Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Internet under attack by zombie computers
UPI ^ | 1/7/07 | Unattributed

Posted on 01/07/2007 6:56:27 PM PST by Huntress

click here to read article


Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-8081-89 last
To: N3WBI3
>> Mac OS-X is a BSD UNIX variant, which pre-dates Linux by decades.

> I dont know if I would call 13 years 'Decades' ;)

That period (I mark it from about 1977, the first BSD distro, until about 1993, when the first thing that might be called a Linux distro appeared) might have been only 16 chronological years, but it was like 30 in any other industry. Consider the history of the development of the railroad, car, airplane, from novelty to solid part of the social and business world. All took much longer. Computers, small ones in particular, went from almost nothing to life-essential.

How time flies when you're having fun.

(BTW, if you wish to date to 1991, when Torvalds announced his kernel, you'd then also have to go back to 1974 when the first BSD system got underway... which is about the same interval. Either way, I grant it isn't over 20 years. It just seemed that way...)

81 posted on 01/08/2007 3:20:58 PM PST by dayglored (Listen, strange women lying in ponds distributing swords is no basis for a system of government!)
[ Post Reply | Private Reply | To 72 | View Replies]

To: driftdiver
The link I posted had one case of 12,000 bad apples in 45 minutes.

Can't you read? The link you posted had 12,000 bad WINDOWS SERVERS in 45 minutes!

BlackICE Firewall runs ONLY ON WINDOWS. The Witty Worm infected WINDOWS COMPUTERS not Macs.

82 posted on 01/08/2007 3:25:29 PM PST by Swordmaker (Remember, the proper pronunciation of IE is "AAAAIIIIIEEEEEEE!)
[ Post Reply | Private Reply | To 79 | View Replies]

To: Swordmaker

"Can't you read? The link you posted had 12,000 bad WINDOWS SERVERS in 45 minutes!"

Yes I can read but evidently you can't. The story is about how the small population of apple machines doesn't make them immune. Those were apple's.


83 posted on 01/08/2007 3:47:40 PM PST by driftdiver
[ Post Reply | Private Reply | To 82 | View Replies]

To: driftdiver; zeugma
Yes I can read but evidently you can't. The story is about how the small population of apple machines doesn't make them immune. Those were apple's.

The story was offering proof that virus writers HAD INDEED written a virus attacking a very small population of vulnerable computers, thereby showing that "Security by Obscurity," is not an adequate explanation for Mac OS X's seeming immunity to malware.

It pointed out that a small population of approximately 12,000 Microsoft Windows computers running a firewall provided by Internet Security Systems (ISS), BlackICE Firewall, which was found to have an exploitable vulnerability. ISS does not make Macintosh software.

Microsoft Windows computers "protected" by BlackICE were infected by the Witty Worm virus even though ISS had provided a patch for the vulnerability a couple of weeks before the Witty Worm was released into the wild because 12,000 of them didn't bother to install the patch.

Every single vulnerable ISS BlackICE "protected" MIcrosoft Windows computer was infected within 45 minutes of the Witty Worm's release, regardless of where they were on the internet!

Symantec has this to say about the Witty Worm:

Discovered: March 20, 2004
Updated: March 22, 2004 03:11:14 PM PST
Also Known As: W32/Witty.worm [McAfee], WORM_WITTY.A [Trend]
Type: Worm
Infection Length: 660 bytes, may vary
Systems Affected: Windows 2000, Windows 95, Windows 98,
Windows Me, Windows NT, Windows Server 2003, Windows XP

W32.Witty.Worm uses a vulnerability in ICQ parsing by ISS products.
The worm sends itself to multiple IP addresses using UDP source port
4000 and a random destination port. The worm resides in memory only,
and does not create files on an infected computer. The worm also has a
payload that overwrites random sectors of a random hard disk.

Note: If your computer is not running a vulnerable version of one of the
affected products, then you will not be infected.

Products affected by this vulnerability are listed below:

BlackICE - Agent for Server 3.6 ebz, ecd, ece, ecf
BlackICE PC Protection 3.6 cbz, ccd, ccf
BlackICE Server Protection 3.6 cbz, ccd, ccf
RealSecure - Network 7.0, XPU 22.4 and 22.10
RealSecure Server Sensor 7.0 XPU 22.4 and 22.10
RealSecure Desktop 7.0 ebf, ebj, ebk, ebl
RealSecure Desktop 3.6 ebz, ecd, ece, ecf
RealSecure Guard 3.6 ebz, ecd, ece, ecf
RealSecure Sentry 3.6 ebz, ecd, ece, ecf

If you are running a product that has the vulnerability, which the worm
uses, we recommend that you apply the relevant patch as soon as possible.

Patches for this vulnerability are available at http://www.iss.net/download/."
- Source.

Now, driftdriver, do you see Macintosh or Apple listed ANYWHERE on that list?

84 posted on 01/08/2007 4:27:51 PM PST by Swordmaker (Remember, the proper pronunciation of IE is "AAAAIIIIIEEEEEEE!)
[ Post Reply | Private Reply | To 83 | View Replies]

To: Swordmaker

Thanks for the additional Witty information. :-)


85 posted on 01/08/2007 7:56:52 PM PST by zeugma (If the world didn't suck, we'd all fall off.)
[ Post Reply | Private Reply | To 84 | View Replies]

To: zeugma; driftdiver

Do you think it will get through Drift's snow job?


86 posted on 01/08/2007 8:02:21 PM PST by Swordmaker (Remember, the proper pronunciation of IE is "AAAAIIIIIEEEEEEE!)
[ Post Reply | Private Reply | To 85 | View Replies]

To: Sunnyflorida; Swordmaker
I am happy that you too answered to Common Tater about his uniformed posting. As I mentioned to a FReeper pal, it amazes me how so many think of themselves as IT gurus just because they can successfully send emails with attachments.

Tater's comment brings to mind an old Nietzche saying: "Better to know nothing than half-know many things!"
87 posted on 01/09/2007 4:11:32 AM PST by rxgalfl
[ Post Reply | Private Reply | To 67 | View Replies]

To: Swordmaker
Do you think it will get through Drift's snow job?

Nope. Unknown unknowns are the most dangerous kind.

88 posted on 01/09/2007 7:44:01 AM PST by zeugma (If the world didn't suck, we'd all fall off.)
[ Post Reply | Private Reply | To 86 | View Replies]

To: Huntress
Uhhhhhhhhhh........

Regurgitated worm stories are so much more interesting the 157th time.....

89 posted on 01/09/2007 7:45:42 AM PST by Cold Heat ("Ward!.........Go easy on the beaver"!)
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-8081-89 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson