Watch out for worms

Miscellaneous Forums/General Discussion/Watch out for worms

Just though i would heads up all windows users;
http://news.bbc.co.uk/2/hi/technology/7832652.stm
Surprise surprise.

Could be bbc sensationalism though

Wow very interesting, sounds like a pretty cool program (I'm by no means a supporter of malware but the mechanism sounds interesting)

This may be a dumb question, but what is an HTTP server (that it apparently creates)?

A web server.

Basically if you've used Widnows Update since November 08 you're fine. It's not surprising to see the most commonly infected machines in places that don't have access to Windows Update due to heavy pirating.

Remember to deworm your pets regularly.

After actually reading the article, I think I actually got this a few days ago. My virus scanner Avast! didn't get rid of it but Malwarebytes' Anti-Malware did. I don't have any restore points before I removed it anymore >.> Ouch.

Seems it's from the Ukraine.

http://edition.cnn.com/2009/TECH/ptech/01/16/virus.downadup/index.html

"All you have to do is follow the worms.." - pink floyd.

Makes you wonder about the people who cannot upadate windows because they still have a 56K modem. The updates are just too big to download. Even on my 100mb hardline it takes a while to get XP up to spec.


Basically if you've used Widnows Update since November 08 you're fine. It's not surprising to see the most commonly infected machines in places that don't have access to Windows Update due to heavy pirating.



Or maybe they dont have access to an internet connection hmm?

Or maybe they dont have access to an internet connection hmm?
If they don't, there's no security risk anyway. ;)

I love Linux.

I live Lonux.

I love people who love Linux for having less trouble with viruses without realising that's because less people use Linux and less stupid people use Linux so it's only natural that Linux has less trouble with viruses than Windows. They make me feel smarter. :)

I love the people who love Linux for having less trouble with viruses because they realize it's because less people use Linux that Linux has less trouble with viruses than windows. They make me feel smarterer.

I love custard slices.

I love you, Brucey. :)

I love...wait...wut?

I live Lonux.
Spoonerism!

I love the lovers of Linux.

I love mac.




..not

I like apple struddles with custard... and I've just tried Ubuntu (bagsides Virtual machine) within VMPlayer - I was using opera within my VM last night. Dunno why - its just novel, no not Novell, novel. Oh yeah, worms and virals in a VM don't hurt your main machine so theres one reason. I'm just not sure of the performance of Windows within a VM with respect to running executables - I fear it'd be woeful.

And i nearly got my kids a worm farm for christmas, back on thread.

less people use Linux and less stupid people use Linux so it's only natural that Linux has less trouble with viruses than Windows.

very true, however even if everyone did use it, with the exception of total user stupidity there would be far less exploits simply due to the way Unix based systems and their offspring were originally designed & built. While not completely infallable its a hell of a lot safer than the way windows was built, regardless of how many people use it.

While not completely infallable its a hell of a lot safer than the way windows was built, regardless of how many people use it.


True, but the user is and will always be the weakest link in the chain.

It doesn't matter if a file is called "dont run me i am a virus.exe", if it promises naked celebrities there will still be a queue forming of people wanting to click on it, no matter how many pop-ups and password requests get thrown at them first.

You can't protect against stupidity. (Not without effectively locking the user out of the system altogether, which kind of defeats the entire purpose of a general purpose computer like the PC)

I agree, no system can protect from that, certainly not home systems as the first user gets a sudo/administrator shell available anyway. (Although this is easier (or more obvious) to invoke on windows).

But the VAST majority of PCs are business machines, on unix or linux without root there is very little a user can do or run that can exploit or bring down the entire system due to such strict permissions at such a low level. Due to variance between systems and the fact you cannot do anything outside your own userspace (and nor can that which a user runs) -which would make it a much safer choice for those kind of users, especially where someone who does know is in control of the root access, like in a business environment.
-
In fact anyone that would run an exe file promising free naked celebs should be sh.. erm. confined to using a slim or set-top box until they can pass a basic ownership test. People need a license to drive a car, plane, use a HAM radio, a UHF Marine radio, so why not an 'Im not a stupid user' test bfore owning a PC (after all as a bot-net or wot-not it too can cause chaos and damage to infrastructure and others property in incompetent hands)

:D
(im joking about the last bit but i sometimes feel that way! :)

Due to variance between systems and the fact you cannot do anything outside your own userspace (and nor can that which a user runs) -which would make it a much safer choice for those kind of users, especially where someone who does know is in control of the root access, like in a business environment.


