Widespread Malware Attacks Target Windows 7, Vista SP1 and XP SP3 Vuln


Recommended Posts

Microsoft confirmed not only that malware attacks designed to take advantage of a Server Service vulnerability, affecting both Windows client and server versions of the platform, were no longer isolated and targeted cases, but also that infections with malicious code had been detected.

On November 25, Bill Sisk, Microsoft Security Response Center communications manager, and Ziv Mador, senior program manager and response coordinator, revealed that the company was aware of a new wave of attacks, targeting a vulnerability rated as Critical, for which Microsoft Security Bulletin MS08-067 had been released in October as an out-of-band patch.

The security update was designed to integrate with a variety of Windows operating systems, including Windows Vista SP1, Windows XP SP3 and even Windows 7. ?During the weekend, we started receiving customer reports for new malware that exploits this vulnerability. During the last two days, that malware gained momentum and, as a result, we see an increased support call volume,? Mador revealed.

?Recently we?ve received a string of reports from customers that have yet to apply the update and are infected by malware. These most recent reports have a common malware family, and the folks in the Microsoft Malware Protection Center (MMPC) have provided detailed information regarding this latest threat,? Sisk added.

Microsoft pointed out that there were two pieces of malware associated with attacks exploiting the Server Service vulnerability: Win32/Conficker.A (also TA08-297A, CVE-2008-4250, VU827267 W32.Downadup (Symantec)) and Win32/IRCbot.BH (Win32/IRCBot.worm.Gen (AhnLab); Win32/IRCBot!generic (CA); WIN.IRC.WORM.Virus (Dr.Web); Exploit-DcomRpc.gen (McAfee); Mal/IRCBot-B (Sophos); Purple Exploit).

The first is a worm that exploits computers with vulnerable SVCHOST.EXE across a network, the latter is a Backdoor Trojan horse, which gets its commands from an attacker via an IRC server. Backdoor:Win32/IRCbot.BH is used by boots attempting to exploit MS08-067.

Worm: Win32/Conficker.A ?mostly spreads within corporations, but also was reported by several hundred home users. It opens a random port between port 1024 and 10000, and acts like a web server. It propagates to random computers on the network by exploiting MS08-067. Once the remote computer is exploited, that computer will download a copy of the worm via HTTP, using the random port opened by the worm. The worm often uses a .JPG extension when copied over, and then it is saved to the local system folder as a random named dll,? Mador revealed.

According to Microsoft, Win32/Conficker.A even patches the very API vulnerability, which it uses to infect machines, in order to prevent any further exploits to take advantage of the security hole. Mador explained that the majority of infection reports were generated in the U.S., but that the worm was also detected in Germany, Spain, France, Italy, Taiwan, Japan, Brazil, Turkey, China, Mexico, Canada, Argentina and Chile. At the same time, Win32/Conficker.A completely avoids to exploit and infect Ukrainian computers.

source

regardless of OS, clueless people need to leave the auto-updater on.

There is a certain level of arrogance when a user turns this off (unless certain cases - eg: development/testing server).

There is a certain level of arrogance when a user turns this off (unless certain cases - eg: development/testing server).

Unfortunately I have an entire team of people i'm trying to convince otherwise.

In the meantime, auto updates are off at the directors demand.

I thought Ballmer said that Vista was secure without Antivirus / more secure by design. More secure than what?!

Seems as leaky as Windows XP and all the previous versions.

Duh! Where'd you get that crazy idea from?

Vista has so much extra absolute crap in it, it could only be LESS secure than other versions of Windows! That's just a simple given!!

I thought Ballmer said that Vista was secure without Antivirus / more secure by design. More secure than what?!

Seems as leaky as Windows XP and all the previous versions.

could you have made a more uneducated comment? Vista is more secure by design and it is true that an engineer once said it was ok without anti virus(a comment he quickly withdrew) but he was only taking about the fact that programs have a much harder time elevating their permissions thanks to UAC.

The vulnerability in question was handled brilliantly by MS and this is no fault of theirs.

Duh! Where'd you get that crazy idea from?

Vista has so much extra absolute crap in it, it could only be LESS secure than other versions of Windows! That's just a simple given!!

lol ,vista is much more secure than previous versions. the number of security updates related updates that come out each month is lower under vista. but anyway people try and complain to microsoft about security and then turn off auto updates.

lol ,vista is much more secure than previous versions. the number of security updates related updates that come out each month is lower under vista. but anyway people try and complain to microsoft about security and then turn off auto updates.

not mentioning it has lower severity vulnerabilities

could you have made a more uneducated comment? Vista is more secure by design and it is true that an engineer once said it was ok without anti virus(a comment he quickly withdrew) but he was only taking about the fact that programs have a much harder time elevating their permissions thanks to UAC.

