Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Is Windows inherently more vulnerable to malware attacks than OS X?
Infoworld ^ | August 22, 2006 | Tom Yager

Posted on 08/24/2006 12:31:17 AM PDT by Swordmaker

It took an attack on a Windows production server, not devotion to Apple, to put that provocative title on this entry.

On August 13 at 3:04 AM, a Windows server that I've been running for all of two weeks--it just replaced an Xserve G5--was attacked by a new strain of malware. This worm/trojan/backdoor/proxy/IRCbot/DDOS agent shared some characteristics with a known exploit, but it went well beyond what was described. I believed at the time of the infection, and even more strongly now, that this exploit's latent damage potential has been underestimated. I view the terse and vague update on the CERT site regarding the less tenacious strain of this beast with a sense of foreboding.

The attack I encountered occasioned a re-examination of a common question: Is Windows more vulnerable to malware than OS X? I've encountered no clearer or more definitive proof point than this attack. To set the stage, I'll describe the malware's methods. The only victim requirement is that a Windows system--client or server from 2000 and XP on up, 32 and 64-bit--be on an Internet-accessible IP address and listening for socket requests to the Windows Server service. The attacker connects to the Windows Server service, overflows a fixed-length buffer and tricks the service into executing code contained in a portion of the buffer. The attack edits the Registry to turn off the Windows firewall and packet filter, disables notifications that you're running with reduced security, and opens your system to anonymous access. It then uses the Registry to insert plant a pair of Windows services that run with SYSTEM privileges. Processes owned by that pseudo-user can literally do anything, unchecked, to the local machine. The malware services launch and announce your exploited system's presence via IRC and IM. After that, an IRC bot or (sub)human driver can make your system do whatever it wants, including making it a nest for more malware. In my case, it was so eager to scan the Internet for other systems to infect that it locked my server's CPUs at 100 percent and gave itself away.

To nail itself in place, two services watch for and regenerate each other even if their files are deleted. The malware adds an entry to Administrator's login script, and it watches for a privileged invocation of Windows Explorer (like Finder) and attaches a malicious thread to that.

I've been giving it great deal of thought, and I came up with a reasons pointing to the likelihood that Windows is at greater risk of catastrophic attacks. It's not easy reading, but it was either this dense packing or a book-length blog post.

Why this can't happen under OS X:

So, after all this, do I have enough to judge Windows inherently more vulnerable to severe malware than OS X? I do.

I've been writing about these shortcomings for years, and it always traces back to Microsoft's untenable policy of maintaining gaps in Windows security to avoid competing with 3rd party vendors and certified partners. Apple's taking a different approach: What users need is in the box: Anti-virus, anti-spam, encryption, image backup and restore, offsite safe storage through .Mac, and launchd. Pretty soon any debate with Microsoft over security can be ended in one round when Apple stands up, says "launchd," and sits back down.


TOPICS: Business/Economy; Computers/Internet
KEYWORDS: lowqualitycrap
Navigation: use the links below to view more comments.
first 1-2021-4041-46 next last

1 posted on 08/24/2006 12:31:19 AM PDT by Swordmaker
[ Post Reply | Private Reply | View Replies]

To: 1234; 6SJ7; Action-America; af_vet_rr; afnamvet; Alexander Rubin; anonymous_user; ...
Infoworld article on why OS X is more secure than Windows... with Chapter and Verse... PING!

If you want on or off the Mac Ping List, Freepmail me.

2 posted on 08/24/2006 12:32:56 AM PDT by Swordmaker (Remember, the proper pronunciation of IE is "AAAAIIIIIEEEEEEE!")
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

Browsing the Apple web site, came across these:

http://www.apple.com/science/profiles/colsa/
http://www.apple.com/itpro/profiles/army/


3 posted on 08/24/2006 12:56:04 AM PDT by coconutt2000 (NO MORE PEACE FOR OIL!!! DOWN WITH TYRANTS, TERRORISTS, AND TIMIDCRATS!!!! (3-T's For World Peace))
[ Post Reply | Private Reply | To 2 | View Replies]

To: Swordmaker

One more:

http://www.apple.com/itpro/profiles/echostorm/


4 posted on 08/24/2006 1:01:31 AM PDT by coconutt2000 (NO MORE PEACE FOR OIL!!! DOWN WITH TYRANTS, TERRORISTS, AND TIMIDCRATS!!!! (3-T's For World Peace))
[ Post Reply | Private Reply | To 2 | View Replies]

To: Swordmaker

3 things we can count on paying taxes and Swordmaker posting trash about windows and great articles about Apple.