Unfortunately, it will likely be many years before Windows system will be in the same realm: the original UNIX environment was written to be run on large corporate mainframes, where 'networking' and seperated user environments are a matter of fact. This same setup pretty much got adopted by the UNIX derivitives like Linux.

Windows, on the other hand, evolved as a graphical shell on top of a stand-alone DOS environment, which originally had pretty much NO seperated user environments (DOS and the old Windows versions pretty much allowed anyone to do anything, and neither did the filesystem support any kind of user-level security settings)

As time progressed Microsoft slapped a bunch of 'security' on top, and introduced things like the NTFS filesystem which allows for more security... But the big problem is that even now there are a TON of legacy applications (and some not so legacy) that pretty much assume that the user has administrators rights. since this isn't very granular, it means that one or a few misbehaving apps may require you to give the user account a lot more rights than strictly necessary... Which in turn makes developers assume that the user is an admin anyway, etc -- rinse and repeat.
Only with Vista does microsoft try to take matters more seriously, but so far it's still early in the adoption process. Maybe at some point in the future Windows uses a security system more similar to Linux or the Mac, but in the mean time people are getting annoyed by the growing pains to get to that point.

True, vista was a vast improvement on XP, but the core of this permission security is still handled at a software not filesystem level. I was kinda hoping windows7 would feature a completely redesigned os where nothing pre-vista would run. All XP/98 apps would be runable in a kind of built in protected environment like a VM or in the way Wine works, with the master OS acting like a kind of firewall.

You have described MSs problem perfectly, legacy. To introduce a system that cuts it all off would be admitting to past faliures, fundementally shortsighted design and windows would have less software available than linux (and far less than OSX) for at least several years.
I guess this would be suicide.

if it promises naked celebrities there ...

Sorry? Naked celebrities? What do I need to run?

I was kinda hoping windows7 would feature a completely redesigned os where nothing pre-vista would run


Not going to happen, period -- Microsoft's entire empire is build around lock-in.

If you can't run any of your old software, only two things can happen:
1) People will cling for dear life to the existing versions (even more so than people sticking with XP instead of switching to Vista)
2) People will use the opportinity to switch away from windows altogether. I mean, if none of your legacy applications will work and you have to start over fresh, why not switch to Linux or Apple that have at least some existing software market out there?

In a way, this is a bit what happened to Intel: It's 64-bit Itanium processors were technically much better than AMD's x64 extensions, but it was not backwards compatible with the x86 architecture, so people couldn't run their existing software on them.
Along came AMD with a technically 'worse' solution that did enable people to run their old stuff, and it pretty much sunk Intel's multi-billion dollar investment completely. Not much later Intel silently adopted the x64 extensions as well, and here we are today, using yet another layer on top of an outdated CPU architecture.

(The x86 platform really is a horrible cludge -- it has scaled upwards pretty decently due to ever-increasing optimizations, speed increases and multi-cores, but at a low level it's a horrible solution. Compared to pretty much every other CPU architecture x86 is horrible to program for -- for example, you only have 4 CPU registers to store your variables, while even the old Motorola 68000 that the Atari and Amiga used had 16 of them)

Anyway, to get back to Microsoft: Don't underestimate how many people actively dislike them -- there is very little brand loyalty or mindshare towards microsoft. There are a lot of people and corporations that only stick with them because they pretty much have to at this point. If you take that reason away, all bets are off again.

Microsoft would NEVER give up it's market monopoly voluntarily, henc there's no way they would give up their existing backwards compatibility. It's both a burden and blessing for them.