The vulnerability in question was handled brilliantly by MS and this is no fault of theirs.

I guess you didn't pick up on the 'sarcasm' :laugh:

Ballmer says some pretty stupid stuff. I bet I do too, but I'm not a CEO of a Multi-Billion dollar company.

What I believe is that Windows is vulnerable by design, and only because Windows is such a successful product, so Microsoft can't hope to fix intrinsic design faults because doing so would break App Compatibility. Two edged sword, it's a no win for Microsoft.

Duh! Where'd you get that crazy idea from?

Vista has so much extra absolute crap in it, it could only be LESS secure than other versions of Windows! That's just a simple given!!

Would you stop posting clearly false information? It is a fact. Vista with uac is a much more secure operating system than xp.

@Denholm, if you have ever seen this guy's posts he is serious.

Would you stop posting clearly false information? It is a fact. Vista with uac is a much more secure operating system than xp.

@Denholm, if you have ever seen this guy's posts he is serious.

Looking at his signature, are you REALLY surprised?

Unfortunately I have an entire team of people i'm trying to convince otherwise.

In the meantime, auto updates are off at the directors demand.

Auto updates should always be OFF when it comes to mission critical machines. It's up to those who manage it to decide what gets installed and what doesn't.

That font size is impressive, I'll give you that, but it's still obvious you don't know what I'm talking about or what mission critical actually means.

exactly... i dont think they get it

automatic updates or windows update is not a simple on & off switch. there are multiple options. but keeping it set as auto update on servers or critical systems isnt a good idea, neither is having it disabled altogether.. you think critical system/server should have auto update on and let them reboot at 3am without being notified? at least they should be set to notify or download then notify.. or prob in bigger organizations they have wsus or system managers that manage higher numbers of systems/servers together.

it's still obvious you don't know what I'm talking about or what mission critical actually means.

very often, the exploits come out within few hours after the patch is released on Windows Update... oh yeah let your mission critical machine to be exploited because it's mission critical... while your administrator is still testing the patches (which are already tested by Microsoft) you're pwned!

Edited by franzon
often the exploits come out within few hours after the patch is released on Windows Update... oh yet let your mission critical machine to be exploited because it's mission critical... while your administrator is still testing the patches (which are already tested by Microsoft) you're pwned!

you still dont get it do you

you think all administrators should immediately install updates when theyre released and reboot servers that are in a production environment?

often the exploits come out within few hours after the patch is released on Windows Update... oh yet let your mission critical machine to be exploited because it's mission critical... while your administrator is still testing the patches (which are already tested by Microsoft) you're pwned!

You should write a book on Systems Administration (Y)

