Showing posts with label windows 7. Show all posts
Showing posts with label windows 7. Show all posts

Thursday, December 26, 2013

Windows XP: When Microsoft Support for it ends in April, XP will become a Gateway for Hackers into All those XP Machines

Source: PC Pro
The final deadline for Windows XP support will act as a starting pistol for hackers, as they target hundreds of millions of users on unpatched systems.

Microsoft has already granted the 12-year-old OS several stays of execution, but the firm has said it will finally end extended support on 8 April 2014 – despite the fact that XP remains the second-most popular OS, with almost a third of PCs running it.

These hundreds of millions of desktops and laptops will be vulnerable to hackers once XP stops receiving security updates, with Microsoft warning earlier this year that hackers could use patches issued for Windows 7 or Windows 8 to scout for XP exploits.

“The very first month that Microsoft releases security updates for supported versions of Windows, attackers will reverse-engineer those updates, find the vulnerabilities and test Windows XP to see if it shares [them],” wrote Tim Rains, the director of Microsoft’s Trustworthy Computing group.

“If it does, attackers will attempt to develop exploit code that can take advantage of those vulnerabilities on Windows XP,” Rains added. “Since a security update will never become available for Windows XP to address these vulnerabilities, Windows XP will essentially have a zero-day vulnerability forever.”

Tuesday, June 12, 2012

"Flame" Malware Code Traced To Stuxnet, US Govt.

Researchers find a link between the two different pieces of malware, suggesting that the U.S. government may be behind both.
By Mathew J. Schwartz -- InformationWeek
Did the U.S. government commission the recently discovered Flame malware? According to new research, the developers of the Stuxnet and Flame malware families crossed paths--swapping source code at least once--which suggests that the U.S. government didn't just commission Stuxnet, but Flame as well. 

"In 2009, part of the code from the Flame platform was used in Stuxnet," said Alex Gostev, the chief malware researcher at Kaspersky Lab, Monday in a blog post. "We believe that source code was used, rather than complete binary modules," he said, which suggests some degree of collaboration or crossover.


But based on Kaspersky's ongoing teardowns of the Flame malware discovered in late May, he believes that "since 2010, the platforms have been developing independently from each other, although there has been interaction at least at the level of exploiting the same vulnerabilities."

According to published news reports, senior White House officials have said that the the United States led Stuxnet development, working with Israel. Hence if Stuxnet and Flame are related, it suggests that the United States is also behind the complex Flame malware.
 
That Stuxnet credit-taking--read by some as election-year boasting and by others as a direct warning to Iran--has led to charges that government officials mishandled classified information, although many security experts said all signs clearly pointed to the two governments having been behind Stuxnet and the related malware Duqu. Now add Flame to that equation.

But Gostev said there appear to have been different development groups behind the two malware families--each working independently since 2007 or 2008--which he refers to as "Team F" (for Flame) and "Team T" (for Tilded, which is the platform on which Stuxnet and Duqu were built).

"Flame and Tilded are completely different projects based on different architectures and each with their own distinct characteristics," he said. "For instance, Flame never uses system drivers, while Stuxnet and Duqu's main method of loading modules for execution is via a kernel driver."

According to Kaspersky Lab, Stuxnet appears to have been created in the first half of 2009, while Flame had been created by the summer of 2008. "The Stuxnet code of 2009 used a module built on the Flame platform, probably created specifically to operate as part of Stuxnet," said Gostev. That module, which he suspects exploited a then-unknown--a.k.a. zero-day--Windows kernel vulnerability later patched by Microsoft, was apparently removed in 2010. Its removal was likely prompted by Stuxnet's developers having created a new way to allow their malware to propagate, by exploiting a then-unknown Windows shell vulnerability, later patched by Microsoft.

While the two groups of malware developers appear to have shared code, "after 2009, the evolution of the Flame platform continued independently from Stuxnet," said Gostev.

Flame includes numerous attack capabilities, including the ability to spread via Windows Update by using a spoofed digital certificate. As a result, the malware can automatically install itself on targeted computers, providing another computer on the same network had first been compromised.

But Microsoft has been working quickly to patch the certificate bug exploited by Flame. Notably, Microsoft released an update Friday for Windows Server Update Services (WSUS) 3.0 Service Pack 2 (SP2), which according to the release notes "strengthens the WSUS communication channels ... [by] trusting only files that are issued by the Microsoft Update certification authority."

Microsoft is also set to issue an update Tuesday--as part of its monthly Patch Tuesday--that will further update all supported versions of Windows to block Flame. Security experts are recommending that all users install the update as soon as possible, since attackers will likely attempt to use the certificate vulnerability before it becomes widely patched. "Apply the certificate patch released a week ago today if you haven't done so already," said SANS Institute chief research officer Johannes B. Ullrich in a blog post. "This way, no patch signed by the bad certificate should be accepted tomorrow. Patch Tuesday is one of the best dates to launch such an attack, as you do expect patches anyway."

When installing the update, however, do so preferably only if using a trusted environment. "Avoid patches while 'on the road.' Apply them in your home [or] work network whenever possible," said Ullrich. "This doesn't eliminate the chance of a 'man in the middle' (MitM) attack, but it reduces the likelihood."

