New Windows Worm Inching Around Internet
helixcode123 writes "The Register is reporting a Windows Worm that
takes advantage of weak default passwords. This
looks pretty nasty, as it mucks with the registry
and disables network sharing." Basically if it finds SMB shares with weak passwords, it drops an executable in the startup folder... for once a security problem that isn't really Microsoft's fault.
I bet they just made a program that tried, "Love, sex, and god".
...for once a security problem that isn't really Microsoft's fault...
Taco: Hell just called. They want you turn back on the heat.
for once a security problem that isn't really Microsoft's fault.
What!! On Slashdot!! a story that absolves Microsoft of guilt when blind-eyed finger pointing would have been so easy...
Who are you and what have you done with the slashdot editors?!?
--
Dilbert - "If aliens take over your boss's body, is that a bad thing?"
Wally - "It depends on the aliens"
xyzzy
on the list of passwords it tries. Guess I don't have to worry about this one.
Best Buy can have you arrested
This is the seventh posting on the front page in a row by Taco. And none of them are dupes!
Dammit, I knew I should have built that bomb shelter...
Let me guess, UDP port 137 is producing lots and lots of logged events?
Thats normal. There are two solutions;
1. Design, build and spread a virus or trojan which will irrevocably destroy all Windows boxes which are connected to the internet without a firewall.
Or
2. Stop logging UDP port 137.
In the free world the media isn't government run; the government is media run.
Because this is slashdot. The fact that your aunt has breast cancer is Microsoft's fault.
"Perhaps the best solution would be biometrics?"
Maybe. If implemented by a security guard with a pair of calipers that he measures your skull with every time you want to log on, then he logs on for you and if your skull doesn't match the numbers on his clipboard he shoots you.
In the free world the media isn't government run; the government is media run.
NO CARRIER
Happy Saint Patrick's day!
DMCA, Hollings, Palladium. What might have sounded like paranoia is now common sense.
A worm that isn't Microsoft's problem!?!? Next thing you know you'll hear about airliners falling out of the sky due to flying pigs...
eh, food for thought...
For example, make it really clear to users enabling file sharing that people can and will try to break in if they connect to the Internet, so strong passwords or other security means are really necessary.
It's a good thought, but consider this:
You should be warned that ena*click*
Are you sure that you want*click*
Sweet. My files are shared.
Withdrawal before climax is very ineffective and those who try this are usually called "parents."
Is the one left open by an Admin who has no business being an Admin....
For 99.997% (Manhattan Project, anyone?) of the cases, I'd agree wholeheartedly. The rest of them, like our Network Admin where I work, are under the thumb of some stupid BEEYOTCH of an IT Director who wants to continue to use the same passwords used by the old Network Administrator (who was shitcanned by her), and refuses to allow the new guy to set newer, more secure passwords. And believe me, it's not a matter of people just not getting along. For Pete's sake, she's even yelled at me for encrypting DSN strings and sticking them in the registry of the server, instead of plopping them in a text file like everyone else, open to the world. And she totally f*cking flipped (when she read the documentation I wrote about the procedure) upon hitting the section that described how every time the DSN was accessed, read, edited, or yelled at sternly the code modified and scrambled it with a new, different algorithm. She described it as "unsafe, and taking things to an extreme that was unnecessary". She also said made some asinine comment about how we would never be able to recover the passwords if the code were ever lost, to which I recall thinking "Well first, that's job security for me, second, don't forget your goddamn passwords, and third, that's what sa access is for, you dumb bitch."
Yep, this type of commentary coming from someone who not only has no business being an IT Director, but swears on a stack of bibles she can reverse engineer MD5 in her head (we have another application that uses MD5 to hash passwords, she simply recognizes the default password hash).
I swear to God I'm not making this shit up. I wish the nasty bitch would stick to pushing pencils and leave the real work to those of us who know.
Spread the RC luvin'
Yea, but copy C:\Windows\Tempor~1\Work.exe C:\Windows\StartMenu\Programs\Startup dosn't work too well on linux.
"disables network sharing."
:)
Thank you god. Now all it has to do is infect our network and all those open Sharedocs shares that WinXP automaticially creates that are full of Nimda are history. Although the PC would most likely be history too.
Either way nimda would be off the network
In Soviet Russia, Trojan exploits YOU!
Is that case sensitive?
Keep Austin Weird!
interesting system. I take a bag of marbles and throw it at my keyboard until I get 8-12 characters and go from there.
"The government of the United States is not, in any sense, founded on the Christian religion."
The fact that your aunt has breast cancer is Microsoft's fault.
THAT is what I have been telling everyone! Of course they don't believe me, and that is Microsoft's fault too!
DAMN YOU MICROSOFT
Shit... Tried in Mozilla the "file://IPofanattacker/ Guess what... My own hard drive directory structure is sitting in front of me. I'm running linux and everything is fuck'n rock solid tight. All IP ports turned off. Can anyone else duplicate this. Just enter any IP address into file://(right here). Mozilla defaults to the hard drive of the actual machine it's running on????!!!! Something which I do not like....
"What's your password?" "It's random." "Great, glad you use a smart strategy, now tell me what it is, please." "I told you, it's 'random'" "How can it be random...you have to decide it when you rotate, and of course it's picked at random...so, anyhow, tell me what it is right now... " " it's random....I just told you!!!"
This is the seventh posting on the front page in a row by Taco. And none of them are dupes!
/. editors have been replaced with the cyborgs that live among us. I for one, welcome our new android overlords. As a trusted /. personality, I can be helpful in rounding up others to toil in thier underground sugar caves.
Along with that, this post observes that Taco posted a story about a worm that did not contain a snide comment about Microsoft.
It's very clear to me now, obviously the
Enigma
since the worm doesn't try the most common password: ******
xyzzy
Nothing happens.
My journal has hot