Feds warn of broad Internet attack

Blondie

~*~*~*~<br><font color=blue>This TF always enjoys
Joined
Aug 18, 1999
Messages
17,306
DHS: Hackers could exploit flaw in Windows software


ASSOCIATED PRESS

WASHINGTON, July 31 — Government and industry experts consider brewing hacker activity a precursor to a broad Internet attack that would target enormous numbers of computers vulnerable from a flaw in Windows software from Microsoft Corp.

EXPERTS DESCRIBED AN unusual confluence of conditions that heighten prospects for a serious disruption soon. They cite the high numbers of potential victims and increasingly sophisticated attack tools already tested successfully by hackers in recent days.

An alert distributed Thursday among U.S. government agencies warned of “widespread scanning and exploitation” of victim computers by hackers who were developing “improved and automated exploit tools.”

The Homeland Security Department cautioned Wednesday that it had detected an “Internet-wide increase in scanning” for victim computers. In an unusually ominous alert, it warned the threat could cause a “significant impact” on the Internet.

Experts advised computer users with renewed urgency to apply a free repairing patch that Microsoft has offered on its Web site since July 16, when it acknowledged that the flaw affected nearly all versions of its flagship Windows operating system software.

(MSNBC is a Microsoft-NBC joint venture.)

An attack could come “any day now,” predicted Chris Wysopal of AtStake Inc., a security company in Cambridge, Mass. Another company, Qualys Inc., put the threat at the top of a newly released ranking of the Internet’s most severe vulnerabilities.

Alan Paller of the SANS Institute in Bethesda, Md., said a disruption could be worse by orders of magnitude than previous high-profile attacks — such as the summer 2001 outbreak of the “Code Red” virus — because of the numbers of vulnerable systems.

Security companies guarding government and corporate networks have identified sporadic break-in attempts worldwide using such tools and have monitored hackers in discussion groups and chat rooms exchanging tips about how to improve the effectiveness of their programs.

Applying Microsoft’s repairing patch takes a few moments for home users but is a more daunting challenge for large corporations with tens of thousands of Windows computers.

“People are definitely aggressively trying to patch this,” said Ken Dunham, an analyst at iDefense Inc., an online security company. “But a large rollout may need to take some time.”


Researchers’ biggest fears — that hackers will quickly unleash automated “worm” software that attacks large numbers of computers within minutes — have so far been unrealized.

“Everybody is predicting a widespread event, going from zero to 60 very quickly,” said Dan Ingevaldson, an engineering director for Atlanta-based Internet Security Systems Inc. He estimated the likelihood of a major Internet attack as “closer to imminent than probable.”

Depending on the hackers’ designs, attack tools could be engineered to disrupt Internet traffic by clogging data pipelines, delete important files or steal sensitive documents. Experts cautioned that a particularly clever hacker could leave little trace of an attack.

Oliver Friedrichs, the senior manager for security response at Symantec Corp., predicted that widespread attacks will not occur soon because hackers still need to resolve important glitches in their own attack tools.
Advertisement

“It is a little early,” Friedrichs said. “The exploit needs to be perfected. The effort applied to the exploit is certainly increased, but we’re not sure if that’s indicative of when we might see a widespread threat. People certainly need to be aware of this.”

FBI spokesman Bill Murray said bureau investigators were studying several hacker tools designed so far and were highly concerned about a wide-scale Internet attack. “We implore the private sector — both business and home users — to visit the Microsoft Web site and install the patches and mitigations necessary to prevent this from creating a negative effect on the Internet as a whole,” Murray said.

The Microsoft flaw affects Windows technology used to share data files across computer networks. It involves a category of vulnerabilities known as “buffer overflows,” which can trick software into accepting dangerous commands.


http://www.msnbc.com/news/946460.asp
 
Interesting, Blondie, good reminder to have those Windows updates and patches installed regularly!
 
I remember downloading an update about a week ago, but I think I'm going to go check and make sure it's the right one! Can't hurt to double check! :bounce:
 
Does this apply to us average folks? And how do we protect ourselves, which patch should we be downloading?
 
Go Ad-Free on DISboards
No Google ads. Support the community.
$4.99/month
$49.95/year
Go Ad-Free →

Our IT guys have been pulling their hair out all morning.

Apparently, the system our hospital and university IS being hacked, and it's causing all kinds of problems for all of us.

I've been asked by IT to shut down and re-start my computer several times today. :(
 
Yep, my hospital too Deb.
 
We got hit with a virus at work this afternoon; the IT guys locked everything down for a while but got it cleared up very quickly.
 
Ok heres the question. Which update is it? I found one for Direct X and one for IE 6 service pack. My IE is not 6 its 5.50. So.. do I download the IE 6 service pack into my 5.50? Should I have downloaded IE 6 a long time ago? If I download any of this stuff will it make me loose my bookmarks? :eek: Sorry to sound so tech challenged..but I am. BTW I have Windows ME.
 
IE 6 has been out for well over a year so you should upgrade. (It should actually be IE 6.028) You should not lose any bookmarks as it should just overlay your current version.
 
Ann - If you upgrade to IE6.0, make sure you go back to the uodate site and check for updates one more time. There are a ton of updates that were released for version 6.0
 


Disney Vacation Planning. Free. Done for You.
Our Authorized Disney Vacation Planners are here to provide personalized, expert advice, answer every question, and uncover the best discounts. Let Dreams Unlimited Travel take care of all the details, so you can sit back, relax, and enjoy a stress-free vacation.
Start Your Disney Vacation
Disney EarMarked Producer






DIS Facebook DIS youtube DIS Instagram DIS Pinterest DIS Tiktok DIS Twitter

Add as a preferred source on Google

Back
Top Bottom