5 posted on 08/24/2006 1:05:05 AM PDT by Echo Talon
[ Post Reply | Private Reply | To 1 | View Replies]

To: Echo Talon
3 things we can count on paying taxes and Swordmaker posting trash about windows and great articles about Apple.

Seems to me that Infoworld published this article... not exactly an Apple cheerleader. Is there anything in here that is false?

6 posted on 08/24/2006 1:26:40 AM PDT by Swordmaker (Remember, the proper pronunciation of IE is "AAAAIIIIIEEEEEEE!")
[ Post Reply | Private Reply | To 5 | View Replies]

To: Swordmaker

dont know, the whole thing could have been made up... did you witness it?


7 posted on 08/24/2006 1:32:20 AM PDT by Echo Talon
[ Post Reply | Private Reply | To 6 | View Replies]

To: Echo Talon

That five-letter "t" word is spelled "truth".


8 posted on 08/24/2006 1:32:46 AM PDT by John Valentine
[ Post Reply | Private Reply | To 5 | View Replies]

To: John Valentine

or trash


9 posted on 08/24/2006 1:38:51 AM PDT by Echo Talon
[ Post Reply | Private Reply | To 8 | View Replies]

To: Echo Talon
dont know, the whole thing could have been made up... did you witness it?

Ah, solipsism - I don't know that YOU exist, Echo...

10 posted on 08/24/2006 1:39:56 AM PDT by Swordmaker (Remember, the proper pronunciation of IE is "AAAAIIIIIEEEEEEE!")
[ Post Reply | Private Reply | To 7 | View Replies]

To: Swordmaker

if a tree falls in the woods and nobody is around.....


11 posted on 08/24/2006 1:47:17 AM PDT by Echo Talon
[ Post Reply | Private Reply | To 10 | View Replies]

To: Echo Talon

Now there's that same mis-spelling again.


12 posted on 08/24/2006 1:53:01 AM PDT by John Valentine
[ Post Reply | Private Reply | To 9 | View Replies]

To: John Valentine

oh boy an anal English teacher..


13 posted on 08/24/2006 1:54:09 AM PDT by Echo Talon
[ Post Reply | Private Reply | To 12 | View Replies]

To: Echo Talon
if a tree falls in the woods and nobody is around.....

The tree doesn't know if you exist, either...

14 posted on 08/24/2006 2:01:38 AM PDT by Swordmaker (Remember, the proper pronunciation of IE is "AAAAIIIIIEEEEEEE!")
[ Post Reply | Private Reply | To 11 | View Replies]

To: Swordmaker
ya never know... :) here
15 posted on 08/24/2006 2:06:43 AM PDT by Echo Talon
[ Post Reply | Private Reply | To 14 | View Replies]

To: Echo Talon

I assume that's an abbreviation of "analytical".


16 posted on 08/24/2006 2:06:59 AM PDT by John Valentine
[ Post Reply | Private Reply | To 13 | View Replies]

To: Echo Talon
ya never know... :) here

The Hills don't know if you exist, either...

OR me...

17 posted on 08/24/2006 2:08:16 AM PDT by Swordmaker (Remember, the proper pronunciation of IE is "AAAAIIIIIEEEEEEE!")
[ Post Reply | Private Reply | To 15 | View Replies]

To: John Valentine
here
choose one.
18 posted on 08/24/2006 2:09:59 AM PDT by Echo Talon
[ Post Reply | Private Reply | To 16 | View Replies]

To: Swordmaker

but the Lord does. :D


19 posted on 08/24/2006 2:11:13 AM PDT by Echo Talon
[ Post Reply | Private Reply | To 17 | View Replies]

To: Echo Talon
"...if a tree falls in the woods and nobody is around..."

...does Echo Talon say it didn't fall...:)

20 posted on 08/24/2006 3:40:49 AM PDT by rlmorel (Islamofacism: It is all fun and games until someone puts an eye out. Or chops off a head.)
[ Post Reply | Private Reply | To 11 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-46 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson