Web browser, because most have important anti-malware technologies not available in the older models. Consider using Google Chrome, which uses so-called sandboxing technology to stop drive-by downloads.
●
Microsoft initiates zero-day vulnerability probe
Microsoft is investigating reports of ongoing "targeted attacks" that reportedly exploit a serious Windows Shell vulnerability.
●
Zeus baddies unleash nasty new bank Trojan
Hackers have created a new version of the Zeus crimeware toolkit that's designed to swipe bank login details of Spanish, German, UK and US banks.
The malware payload, described by CA as Zeus version 3, is far more selective in the banks it targets. Previous versions targeted financial institutions around the world while the latest variant comes in two flavours: one that only target banks in Spain and Germany, and a second that only targets financial institutions in the UK and US.
●
MS Patch Tuesday: Googler zero-day fixed in 33 days
●
You Have to Wait a Month for Reinforcements
Folks who have migrated to GNU/Linux may have to work hard to make the transition but they can relax a lot afterwards. That other OS and its apps will be around for years drawing attention from malware and GNU/Linux will just keep growing staying small and modular with lots of immunity built in. The cost of fighting malware is almost entirely born by users of that other OS and GNU/Linux gets a free ride. I like that. The cost of monopoly is compounding itself and the price of Freedom declines.
Recent Techrights' Posts
- Microsoft: Our "Goodwill" Gained Over 51 Billion Dollars in the Past Nine Months Alone, Now "Worth" as Much as All Our Physical Assets (Property and Equipment)
- The makeup of a Ponzi scheme where the balance sheet has immaterial nonsense
- FSFE (Ja, Das Gulag Deutschland) Has Lost Its Tongue
- Articles/month
- Ian Jackson & Debian reject mediation
- Reprinted with permission from disguised.work
- How to get selected for Outreachy internships
- Reprinted with permission from disguised.work
- Red Hat Corporate Communications is "Red" Now
- Also notice they offer just two options: MICROSOFT or... MICROSOFT!
-
- Links 27/04/2024: Kaiser Gave Patients' Data to Microsoft, "Microsoft Lost ‘Dream Job’ Status"
- Links for the day
- Gemini Links 27/04/2024: Sunrise Photos and Slow Productivity
- Links for the day
- Almost 2,700 New Posts Since Upgrading to Static Site 7 Months Ago, Still Getting More Productive Over Time
- We've come a long way since last autumn
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Friday, April 26, 2024
- IRC logs for Friday, April 26, 2024
- Overpaid lawyer & Debian miss WIPO deadline
- Reprinted with permission from disguised.work
- Brian Gupta & Debian: WIPO claim botched, suspended
- Reprinted with permission from disguised.work
- Microsoft's XBox is Dying (For Second Year in a Row Over 30% Drop in Hardware Sales)
- they boast about fake numbers or very deliberately misleading numbers that represent two companies, not one
- [Meme] Granting a Million Monopolies in Europe (to Non-European Companies) at Europe's Expense
- Financialization of the EPO
- Salary Adjustment Procedure at the EPO Challenged
- the EPO must properly compensate staff in order to attract and retain suitably skilled examiners
- Links 26/04/2024: Surveillance Abundant, Restoring Net Neutrality Rules (US)
- Links for the day
- Gemini Links 26/04/2024: uConsole and EXWM and stdu 1.0.0
- Links for the day
- Links 26/04/2024: XBox Sales Have Collapsed, Facebook's Shares Collapse Too
- Links for the day
- Albanian women, Brazilian women & Debian Outreachy racism under Chris Lamb
- Reprinted with permission from disguised.work
- Microsoft-Funded 'News' Site: XBox Hardware Revenue Declined by 31%
- Ignore the ludicrous media spin
- Mark Shuttleworth, Elio Qoshi & Debian/Ubuntu underage girls
- Reprinted with permission from disguised.work
- Karen Sandler, Outreachy & Debian Money in Albania
- Reprinted with permission from disguised.work
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Thursday, April 25, 2024
- IRC logs for Thursday, April 25, 2024
- Links 26/04/2024: Facebook Collapses, Kangaroo Courts for Patents, BlizzCon Canceled Under Microsoft
- Links for the day
- Gemini Links 26/04/2024: Music, Philosophy, and Socialising
- Links for the day
- Microsoft Claims "Goodwill" Is an Asset Valued at $119,163,000,000, Cash Decreased From $34,704,000,000 to $19,634,000,000 and Total Liabilities Grew to $231,123,000,000
- Earnings Release FY24 Q3
- More Microsoft Cuts: Events Canceled, Real Sales Down Sharply
- So they will call (or rebrand) everything "AI" or "Azure" or "cloud" while adding revenues from Blizzard to pretend something is growing
- CISA Has a Microsoft Conflict of Interest Problem (CISA Cannot Achieve Its Goals, It Protects the Worst Culprit)
- people from Microsoft "speaking for" "Open Source" and for "security"
- Links 25/04/2024: South Korean Military to Ban iPhone, Armenian Remembrance Day
- Links for the day
- Gemini Links 25/04/2024: SFTP, VoIP, Streaming, Full-Content Web Feeds, and Gemini Thoughts
- Links for the day
- Audiocasts/Shows: FLOSS Weekly and mintCast
- the latest pair of episodes
- [Meme] Arvind Krishna's Business Machines
- He is harming Red Hat in a number of ways (he doesn't understand it) and Fedora users are running out of patience (many volunteers quit years ago)
- [Video] Debian's Newfound Love of Censorship Has Become a Threat to the Entire Internet
- SPI/Debian might end up with rotten tomatoes in the face
- Joerg (Ganneff) Jaspert, Dalbergschule Fulda & Debian Death threats
- Reprinted with permission from disguised.work
- Amber Heard, Junior Female Developers & Debian Embezzlement
- Reprinted with permission from disguised.work
- [Video] Time to Acknowledge Debian Has a Real Problem and This Problem Needs to be Solved
- it would make sense to try to resolve conflicts and issues, not exacerbate these
- Daniel Pocock elected on ANZAC Day and anniversary of Easter Rising (FSFE Fellowship)
- Reprinted with permission from Daniel Pocock
- [Video] IBM's Poor Results Reinforce the Idea of Mass Layoffs on the Way (Just Like at Microsoft)
- it seems likely Red Hat layoffs are in the making
- Ulrike Uhlig & Debian, the $200,000 woman who quit
- Reprinted with permission from disguised.work
- IRC Proceedings: Wednesday, April 24, 2024
- IRC logs for Wednesday, April 24, 2024
- Over at Tux Machines...
- GNU/Linux news for the past day