Slashdot Mirror


Fake Microsoft Patch Triggers Virus Attack

boarder8925 writes "eWeek reports: 'Like day follows night, a bogus cumulative update with a malicious attachment has followed Microsoft's patch day. In what has become a monthly staple, virus writers are taking advantage of the heightened public interest around Microsoft's patching cycle to trick users into executing a malicious attachment. The latest social engineering trick arrives via e-mail with an attachment that purports to be a 'cumulative patch' for May 2005.'"

3 of 275 comments (clear)

  1. You know what'd stop lame social engineering by Anonymous Coward · · Score: 5, Insightful
    In Gavin De Beckers book 'The Gift of Fear' he says that an effective way to stop assassins topping off high profile people is not to give them glorious media write ups. Bring 'em down a notch by stating what they are - savages who don't deserve civilization. Bruce Schneier talks about the same thing-publicity attacks. People who want attention. So stop paying attention to them.

    Now, I'm all for making public the attacks but I think we should start bagging out the actual attackers. Cmon, social engineering through an email? Sure it'll fool a few people, and a few people is all you need to bring down a network, but let's patronise these guys. They're fuckin' con men for pete's sake and lame conmen at that. The only people they're tricking is morons. I move for guys like this to be put down at every chance.

    Stop glorifying criminals!

  2. Re:This is why the "double standard" by Anonymous Coward · · Score: 5, Insightful

    The simple rule is to know what you're doing, or, if you don't know what you're doing, have it done by someone you trust. People don't start working on their cars unless they know what they're doing. They have the maintenance done by a mechanic or an experienced friend. Yet somehow we think that computer maintenance should be done by complete ignorants. It's never going to work.

  3. Re:This is why the "double standard" by bigman2003 · · Score: 5, Insightful

    Good point...

    BUT, I work in a small IT department- and we spend about 1/2 of our weekly meeting talking about how 'stupid' these users are.

    Not saying that I don't take part in the conversation...but I keep thinking to myself, "They aren't supposed to know this stuff, it isn't their job, it's OUR job."

    I really hate it when we get on our high-horses and look down at people because they don't know as much about the computer they use as we do. I would hope not, otherwise we would be some weak-ass IT people.

    I'm guilty to, and every IT person I have ever met is just as guilty. But when we need to purchase something, we walk over to the purchasing people and say 'I have no idea what I am doing, but I need to order this thing...' I wonder if when we leave, they all start laughing at us and call us a 'bunch of fucking idiots.'

    I hope so...because we have some real arrogant bastards in IT who really need to realize that nobody else really gives a damn about the difference between right-click and left click...

    --
    No reason to lie.