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • DJI Neo 2 Fly More Combo gets a Prime Day exclusive pricing by Steven Parker DJI reached out to let us know that the DJI Neo 2 Fly More Combo has reached its lowest price ever ahead of Prime Day that starts tomorrow. This Fly More Combo kit adds two extra batteries, and a charge hub so you can charge all three at the same time, or keep two spares fully charged for quick swap and drone flying. (buying link below) Here are some of the important specifications: DJI Neo 2 Fly More Combo Dimensions: 147x171x41mm without DJI Neo 2 Digital Transceiver 167x171x54mm with DJI Neo 2 Digital Transceiver Takeoff Weight: 151 g without DJI Neo 2 Digital Transceiver 160 g with DJI Neo 2 Digital Transceiver Max Ascent Speed: 0.5 m/s (Cine mode) 3 m/s (Normal mode) 5 m/s (Sport Mode) Max Descent Speed: 0.5 m/s (Cine Mode) 3 m/s (Normal Mode) 3 m/s (Sport Mode) Max Horizontal Speed: 8 m/s (Normal Mode) 12 m/s (Sport Mode) 12 m/s (tracking status) Max Takeoff Altitude: 2000 m Max Flight Time: Approx. 19 minutes (approx. 17 minutes with the propeller guards) Each battery allows the drone to perform at least 20 palm takeoff and landing for shoots in succession Max Hovering Time: Approx. 18 minutes (16.5 minutes with the propeller guards) Max Flight Distance: 7 Km Max Wind Speed Resistance: 10.7 m/s (Level 5) Operating Temperature: -10° to 40° C (14° to 104° F) Global Navigation System: GPS + Galileo + BeiDou Hovering Accuracy Range: Vertical: ±0.1 m (with vision positioning) ±0.5 m (with satellite positioning) Horizontal: ±0.3 m (with vision positioning) ±1.5 m (with satellite positioning) Internal Storage: 49 GB Class: C0 (EU) Image Sensor: 1/2-inch CMOS Sensor Lens: FOV: 119.8° Format Equivalent: 16.5 mm Aperture: f/2.2 Focus: 0.7 m to ∞ ISO Range: Photo 100-3200 (Single Auto) 100-12800 (Burst Auto/Timed Auto) 100-12800 (Manual) Video 100-12800 (Auto) 100-12800 (Manual) Shutter Speed: Video: 1/8000-1/30 s Photo: 1/8000-1/10 s Max Image Size: 12 MP Photo 4000×3000 (4:3) 4000×2250 (16:9) Still Photography Modes: Single/Timed Shot Single Shot: 12 MP Timed Shot: 12 MP, 2/3/5/7/10/15/20/30/60 s Photo Format: JPEG Video Resolution: Horizontal Shooting: 4K (4:3*): 3840×2880@60/50/30fps 1080p (4:3*): 1440×1080@60/50/30fps 4K (16:9): 3840×2160@100**/60/50/30fps 1080p (16:9): 1920×1080@100**/60/50/30fps Vertical Shooting: 2.7K (9:16): 1512×2688@60/50/30fps Video features: MP4 Bitrate: 80 Mbps File System: exFAT Color Mode: Normal EIS: Supports RockSteady and turning stabilization off Gimbal: Stabilization: 2-axis mechanical gimbal (tilt, roll) Mechanical Range: Tilt: -125° to 105°, Roll: -43° to 43° Controllable Range: Tilt: -90° to 70° Max Control Speed (tilt): 100°/s Angular Vibration Range: ±0.01° Image Roll Correction: Supports correction of footage recorded on the drone. WiFi: 802.11a/b/g/n/ac/ax Bluetooth: 5.2 Battery: Capacity: 1606 mAh Weight: 46 g Nominal Voltage: 7.16 V Max Charging Voltage: 8.6 V Battery Type: Li-ion Chemical System: LiNiMnCoO2 Energy: 11.5 Wh Charging Temperature: 5° to 40° C (41° to 104° F) Charge time: When Using the Two-Way Charging Hub (65W): Approx. 68 mins to charge three batteries simultaneously from 0% to 100% When Directly Charging the Aircraft Body (15W): Approx. 70 minutes to charge from 0% to 100% (MSRP) Price: $349 As such, you have everything you need to get started right in the box, including the two extra batteries, and a spare set of propellers should things go amiss with the original set of blades on the drone. Oh, the humanity! What's in the box? DJI Neo 2 Aircraft x 1; DJI Neo 2 Intelligent Flight Battery x 3 DJI Neo 2 Two-Way Charging Hub x 1; DJI Neo 2 Spare Propellers (Pair) x 1 DJI Neo 2 Spare Propeller Screw x 4; Screwdriver x 1 DJI Neo 2 Propeller Guard (Pair) x 1; DJI Neo 2 Gimbal Protector x 1 USB-C to USB-C Data Cable x 1 Having never had the chance to mess around with a drone myself, a few more highlights for this drone are listed below: Lightweight & Portable Design - Weighing just 151g and C0 certified, this compact drone features full-coverage propeller guards for safer, worry-free transport and flight. Palm Takeoff & Landing, Gesture Control - Enjoy easy palm takeoff and landing, plus intuitive gesture controls for hands-free operation and seamless flying experiences. Smooth & Reliable Tracking - ActiveTrack keeps your subject in focus, while Apple Watch lets you view live feed, check flight status, or use voice control to adjust tracking. Easy Moment Capture With SelfieShot - Snap memorable moments easily with SelfieShot, allowing quick and convenient selfies anytime with just a simple tap. All-Around Safety & Flexible Flight - Fly confidently with omnidirectional obstacle sensing and enjoy versatile flight for safer, more dynamic aerial adventures. 4K High-Quality Imaging - Capture every moment in stunning detail with 4K resolution, delivering crisp, lifelike photos and videos every time. Good to know DJI also notes on the Amazon sales page that due to platform compatibility issues, the DJI Fly app has been removed from Google Play. Visit the official DJI website to download the user manual and the latest DJI Fly app for a better experience. Which means you will have to sideload it on your Android. Where to buy DJI Neo 2 Fly More Combo for $349 at Amazon US The above price has been communicated to me as a Prime Day exclusive. As an Amazon Associate we earn from qualifying purchases.
