Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Government, industry experts anxious over possible Internet attack [Target: Microsoft Windows]
Associated Press | July 31, 2003 | TED BRIDIS

Posted on 07/30/2003 10:58:50 PM PDT by HAL9000

WASHINGTON (AP) -- Government and industry experts are increasingly concerned about brewing hacker activity they consider a precursor to a broad Internet attack that will target a serious flaw in Windows software from Microsoft Corp.

Experts are advising computer users with renewed urgency to apply a free repairing patch that Microsoft has offered on its Web site since July 16, when it acknowledged that the flaw affected nearly all versions of its flagship Windows operating system software.

The Homeland Security Department cautioned Wednesday that hackers in recent days have successfully tested new tools to seize control of such vulnerable computers over the Internet, stealing data, deleting files or eavesdropping on e-mails. The government also said it had detected an "Internet-wide increase in scanning" for victim computers.

Security companies guarding government and corporate networks have identified sporadic break-in attempts worldwide using such tools and monitored hackers in discussion groups and chat rooms exchanging tips about how to improve the effectiveness of their programs.

Applying Microsoft's repairing patch takes a few moments for home users but is a more daunting challenge for large corporations with tens of thousands of Windows computers -- leading to a race against hackers for frazzled computer administrators.

"People are definitely aggressively trying to patch this," said Ken Dunham, an analyst at iDefense Inc., an online security company. "But a large rollout may need to take some time."

Researchers' biggest fears -- that hackers will quickly unleash automated "worm" software that attacks large numbers of computers within minutes -- have so far been unrealized. Although a major hacker convention, known as "DefCon," takes place this week in Las Vegas, experts said an attack could be launched within days, weeks or months.

"Everybody is predicting a widespread event, going from zero to 60 very quickly," said Dan Ingevaldson, an engineering director for Atlanta-based Internet Security Systems Inc. He estimated the likelihood of a major Internet attack as "closer to imminent than probable."

Depending on the hackers' designs, attack tools could be engineered to disrupt Internet traffic by clogging data pipelines, deleting important files or stealing sensitive documents. Experts cautioned that a particularly clever hacker could leave little trace of an attack.

Oliver Friedrichs, the senior manager for security response at Symantec Corp., predicted that widespread attacks won't occur soon because hackers still need to resolve important glitches in their own attack tools.

"It is a little early," Friedrichs said. "The exploit needs to be perfected. The effort applied to the exploit is certainly increased, but we're not sure if that's indicative of when we might see a widespread threat. People certainly need to be aware of this."

FBI spokesman Bill Murray said bureau investigators were studying several hacker tools designed so far and were highly concerned about a wide-scale Internet attack. "We implore the private sector -- both business and home users -- to visit the Microsoft Web site and install the patches and mitigations necessary to prevent this from creating a negative effect on the Internet as a whole," Murray said.

The Microsoft flaw affects Windows technology used to share data files across computer networks. It involves a category of vulnerabilities known as "buffer overflows," which can trick software into accepting dangerous commands. Four Polish researchers who call themselves the "Last Stage of Delirium Research Group" discovered the Windows problem and reported details to Microsoft.

"We know it's possible to write a worm for it. We don't know whether a worm will be written for it," said Steve Lipner, a senior Microsoft security executive. "It's certainly one (flaw) that we look at and say, 'Gee, we'd really like everybody to put that patch on."'

Citing the flaw, Internet Security Systems previously raised its alert level to its second notch, reflecting "increased vigilance." The company operates an early warning network for the technology industry, the Information Technology Information Sharing and Analysis Center.



TOPICS: News/Current Events; Technical
KEYWORDS: cybersecurity; hackers; lowqualitycrap; microsoft; windows

1 posted on 07/30/2003 10:58:52 PM PDT by HAL9000
[ Post Reply | Private Reply | View Replies]

To: HAL9000
Could someone put a link to the website for getting the patch? (I am a computer illiterate but trying to learn more.)
2 posted on 07/30/2003 11:08:11 PM PDT by First Amendment
[ Post Reply | Private Reply | To 1 | View Replies]

To: pram
IF YOU LIKE YOUR DATA (any files on you computer) BACK IT UP!! Prior to doing any updates. Also, make sure that you know your passwords / user names for sites that you go to (in case something bad happens). THAT is the reason Network administrators take so long to apply service packs, and patches to windows machines - because they want to find out if bad stuff happens, before they themselves apply the patches (usually involves a lot of testing or time to allow others to apply and get burned).

go to:

http://v4.windowsupdate.microsoft.com/en/default.asp

There should be a link there that says "Scan for Updates".
Click on that link, and then apply the patches that show up. Do the critical ones first.
3 posted on 07/30/2003 11:16:39 PM PDT by NotQuiteCricket (www.strangesolutions.com <<< Made in USA)
[ Post Reply | Private Reply | To 2 | View Replies]

To: NotQuiteCricket
Thanks - I'll try tomorrow when my brain shows up for duty.
4 posted on 07/31/2003 1:19:42 AM PDT by First Amendment
[ Post Reply | Private Reply | To 3 | View Replies]

To: NotQuiteCricket
I rarely have problem's with Security Patches, Service Pack's on the other hand, best to let other's out the bug's! Blackbird.
5 posted on 07/31/2003 1:55:05 AM PDT by BlackbirdSST
[ Post Reply | Private Reply | To 3 | View Replies]

To: HAL9000; pram; NotQuiteCricket; BlackbirdSST
Invitation to Visit:

FR's - Computer Central - Webpage -(Revised! again)
FR Thread - Welcome to "Computer Central"! - Discussion Thread

6 posted on 07/31/2003 2:13:28 AM PDT by Computer Central (Visit FR's "Computer Central"-(Revised!) - http://www.freerepublic.com/~computercentral/)
[ Post Reply | Private Reply | To 3 | View Replies]

To: NotQuiteCricket
BUMP
7 posted on 08/08/2003 9:26:44 AM PDT by GrandMoM ("Vengeance is Mine , I will repay," says the Lord.)
[ Post Reply | Private Reply | To 3 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson