
Tuesday, January 3, 2006
It may be the new year, but here’s a seemingly age old problem – Microsoft’s Windows operating system is vulnerable to hackers.
You’ve heard that statement so many times before, it’s hardly news. But this may be.
According to anti-virus firm F-Secure, the latest flaw in the product Bill Gates created may be the biggest ever detected, and has the potential to affect millions of users of the O.S. going all the way back to the 1990s.
It first came to light last week, when hackers published the source code for a problem that affects something called the Windows Metafile, a list of commands that can be used to draw graphics on your screen.
But the virus fighting experts say this flaw is different from others because it covers so many different flavours of Windows, and doesn’t require you to do much more than simply visit a webpage, look at an email or read an instant message. It can then put spyware on your machine without you even knowing it.
"The … vulnerability probably affects more computers than any other security vulnerability, ever," states F-Secure’s Mikko Hypponen on the company’s website.
Worse still, Microsoft – which has been aware of the problem since last week – has yet to come up with a patch for the problem. And when hackers published their findings on the net in late December, they gave their malicious finding out to all who might seek to exploit it.
Spyware can leave computers open to a host of problems, including allowing hackers to track where you go and what you type, as well as potentially turning your PC into a ‘zombie’ that sends out thousands of spam emails a day without you even knowing it.
The flaw also has the potential to allow viruses onto your machine, although that hasn’t happened yet.
It’s a pain for consumers but it costs businesses billions of dollars a year to fight it.
And those in the know now say this is a big business in another way. The old concept of the teenager in his bedroom sending out malicious code that replicates itself across the world is all but over.
Instead, hacking has becomes a major tool for organized crime, allowing it to rake in untold billions at the expense of others in a felony that’s almost untraceable.
So what can you do? Until Microsoft issues its patch, not a lot. The Explorer browser is the most vulnerable. Those who use Opera or Firefox will be prompted about running a .wmf file. Only people answering ‘yes’ run the risk of infection.
And you can always practice safe computing by keeping your virus software up to date.
Microsoft has issued a warning urging its millions of users to simply stay away from suspicious websites and not to open emails they’re not sure of. “Users should take care not to visit unfamiliar or untrusted websites that could potentially host the malicious code,” a statement reads.
Which leaves millions pretty much on their own for now. The computer giant hopes to have a fix ready for its next update on January 10th – still a week away.
It’s another black mark for the company, which has made improving its flawed security a cornerstone of recent marketing efforts.
"Microsoft's delay is inexcusable," rails Alan Paller, director of research at computer security group SANS Institute. "There's no excuse other than incompetence and negligence."
But the Redmond, Washington giant responds it has to be sure any patch works, and won't be rushed into talking millions into downloading something that's simply not ready.
Update:The Fix Is InFriday, January 6, 2006
First they claimed they wouldn’t have a fix ready until next week.
Then they added they had to thoroughly test all the possible solutions.
But stung by criticism of what some experts are calling the worst flaw ever detected in Microsoft’s Windows, the company has quickly rushed out a patch that can be downloaded online.
The trouble first started when hackers published the source code that would let others take over your PC through an element that the operating system uses to display images.
Pictures have been used to spread viruses and spyware before, but this one was different – all users were vulnerable because they simply had to visit a tainted web page or open an email to get it, and they wouldn’t even be aware of it.
Worse still, firewalls and anti-virus software could do little to stop the problem.
Microsoft has been roundly criticized for waiting so long to come out with a fix, simply advising users to beware of where they went on the Internet instead.
"Microsoft's delay is inexcusable," fumed Alan Paller of the security group SANS Institute when the full scope of the problem was made public. "There's no excuse other than incompetence and negligence."
The computer giant has been stung by such comments and rushed the patch online. It can be downloaded by
clicking here.Microsoft has been the focal point of hacker attacks for years, leading the firm to promise it would takes steps to improve security. This latest setback may solidify the idea in the mind of users that it still has a long way to go.
Later,
Kenaz