Microsoft confirms Russian pill-pusher attack on its network

Corrine

Account closed
Local time
6:44 PM
Messages
2,303
Location
Upstate NY
Complete article at Microsoft confirms Russian pill-pusher attack on its network • The Register

The admission came in response to an article The Register published on Tuesday. It reported that two internet addresses belonging to Microsoft were helping to route traffic to more than 1,000 websites that belong to a fraudulent online pharmacy known as the Canadian Health&Care Mall. Microsoft on Wednesday said an investigation of that report confirmed the hijacking was the result of an attack on machines connected to its network.

One of the IPs was involved in a DDoS of Brian Krebs site:
The attackers then told machines they controlled to access a number of non-existent pages at sites that were pointing to the Internet address my hosting provider has assigned to KrebsOnSecurity.com (94.228.133.16). This forced several hundred or thousand machines to direct their traffic at my site, all in an attempt to prevent legitimate visitors from visiting it.

Pill Gang Used Microsoft’s Network in Attack on KrebsOnSecurity.com — Krebs on Security
 

My Computer My Computer

At a glance

Windows 7 & Windows Vista Ultimate
OS
Windows 7 & Windows Vista Ultimate
thanks Corrine !
 

My Computer My Computer

At a glance

W7-Enterprise + WS-2008 (Converted to Worksta...P4 2,4GHz (at 1,8GHz, "slow" RDRAM, only 400M...2GBNVIDIA QUADRO2 PRO 64MB
Computer Manufacturer/Model Number
Dell
OS
W7-Enterprise + WS-2008 (Converted to Workstation)
CPU
P4 2,4GHz (at 1,8GHz, "slow" RDRAM, only 400MHz FSB...)
Motherboard
Intel 850E
Memory
2GB
Graphics Card(s)
NVIDIA QUADRO2 PRO 64MB
Sound Card
Yes
Monitor(s) Displays
Dell 1702FP
Screen Resolution
1280x1024
Hard Drives
Yes
PSU
Yes
Case
Yes
Cooling
Yes
Keyboard
Yes
Mouse
Yes, and i also have Cats...
Internet Speed
University: 100 MBit/s, Home: UMTS 7,2 MBit/s
Other Info
W7 on a DINOSAUR: P2 with 266MHz CPU & 160MB RAM
Thanks Corrine. One thing I found interesting in that article was the last statement in the last paragraph:
...the machines that were compromised were running Linux.
 

My Computer My Computer

At a glance

Windows 7 Profession 64-bitIntel Core i7-860 QuadMushkin 4x2Gb PC12800Gigabyte GTX260 896Mb
Computer Manufacturer/Model Number
BrightWorks Systems B4
OS
Windows 7 Profession 64-bit
CPU
Intel Core i7-860 Quad
Motherboard
Gigabyte P55-UD4P
Memory
Mushkin 4x2Gb PC12800
Graphics Card(s)
Gigabyte GTX260 896Mb
Sound Card
Integrated 7.1 HD Dolby
Monitor(s) Displays
2 Samsung 2220wm-HAS 22"
Screen Resolution
1680 x 1050 | 1680 x 1050
Hard Drives
WD HE 1Tb
PSU
Corsair TX-750W
Case
Ultra M998
Cooling
OEM
Keyboard
MS Wireless Comfort 5000
Mouse
MS Wireless 5000
Internet Speed
Cable and pretty darn fast
Thanks Corrine. One thing I found interesting in that article was the last statement in the last paragraph:
...the machines that were compromised were running Linux.
Now that IS interesting, as Linux PR likes to tell you that their software is unbeatable.
 

My Computer My Computer

At a glance

Windows 7 Professional 64 Bit SP1INTEL DUAL CORE 2.1Ghz4GB DDR3INTEL
Computer Manufacturer/Model Number
HP DV6 1330sa
OS
Windows 7 Professional 64 Bit SP1
CPU
INTEL DUAL CORE 2.1Ghz
Motherboard
N/A
Memory
4GB DDR3
Graphics Card(s)
INTEL
Sound Card
LAPTOP
Monitor(s) Displays
2
Screen Resolution
3200x1080
Hard Drives
250GB
PSU
LAPTOP
Case
LAPTOP
Cooling
LAPTOP
Keyboard
SOLID YEAR 260U
Mouse
USB
Internet Speed
20 MB/S
Thanks Corrine. One thing I found interesting in that article was the last statement in the last paragraph:
...the machines that were compromised were running Linux.

a few lines down in the SAME article:

"We found that two misconfigured network hardware devices in a testing lab were compromised due to human error. Those devices have been removed and we can confirm that no customer data was compromised and no production systems were affected. We are taking steps to better ensure that testing lab hardware devices that are Internet accessible are configured with proper security controls.”

Pasted from <Pill Gang Used Microsoft’s Network in Attack on KrebsOnSecurity.com — Krebs on Security>

but, regardless of operating system, of course you have to configure the computer correctly if it´s going to be secure....
 

