Slashdot Mirror


The 12-minute Windows Heist

An anonymous reader writes "Sophos has come up with some pretty interesting research: apparently, there's a 50 percent chance unprotected Windows PCs will be compromised within 12 minutes of going online. Sophos came to that conclusion based on research covering the last six months of virus activity. The company said authors of malware such as spam, viruses, phishing scams and spyware have increased both the volume and sophistication of their assaults, releasing almost 8,000 new viruses in the first half of 2005 and increasingly teaming up in joint ventures to make money. The new-virus figure is up 59 percent on the same period last year."

9 of 497 comments (clear)

  1. Old news by Cromac · · Score: 5, Informative
    This isn't news. There have been reports out for months showing unprotected Windows machines being compromised within a few minutes on cable or dsl connections.

    From 11/29/2004: Unprotected PCs can be hijacked in minutes

  2. Re:Good news everybody! by Doppler00 · · Score: 5, Funny

    My question is, which happens faster, first post, or getting a windows machine infected?

    Just a theoretical question...

  3. Hogwash by AvantLegion · · Score: 5, Funny
    Hogwash. I've been online for over 11 1/2 minutes and I haven't had anCLICK HERE FOR DISCOUNT V1AGR4!!!11

  4. And if you enable... by daveschroeder · · Score: 5, Interesting

    ...the built in Windows XP firewall (enabled by default on SP2 and assuming you don't have any other services enabled or open) and/or have a $30 personal firewall/router, there is a 100% chance you won't get compromised.

    But wait, they're talking about spyware, viruses, and phishing. So, those things can install themselves now?

    Don't get me wrong...viewed by itself, Windows has historically a dismally horrible track record. But a patched Windows XP SP2 machine behind a personal firewall/router with current anti-virus/anti-malware protection can be a secure system. Granted, it's been a long time coming, and it's easy for many users to fall into traps, but this seems like nothing more than a typical scare tactic by an AV vendor.

    Never trust an AV vendor saying the sky is falling.

    1. Re:And if you enable... by ScrewMaster · · Score: 5, Interesting

      Never trust anyone who says the sky is falling if they happen to have a vested interest in it. The day will come (if it hasn't already) where antivirus vendors start releasing homegrown viruses to increase sales. It's already happened in the spyware world.

      Actually, the SOP for government and business here in the U.S. has increasingly fallen into a crisis/scare-tactic mode. That is, if you don't get what you want, simply magnify an actual problem to Biblical proportions (the Bush Administration and the War on Terror), or simply manufacture a crisis (the RIAA/MPAA and the War on P2P) to deflect interest in your own failings. Either way, it seems to work pretty well.

      --
      The higher the technology, the sharper that two-edged sword.
  5. Impressive by dedazo · · Score: 5, Interesting
    And the last time someone "measured" this, it was 23 seconds or something like that.

    And the next time it will be 23 minutes. And so on.

    You could not pay me to put a Windows or Linux machine on my DMZ. They're all behind my $30 NAT router and they can be patched to my heart's content without having to worry about them getting p0wn3d. Oh, and to all you Linux fanboys who are going to be insulted by this - try putting a fresh RH9 (off ISOs) on your DMZ, and let's see how long it lasts.

    --
    Web2.0: I love when people Flickr my cuil and digg my boingboing until my google is reddit and I start to yahoo
  6. Scaremongering by jfengel · · Score: 5, Insightful

    There are attacks which don't require your help; Sasser in particular goes through an open port rather than through Outlook or IE. There are a few others.

    But that's pretty unlikely with a new PC, which presumably comes with the latest service packs. The article is incredibly short on actual data. There's nothing to support their 12-minute average. I get the impression that they chose the scariest headline to support an article which is mostly about phishing attacks, trojans, etc: attacks that require your help.

    So for all I know they're talking about the fact that there are enough attackers that if you throw a Windows ME (or even unpatched XP) box on the Internet, yeah, you're hacked. That says a lot, but not about how insecure Windows is. It says that there are still plenty of computers running hacks like Sasser; if you're not protected against it, you're screwed.

    That's mostly scaremongering, since unless you're installing a very out-of-date Windows, you're protected. You're not protected against new attacks, nor are you protected against many trojans. They're trying to convince you to buy software for that, which is relevant, by using scary but irrelevant numbers.

  7. Re:50% chance? by g-san · · Score: 5, Interesting

    If you want a shocker, sniff your internet connection. Go download ethereal from www.ethereal.com, and open your internet connection with your firewall turned off (make sure your patches are up to date please :). Don't browse, don't do anything. Start a capture, select your PPP interface for a modem or ethernet for a broadband connection, turn on "Update list of packets in real time," and "Automatic scrolling in live capture," and turn off all the name resolution options. Click OK.
    Look for TCP SYN packets to port 135 or 445. You may have to wait a few minutes. That is something trying to make a connection to your machine, ports 135 are the main ports for Windows Networking. Heh, I turned did it while I was typing this and already got a connection attempt to 135. That is most likely a virus on some poor sods unpatched machine, running through IP addresses looking for more systems to infect. If you want to know what all that stuff is, search for it on google. And for all you hackers out there, try writing (connection to port 139 scrolling in background, hehehe) a simple TCP listener in your favorite programming language to see more than just a TCP reset.
    Bad things are living in the internet nowadays.

  8. Comment removed by account_deleted · · Score: 5, Funny

    Comment removed based on user account deletion