Widespread Malware Attacks Target Windows 7, Vista SP1 and XP SP3 Vuln


Recommended Posts

Microsoft confirmed not only that malware attacks designed to take advantage of a Server Service vulnerability, affecting both Windows client and server versions of the platform, were no longer isolated and targeted cases, but also that infections with malicious code had been detected.

On November 25, Bill Sisk, Microsoft Security Response Center communications manager, and Ziv Mador, senior program manager and response coordinator, revealed that the company was aware of a new wave of attacks, targeting a vulnerability rated as Critical, for which Microsoft Security Bulletin MS08-067 had been released in October as an out-of-band patch.

The security update was designed to integrate with a variety of Windows operating systems, including Windows Vista SP1, Windows XP SP3 and even Windows 7. ?During the weekend, we started receiving customer reports for new malware that exploits this vulnerability. During the last two days, that malware gained momentum and, as a result, we see an increased support call volume,? Mador revealed.

?Recently we?ve received a string of reports from customers that have yet to apply the update and are infected by malware. These most recent reports have a common malware family, and the folks in the Microsoft Malware Protection Center (MMPC) have provided detailed information regarding this latest threat,? Sisk added.

Microsoft pointed out that there were two pieces of malware associated with attacks exploiting the Server Service vulnerability: Win32/Conficker.A (also TA08-297A, CVE-2008-4250, VU827267 W32.Downadup (Symantec)) and Win32/IRCbot.BH (Win32/IRCBot.worm.Gen (AhnLab); Win32/IRCBot!generic (CA); WIN.IRC.WORM.Virus (Dr.Web); Exploit-DcomRpc.gen (McAfee); Mal/IRCBot-B (Sophos); Purple Exploit).

The first is a worm that exploits computers with vulnerable SVCHOST.EXE across a network, the latter is a Backdoor Trojan horse, which gets its commands from an attacker via an IRC server. Backdoor:Win32/IRCbot.BH is used by boots attempting to exploit MS08-067.

Worm: Win32/Conficker.A ?mostly spreads within corporations, but also was reported by several hundred home users. It opens a random port between port 1024 and 10000, and acts like a web server. It propagates to random computers on the network by exploiting MS08-067. Once the remote computer is exploited, that computer will download a copy of the worm via HTTP, using the random port opened by the worm. The worm often uses a .JPG extension when copied over, and then it is saved to the local system folder as a random named dll,? Mador revealed.

According to Microsoft, Win32/Conficker.A even patches the very API vulnerability, which it uses to infect machines, in order to prevent any further exploits to take advantage of the security hole. Mador explained that the majority of infection reports were generated in the U.S., but that the worm was also detected in Germany, Spain, France, Italy, Taiwan, Japan, Brazil, Turkey, China, Mexico, Canada, Argentina and Chile. At the same time, Win32/Conficker.A completely avoids to exploit and infect Ukrainian computers.

source

regardless of OS, clueless people need to leave the auto-updater on.

There is a certain level of arrogance when a user turns this off (unless certain cases - eg: development/testing server).

There is a certain level of arrogance when a user turns this off (unless certain cases - eg: development/testing server).

Unfortunately I have an entire team of people i'm trying to convince otherwise.

In the meantime, auto updates are off at the directors demand.

I thought Ballmer said that Vista was secure without Antivirus / more secure by design. More secure than what?!

Seems as leaky as Windows XP and all the previous versions.

Duh! Where'd you get that crazy idea from?

Vista has so much extra absolute crap in it, it could only be LESS secure than other versions of Windows! That's just a simple given!!

I thought Ballmer said that Vista was secure without Antivirus / more secure by design. More secure than what?!

Seems as leaky as Windows XP and all the previous versions.

could you have made a more uneducated comment? Vista is more secure by design and it is true that an engineer once said it was ok without anti virus(a comment he quickly withdrew) but he was only taking about the fact that programs have a much harder time elevating their permissions thanks to UAC.

The vulnerability in question was handled brilliantly by MS and this is no fault of theirs.

Duh! Where'd you get that crazy idea from?

Vista has so much extra absolute crap in it, it could only be LESS secure than other versions of Windows! That's just a simple given!!

lol ,vista is much more secure than previous versions. the number of security updates related updates that come out each month is lower under vista. but anyway people try and complain to microsoft about security and then turn off auto updates.

lol ,vista is much more secure than previous versions. the number of security updates related updates that come out each month is lower under vista. but anyway people try and complain to microsoft about security and then turn off auto updates.

not mentioning it has lower severity vulnerabilities

could you have made a more uneducated comment? Vista is more secure by design and it is true that an engineer once said it was ok without anti virus(a comment he quickly withdrew) but he was only taking about the fact that programs have a much harder time elevating their permissions thanks to UAC.

The vulnerability in question was handled brilliantly by MS and this is no fault of theirs.

I guess you didn't pick up on the 'sarcasm' :laugh:

Ballmer says some pretty stupid stuff. I bet I do too, but I'm not a CEO of a Multi-Billion dollar company.

What I believe is that Windows is vulnerable by design, and only because Windows is such a successful product, so Microsoft can't hope to fix intrinsic design faults because doing so would break App Compatibility. Two edged sword, it's a no win for Microsoft.