My Computer My Computer

At a glance

W7-Enterprise + WS-2008 (Converted to Worksta...P4 2,4GHz (at 1,8GHz, "slow" RDRAM, only 400M...2GBNVIDIA QUADRO2 PRO 64MB
Computer Manufacturer/Model Number
Dell
OS
W7-Enterprise + WS-2008 (Converted to Workstation)
CPU
P4 2,4GHz (at 1,8GHz, "slow" RDRAM, only 400MHz FSB...)
Motherboard
Intel 850E
Memory
2GB
Graphics Card(s)
NVIDIA QUADRO2 PRO 64MB
Sound Card
Yes
Monitor(s) Displays
Dell 1702FP
Screen Resolution
1280x1024
Hard Drives
Yes
PSU
Yes
Case
Yes
Cooling
Yes
Keyboard
Yes
Mouse
Yes, and i also have Cats...
Internet Speed
University: 100 MBit/s, Home: UMTS 7,2 MBit/s
Other Info
W7 on a DINOSAUR: P2 with 266MHz CPU & 160MB RAM
Thanks Corrine. One thing I found interesting in that article was the last statement in the last paragraph:
...the machines that were compromised were running Linux.
Now that IS interesting, as Linux PR likes to tell you that their software is unbeatable.

Linux IS safe.

but Linux is actually not an operating system, Linux is only the kernel.
when you package the kernel with other software you get a "Linux-distribution", an Operating System like fx. Debian, Ubuntu, Suse etc.

but, regardless of operating system, of course you have to configure the computer correctly if it´s going to be secure....

read my previous post above. ↑


ps. if you want to try a Linux-system, then i recommend Ubuntu or one of it´s variants, Kubuntu / Xubuntu....
i´ve tried several Linux-systems and Kubuntu is one of my favourites together with Debian.
a brand new version (10.10 was relased just a few days ago, on 101010 (a nice "BINARY" date)
;):D
(October 10 2010)
ds.
 
Last edited:

My Computer My Computer

At a glance

W7-Enterprise + WS-2008 (Converted to Worksta...P4 2,4GHz (at 1,8GHz, "slow" RDRAM, only 400M...2GBNVIDIA QUADRO2 PRO 64MB
Computer Manufacturer/Model Number
Dell
OS
W7-Enterprise + WS-2008 (Converted to Workstation)
CPU
P4 2,4GHz (at 1,8GHz, "slow" RDRAM, only 400MHz FSB...)
Motherboard
Intel 850E
Memory
2GB
Graphics Card(s)
NVIDIA QUADRO2 PRO 64MB
Sound Card
Yes
Monitor(s) Displays
Dell 1702FP
Screen Resolution
1280x1024
Hard Drives
Yes
PSU
Yes
Case
Yes
Cooling
Yes
Keyboard
Yes
Mouse
Yes, and i also have Cats...
Internet Speed
University: 100 MBit/s, Home: UMTS 7,2 MBit/s
Other Info
W7 on a DINOSAUR: P2 with 266MHz CPU & 160MB RAM
You could use the same argument about kernels with Windows then. That's kind of like saying a car without the body is not a car. I think dune buggy owners would disagree. Note the opening sentence from the Linux Home Page at Linux.org,
Linux is a free Unix-type operating system...
Or Linux.com
Linux is, in simplest terms, an operating system.
Linux IS safe.
:huh: No it's not! NO operating system is 100% safe. Think Linux is free from malware? Think again; it's been hacked. Even going back to 2001, there has been malware targeting it as seen in these articles, F-Secure Computer Virus Information Pages: Adore and Bug Watch: Is Linux safe from attack? 17 Apr 2001.

I also note that compromised computers are always, or at least 99.9% of the time, the fault of human error. The human either failed to keep their system updated, patched, scanned and blocked, or he or she failed to avoid risky behavior, like illegal P2P filesharing - a known distribution point badguys use to release their latest code.
 

My Computer My Computer

At a glance

Windows 7 Profession 64-bitIntel Core i7-860 QuadMushkin 4x2Gb PC12800Gigabyte GTX260 896Mb
Computer Manufacturer/Model Number
BrightWorks Systems B4
OS
Windows 7 Profession 64-bit
CPU
Intel Core i7-860 Quad
Motherboard
Gigabyte P55-UD4P
Memory
Mushkin 4x2Gb PC12800
Graphics Card(s)
Gigabyte GTX260 896Mb
Sound Card
Integrated 7.1 HD Dolby
Monitor(s) Displays
2 Samsung 2220wm-HAS 22"
Screen Resolution
1680 x 1050 | 1680 x 1050
Hard Drives
WD HE 1Tb
PSU
Corsair TX-750W
Case
Ultra M998
Cooling
OEM
Keyboard
MS Wireless Comfort 5000
Mouse
MS Wireless 5000
Internet Speed
Cable and pretty darn fast
Back
Top