For users who must update while on the road, perhaps because they travel frequently, always use a VPN connection back to the corporate network, said Ullrich, since hotel networks can be malware and attack hotbeds. "Hotel networks and public hotspots frequently use badly configured HTTP proxies that can be compromised and many users expect bad SSL certificates--because of ongoing MitM attacks," he said.

Wednesday, July 14, 2010

Support for Windows 2000 and Windows XP SP2 comes to an end (2 stories)

By Peter Bright | Ars Technica

Today is the last day that Windows 2000 and Windows XP Service Pack 2 will receive support and patches from Microsoft. Starting tomorrow, Service Pack 3 will be required to receive support and hotfixes for Windows XP.

In the past, the end of support for a service pack would mean that Microsoft would refuse to offer any kind of telephone support or troubleshooting assistance. This policy was relaxed a little in April; limited support will remain available for those organizations sticking with Service Pack 2. However, any hotfixes or security updates will be restricted to Service Pack 3.

Customers on Windows 2000 will not even have this option. The operating system is now out of its extended support phase. This brings an end to any and all hotfixes, security updates, or even paid support options. Fewer than half a percent of Internet-connected machines appear to use Windows 2000, and with the end of support, it is now open season on that minority: Microsoft will take no action to provide fixes for any security issues, regardless of their severity.

***

XP fans get reprieve in form of downgrade rights extension
By Peter Bright | Last updated about 13 hours ago

Downgrade rights have been a long-standing feature of Microsoft's operating system licensing. They allow users to buy a license for the latest version of the operating system, and then use that license with an earlier incarnation. Volume license users have long had a broadly unrestricted right to downgrade; though unsupported, they could choose to run Windows 95 if it suited their needs. OEM licenses, sold with preinstalled copies of the software, also have downgrade rights, but unlike the volume license kind, they tend to be restricted to specific versions.

Windows 7's OEM downgrade rights, available for Windows 7 Professional and Windows 7 Ultimate, were originally due to expire this October. Microsoft has now announced that these end-user downgrade rights are being extended further.

OEMs themselves will have to stop preinstalling downgraded copies of Windows XP on October 22, 2010. However, end-users will now be able to downgrade PCs with OEM installations of Windows 7 Professional and Ultimate to the corresponding version of Windows Vista or Windows XP Professional, and will be allowed to do so for the duration of Windows 7's lifecycle.

Microsoft says that this change is in response to business demands; it would be confusing if some Windows 7-licensed PCs included downgrade rights but others did not. The change in policy means that the licensing conditions will be uniform, and the same conditions will apply regardless of when the machines were purchased.

The company did not explicitly state which lifecycle. Under current rules, OEM availability ends two years after the next operating system is released. Presuming that Windows 8 lands in late 2012 (for a three-year release cycle), that would mean that OEM licenses of Windows 7 would be available until late 2014. Beyond that, customers would have to use volume license downgrade rights.

The supported lifecycle is longer; consumer editions of Windows 7 will receive mainstream support until 2015, and corporate editions until 2020. If this is the lifecycle that OEM downgrade rights are tied to, it would extend downgrade rights to 2015 (for Windows 7 Ultimate) or 2020 (for Windows 7 Professional). Though this interpretation has been widely reported across the Internet, it seems hard to reconcile with Redmond's current stated availability policy.

The chance of a computer bought in 2020 working flawlessly with Windows XP is slim—indeed, even in 2015, Windows XP's hardware support is likely to be problematic—so even if the 2020 date is accurate, it is unlikely to have any practical value.

This extended availability also does not appear to impact the support schedule for the old operating system; Windows XP support is due to expire in April 2014. So not only will the operating system be unlikely to work, it will be insecure, too.

Those businesses dependent on OEM rather than volume licenses will, no doubt, welcome the change. Microsoft's own figures say that three-quarters of businesses still use Windows XP in some capacity, so the ability to buy machines with the right to downgrade will certainly find its uses.

However, Windows XP's dominance is certainly diminishing. Microsoft says that 65 percent of companies either have started their migration to Windows 7 or will do so within six months, rising to 89 percent planning to do so within 24 months—upgrading just in time for the release of Windows 8.

Moreover, the wisdom of buying new hardware just to run Windows XP is increasingly questionable. Microsoft is not going to decide one day that every post-Windows XP operating system was a grave error, and is not going to undo all the changes in those operating systems that cause software and device driver incompatibility. The company has moved on. Going forward, the compatibility situation is only going to get worse: new technology like USB3 and LightPeak will become mainstream, new processor extensions such as Intel's AVX will start to gain traction, and even hard disks might start to forfeit Windows XP compatibility.

Though Microsoft has repeatedly relented, extending Windows XP availability and support, it is sticking to its guns when it comes to the necessity of the platform changes that Windows Vista and Windows 7 have made. If a business absolutely must use Windows XP to run some essential software, Microsoft's solution is virtualization. Any company hoping to stick with the obsolete platform indefinitely is setting itself up for disappointment.