ABC Money
Home

Microsoft: Attacks on Windows flaw rise


Published :
Sat, 31 Mar 2007 01:02
By : Agencies
Print this Story


AddThis Social Bookmark Button

SEATTLE (AP) - Hackers stepped up attacks Friday on computers running some versions of Windows, a day after Microsoft disclosed a hole related to the mouse cursor. Microsoft Corp. sent out a security advisory Thursday warning customers that a vulnerability in '.ani' files -- used to change the cursor into an hourglass while a program works, or into a dancing animal or other animation on specially designed Web sites -- was allowing hackers to break into computers and install malicious software.

'Overnight we did see the attacks change from limited and targeted attacks to slightly more, but do still categorize it as a limited attack,' said Mark Miller, director of the software maker's security response group.

The so-called zero-day attack, a vulnerability that is discovered before Microsoft has a chance to fix the problem, is aimed at PCs running Windows Vista, the new operating system that the company has touted as its most secure. The hole has also been found on Windows 2000 Service Pack 4, Windows XP Service Pack 2 and some versions of Windows Server 2003.

Once hackers have access to a computer, they can install any number of nasty programs -- ones that steal passwords or record keystrokes, which the hackers could then sell to identity thieves.

Microsoft first learned of the vulnerability in December, and has been working on a patch since, Miller said. He did not say whether it would be distributed on its own or as part of a scheduled update.

On Wednesday, security software vendor McAfee Inc. saw a post on a Chinese message board indicating hackers were planning to exploit the hole, which set Microsoft's security advisory in motion.

'It is important to note that while we do think Vista is the most secure operating system released, no software is 100 percent secure,' Miller said.

Computer users could end up with a malicious program on their PC after a Web browsing session and not know it, said Craig Schmugar, a virus researcher for McAfee Avert Labs, the research arm of McAfee.

So far, he said, attacks have been limited to Web surfing with Internet Explorer versions 6 or 7. Firefox, the open-source browser from Mozilla, does not yet seem vulnerable. While Microsoft urged people to be extremely cautious with e-mail, security companies said they have not seen any instances of attacks via e-mail.

While it's hard to tell what hackers will do once they have access to a computer, a group of Chinese hackers may be plotting to steal login information for the wildly popular multi-player video game, World of Warcraft. People who buy the stolen login information can profit by selling items inside the game world, said Ken Dunham, director of the rapid response team at iDefense, the research division of VeriSign Inc.

Dunham said his team learned of the plan on a Chinese hacker message board.

Copyright 2007 Associated Press. All rights reserved. This material may not be published, broadcast, rewritten, or redistributed.




Share on


 You Might Like
China's Lenovo to pre-load Microsoft Windows Live on PCs sold worldwide
Attacks on Windows flaw increase
+
Apple: iTunes users should wait on Vista
Apple: iTunes users should wait on Vista

Comment on this Article
Comment:
Title:
Name:
Please Enter
 
Here
  

 Search News

 Look For
Business
Credit cards
Finance
Loans
Money
Mortgages

 
 Stock Quotes *
SYMBOL
LAST
CHANGE
DOW JONES
8419.09
+270.00 ( 3.31 %)
NASDAQ
1449.80
+51.73 ( 3.63 %)
FTSE 100
4122.86
+57.37 ( 1.41 %)

SYMBOL ( 2008-12-02 )
LAST
CHANGE
RECKITT BENCKISER ( 11:35am )
2684.00
+70.00 ( 2.69 %)
ASTRAZENECA ( 11:35am )
2475.00
+55.00 ( 2.31 %)
BRITISH AMERICAN TOBACCO ( 11:35am )
1651.00
+51.00 ( 3.22 %)
CARNIVAL ( 11:35am )
1347.00
+51.00 ( 4.02 %)
ROYAL DUTCH SHELL-B ( 11:35am )
1653.00
+47.00 ( 2.98 %)

SYMBOL ( 2008-12-02 )
LAST
CHANGE
EXXON MOBIL CORP ( 4:02pm )
77.61
+3.30 ( 4.37 %)
IBM ( 4:01pm )
79.84
+2.94 ( 3.78 %)
JP MORGAN CHASE CO ( 4:01pm )
28.53
+2.41 ( 9.08 %)
GEN ELECTRIC CO ( 4:02pm )
17.61
+2.11 ( 13.07 %)
MERCK CO INC ( 4:02pm )
26.68
+1.83 ( 7.07 %)

SYMBOL ( 2008-12-02 )
LAST
CHANGE
ARDEN GROUP INC ( 4:00pm )
135.77
+11.04 ( 8.69 %)
DIAMOND HILL INV ( 4:00pm )
56.67
+10.42 ( 21.37 %)
GOOGLE ( 4:00pm )
275.11
+9.12 ( 3.37 %)
AMER NATL INS CO ( 4:00pm )
69.87
+8.96 ( 14.38 %)
ATRION CP ( 4:00pm )
95.29
+8.28 ( 9.10 %)

Gainers & Losers
Dow Jones
Euro Stoxx 50
FTSE 100
FTSE 250
FTSE AIM
FTSE ALL
Nasdaq

 Portfolio Manager

You must log in to access this area of the site. If you are not a registered user click here to sign up for instant access!


 Finance Explained

Money making ideas

Save money

Money management
Savings accounts
Investing money
Share dealing
Stock broker
Forex currency trading
Pension plans
Functions of Money

(c) 2007 ABCmoney.co.uk, All Rights Reserved
*ABCMoney.co.uk does not guarantee the accuracy of any share prices or stock quotations displayed. These are not real time quotes; all are delayed by at least twenty minutes and are for information purposes only.