Slashdot Mirror


1 In 3 Windows PCs Still Vulnerable To Worm Attack

CWmike writes "The worm that has infected several million Windows PCs, Downadup or 'Conficker,' is having a field day because nearly a third of all systems remain unpatched 80 days after Microsoft rolled out an emergency fix, security firm Qualys said. Downadup surged dramatically this week and has infected an estimated 3.5 million PCs so far, according to Finnish security company F-Secure Corp. The worm exploits a bug in the Windows Server service used in Windows 2000, XP, Vista, Server 2003, and Server 2008. Qualys' CTO said, 'These slow [corporate] patch cycles are simply not acceptable. They lead directly to these high infection rates.'" This is indicative of why some are calling for Microsoft to rethink Patch Tuesday, as reader buzzardsbay pointed out.

6 of 242 comments (clear)

  1. router by TheSHAD0W · · Score: 5, Insightful

    This is why I recommend everyone have a router installed on their internet connection, even if they have only one PC. Routers inherently block almost all worms.

    1. Re:router by Trevelyan · · Score: 4, Insightful

      You assume that the router has a some firewall, acl or nat set, ie its not inherent. Also this is more for home users. However this worm is doing well in corporate networks, spreading from one co. to another via latops, and so negating any external firewall.

  2. Not Acceptable? by PolyDwarf · · Score: 5, Insightful

    Qualys' CTO said, 'These slow [corporate] patch cycles are simply not acceptable. They lead directly to these high infection rates.'"

    It's also not acceptable that corporate desktops become useless because of an update that MS rolled out that broke mission-critical software.

    There's a reason there's an IT vetting process with patches (fool me once, shame on you... fool me twice, three times, every patch tuesday, shame on me). There's also a reason why those processes take a while. If you disagree with IT workers doing their jobs and making sure that an update won't screw up the network/application/productivity/company, take it up with software vendors and MS, not with the people who are trying to make sure their company stays functioning. Or will you be willing to pay for their time in fixing problems if they apply patches that break things?

  3. How about installing updates? by HerculesMO · · Score: 4, Insightful

    The update was issued in October.

    If you haven't patched, there's no fault of anybody but your own.

    If your car has a recall for a safety belt problem, and you don't get it fixed and get into an accident, is it suddenly the car manufacturer's fault? No.

    And likewise it's not MS's fault if you can't install patches on your OS.

    --
    The price is always right if someone else is paying.
  4. Re:Genuine Advantage Validation by 0prime · · Score: 5, Insightful

    Uhhh as a former student, this seems pretty silly. I haven't had any problems with XP or the Office 2003 Suite at all. What are these people expecting Windows to do, pull their personal info, poll it to Microsoft through WGA, and have Microsoft check College enrollment records?

    I do know of one other reason why people would be afraid of WGA, though.

    --
    I am not a *blank*, but I did stay at a Holiday Inn Express last night.
  5. Re:Get any work done? by Ephemeriis · · Score: 4, Insightful

    Jeez, with virus scanners, several types of automatic updates, and other gadgety things polluting the standard corporate desktop, it is a wonder that people can get any work done on their PCs anyway. Six Inches of Air.

    Corporate desktops aren't that bad. I mean, they can be... But usually there's at least a little oversight. You don't typically see people with eleven different smiley-toolbars in a business... It happens, but not so much.

    Home users, on the other hand, can be a true nightmare. Plugins for various web pages... Piles of downloaded crapware games... IncrediMail... Several different media players and a pile of music or movies... A couple different P2P programs... A couple different malware scanners... I cringe just thinking about it.

    You're right though. Entirely too many different bits of software want to do their own updates. Windows Updates, Office Updates, anti-malware updates, updates for Adobe Reader, updates for Flash, updates for Java, updates for Real Player, updates for HP's drivers and suites, updates for QuickTime and iTunes...

    It's ridiculous. I'll routinely see at least a half-dozen updaters running in the background.

    That's one of the things I really like about most Linux distributions... Generally you've got a single package manager that takes care of everything for you.

    --
    "Work is the curse of the drinking classes." -Oscar Wilde