Duh! Where'd you get that crazy idea from?

Vista has so much extra absolute crap in it, it could only be LESS secure than other versions of Windows! That's just a simple given!!

Would you stop posting clearly false information? It is a fact. Vista with uac is a much more secure operating system than xp.

@Denholm, if you have ever seen this guy's posts he is serious.

Would you stop posting clearly false information? It is a fact. Vista with uac is a much more secure operating system than xp.

@Denholm, if you have ever seen this guy's posts he is serious.

Looking at his signature, are you REALLY surprised?

Unfortunately I have an entire team of people i'm trying to convince otherwise.

In the meantime, auto updates are off at the directors demand.

Auto updates should always be OFF when it comes to mission critical machines. It's up to those who manage it to decide what gets installed and what doesn't.

That font size is impressive, I'll give you that, but it's still obvious you don't know what I'm talking about or what mission critical actually means.

exactly... i dont think they get it

automatic updates or windows update is not a simple on & off switch. there are multiple options. but keeping it set as auto update on servers or critical systems isnt a good idea, neither is having it disabled altogether.. you think critical system/server should have auto update on and let them reboot at 3am without being notified? at least they should be set to notify or download then notify.. or prob in bigger organizations they have wsus or system managers that manage higher numbers of systems/servers together.

it's still obvious you don't know what I'm talking about or what mission critical actually means.

very often, the exploits come out within few hours after the patch is released on Windows Update... oh yeah let your mission critical machine to be exploited because it's mission critical... while your administrator is still testing the patches (which are already tested by Microsoft) you're pwned!

Edited by franzon
often the exploits come out within few hours after the patch is released on Windows Update... oh yet let your mission critical machine to be exploited because it's mission critical... while your administrator is still testing the patches (which are already tested by Microsoft) you're pwned!

you still dont get it do you

you think all administrators should immediately install updates when theyre released and reboot servers that are in a production environment?

often the exploits come out within few hours after the patch is released on Windows Update... oh yet let your mission critical machine to be exploited because it's mission critical... while your administrator is still testing the patches (which are already tested by Microsoft) you're pwned!

You should write a book on Systems Administration (Y)

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • My Photos app is version 2026.11050.1001.0 and it remembers the window size and position. My Snipping Tool is version 11.2602.49.0 and it can capture the taskbar.
    • MusicBee 3.6.9668 by Razvan Serea MusicBee is an application geared toward managing extensive music collections, easy to use and with a comprehensive feature set. It makes it easy to organize, find, and play music files on your computer, on portable devices, and on the Web. It provides playback of a wide range of audio formats, smart playlists with the ability to discover and play new music from the web, advanced tag editing with automated artwork and tag look up, folder monitoring, automated file re-organization, portable device synchronization, and secure CD ripping with AccurateRip verification. MusicBee features: Supported formats: MP3, AAC, M4A, MPC, OGG, FLAC, APE, TAK, WV, WMA and WAV. Audio CDs: Audio CD playback and ripping (with CD-Text capabilities) is supported. CD tracks can be ripped (in fast or secure mode) as individual files or as a single album with embedded cuesheet. Conversion: Conversion from and to all supported formats as metadata are preserved. Synchronization of tags only (in case that the output file already exists) instead of reencoding is possible. ReplayGain support: both playback and calculation. File Organization: Organization and renaming of music files into folders and files based on tag values such as artist, album, name, track number, etc. that can be specified. MusicBee can do this automatically for all files in a music library or the user can choose the files or folders themselves. Web Browsing: Browsing of the web using Mozilla's XULRunner environment. Scrobbling: Tracks played from MusicBee can optionally be scrobbled to Last.fm. Customizable user interface layout. Customizable keyboard shortcuts. MiniLyrics support Download: MusicBee 3.6.9668 | MusicBee Portable | ~9.0 MB (Freeware) Download: Windows Store Edition View: MusicBee Home page | Release Notes | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • On xiaomi hyperos there's also an option to disable google assistant. I've got everything disabled. Only thing I do have installed is a web wrapped for duck.ai which claims to let you use various AIs anonymously
    • I need to understand the rationale of not shipping all of these K2 improvements in a single update/release. It's giving "we will fix Windows 11 but no commitments". It seems to me that they just announce these improvements just to appease the community.
    • The term "RTM" is long gone starting with Windows 10. Every current release is a GA build. This is the result of MS making Windows as a Service (WaaS).
  • Recent Achievements

    • Conversation Starter
      sumytbe earned a badge
      Conversation Starter
    • One Year In
      B4dM1k3 earned a badge
      One Year In
    • One Year In
      DarkWun earned a badge
      One Year In
    • Dedicated
      Almohandis earned a badge
      Dedicated
    • Dedicated
      JuvenileDelinquent earned a badge
      Dedicated
  • Popular Contributors

    1. 1
      +primortal
      520
    2. 2
      +Edouard
      185
    3. 3
      PsYcHoKiLLa
      87
    4. 4
      Michael Scrip
      81
    5. 5
      Steven P.
      73
  • Tell a friend

    Love Neowin? Tell a friend!