    • Upgrade for cheap to Windows 11 Pro or Home Edition digital license by Steven Parker Today's highlighted deal comes via our Apps + Software section of the Neowin Deals store, where you can save up to 94% off on a Microsoft Windows 11 Home, or Pro digital license. Upgrade your computing experience with Windows 11 Pro. This cutting-edge operating system boasts a sleek new design and advanced tools to help you work faster and smarter. From creative projects to gaming and beyond, Windows 11 delivers the power and flexibility you need to achieve your goals. With a focus on productivity, the new features are easy to learn and use, enhancing your workflow and efficiency. Whether you're a student, professional, gamer, or creative, Windows 11 Home has everything you need to take your productivity to the next level. New interface. easier on the eyes & easier to use Biometrics login*.Encrypted authentication & advanced antivirus defenses DirectX 12 Ultimate. Play the latest games with graphics that rival reality. DirectX 12 Ultimate comes ready to maximize your hardware* Screen space. Snap layouts, desktops & seamless redocking Widgets. Stay up-to-date with the content you love & the new you care about Microsoft Teams. Stay in touch with friends and family with Microsoft Teams, which can be seamlessly integrated into your taskbar** Wake & lock. Automatically wake up when you approach and lock when you leave Smart App Control. Provides a layer of security by only permitting apps with good reputations to be installed Windows Studio Effects. Designed with Background Blur, Eye Contact, Voice Focus, & Automatic Framing Touchscreen. For a true mouse-less or keyboard-less experience TPM 2.0. Helps prevent unwanted tampering Windows 11 Pro also includes a number of productivity-focused features, such as the ability to snap multiple windows together and create custom layouts, improved voice typing, and a new, more powerful search experience. Personal and professional users will enjoy a modern and secure computing experience, with improved performance and productivity features to help users get more done. Only on Windows 11 Pro If you require enterprise-oriented features for your daily professional tasks, then Windows 11 Pro is a better option. Set up with a local account (only when set up for work or school) Join Active Directory/Azure AD Hyper-V Windows Sandbox Microsoft Remote Desktop BitLocker device encryption Windows Information Protection Mobile device management (MDM) Group Policy Enterprise State Roaming with Azure Assigned Access Dynamic Provisioning Windows Update for Business Kiosk mode Maximum RAM: 2TB Maximum no. of CPUs: 2 Maximum no. of CPU cores: 128 Good to know This license is for Windows 11 only. It is NOT intended to be used for upgrading Microsoft Office (MSO) included in Parallels Pro. However, it will still work with Parallels Pro and allow you to run Windows applications including MSO, but it DOES NOT include an upgrade MSO itself. It is still compatible with Microsoft Office ONLY if you have a separate license for it. Length of access: lifetime Redemption deadline: redeem your code within 30 days of purchase Access options: desktop Max number of device(s): 1 Version: Windows 11 Pro Updates included Queries on legality of this deal, here A Windows 11 Pro retail license normally costs $199, with Windows 11 Home usually costing $139 but you can pick either one up for just $9.97 for a limited time. For a full description, specs, and license info, click the link below. Get Windows 11 Pro for just $9.97 (was $199) Get Windows 11 Home for just $9.97 (was $139) Although priced in U.S. dollars, this deal is available for digital purchase worldwide. Support queries If you have queries or need support for any of the Neowin Deals, please use the contact form here. Neowin Deals are managed and sold by StackCommerce who represent Neowin on an affiliate basis. Why we post these deals We post these because we earn commission on each sale so as not to rely solely on advertising, which many of our readers block. It all helps toward paying staff reporters, servers and hosting costs. So for those that keep moaning and complaining, be thankful we're still online for you to even do that. Other ways to support Neowin Whitelist Neowin by not blocking our ads Create a free member account to see fewer ads Make a donation to support our day to day running costs Subscribe to Neowin - for $14 a year, or $28 a year for an ad-free experience Disclosure: Neowin benefits from revenue of each sale made through our branded deals site powered by StackCommerce.
    • Why say “Retarded” then? Lol 
    • If you don't care to read what I said, then you prove my point. Maybe written media is beyond your attention span. Titles are not summaries my friend.
  • Recent Achievements

    • Dedicated
      tuben earned a badge
      Dedicated
    • Week One Done
      mnsgroup earned a badge
      Week One Done
    • Conversation Starter
      sumytbe earned a badge
      Conversation Starter
    • One Year In
      B4dM1k3 earned a badge
      One Year In
    • One Year In
      DarkWun earned a badge
      One Year In
  • Popular Contributors

    1. 1
      +primortal
      519
    2. 2
      +Edouard
      205
    3. 3
      PsYcHoKiLLa
      97
    4. 4
      Michael Scrip
      82
    5. 5
      Steven P.
      68
  • Tell a friend

    Love Neowin? Tell a friend!