New Massive Botnet Building On Windows Hole
CWmike writes "The worm exploiting a critical Windows bug that Microsoft patched with an emergency fix in late October is now being used to build a fast-growing botnet, said Ivan Macalintal, a senior research engineer with Trend Micro. Dubbed 'Downad.a' by Trend (and 'Conficker.a' by Microsoft and 'Downadup' by Symantec), the worm is a key component in a massive new botnet that a new criminal element, not associated with McColo, is creating. 'We think 500,000 is a ballpark figure,' said Macalintal when asked the size of the new botnet. 'That's not as large as some, such as [the] Kraken [botnet], or Storm earlier, but it's... starting to grow.'"
*Bill Gates rubs hands together*
"Excellent... Just excellent... Rise my army, rise up and do my bidding!"
No, and that's obviously Microsoft's fault.
Remember Blaster, which had a full 40 days or something like that before the exploit was seen in the wild. 10 days is obviously not enough lead time. I personally think we should all be given at least 6 months warning for each vulnerability. Then the attack success rate would plummet to 20% from the 70% it seems to be at these days.
One year would be even better. 365 glorious days to decide whether or not to patch! That would be great.
Enabling auto-update implies the user trusts Microsoft to (a) update Windows properly and (b) not steal their bank account and credit card information with each update.
I would say most Windows users do not believe in (a). Some think they know better what updates to install than Microsoft suggests.
A significant number of users do not believe in (b). They have heard so much trash talk about Microsoft that they believe it is a criminal enterprise being operated by the Mafia.
I would say there is no hope for anything good coming from this set of beliefs.
I disable Windows when I do an install of Linux.
Does that mean Macs have 10% of the market share of annoying ass spam networks? Cause they've already got 100% of the annoying and misleading commercials...
Or Just move to Linux, BSD, OSX...
silarulz!
revolves around unscrupulous business tactics and emergency fixes to a dated and uncompetitive product turned fixture by lock-in, an enormous spinning vortex of shit known as a botnet is only natural.
Windows vista and its DRM in and of themselves are a botnet that offer you plugins and upgrades at the expense of your CPU time and sanity much the same way a botnet effectively doles out dickpill adds.
you can hurl your best in-house antivirus at it, but since that was composed by coders flogged to the finish line by marketing, i dont see how thats destined to placate the issue.
Good people go to bed earlier.