Results 1 to 2 of 2

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

  1. #1
    Senior Member JohnDoe2's Avatar
    Join Date
    Aug 2008
    Location
    PARADISE (San Diego)
    Posts
    99,040

    Microsoft patches bug 'used by Chinese hackers'

    10 February 2015 Last updated at15:15 ET

    Microsoft patches bug 'used by Chinese hackers'

    By Mark Ward Technology correspondent, BBC News


    Adobe's Flash software was used to try and compromise vulnerable machines


    Related Stories




    Microsoft has released a patch to close a bug exploited by hackers, who targeted US military and government networks.

    The flaw was used to compromise Windows PCs that visited sites seeded with other malware created by the group.


    Popular news site Forbes was one victim unwittingly enrolled into the cyber-espionage campaign.


    Security systems on US military networks ultimately foiled attempts to steal data, said one expert.


    "It's fairly brazen for a Chinese cyber-espionage group to use such a public site," said John Hultquist from iSight Partners, which said it had traced the attack back to a group called Codoso.


    Data grabbing

    Forbes' site was compromised via a software add-on, or widget, that made use of a version of Adobe's Flash software, which in turn was vulnerable to an exploit believed to have been created by Codoso.

    This was paired with a separate vulnerability that the hackers used to takeover Windows machines.


    The booby-trapped widget was present on the Forbes site between 28 November and 1 December, 2014, said a spokeswoman for the news site.


    "Forbes took immediate actions to remediate the incident," said the spokeswoman.


    "The investigation has found no indication of additional or ongoing compromise nor any evidence of data exfiltration."


    No group had claimed responsibility for the attack, she added.


    Mr Hultquist told the BBC that iSight had been tracking Codoso since 2010 and was confident it was behind the attack.


    Additional intelligence about its origin has been provided by security company Invincea which spotted machines infected via the Forbes exploit on military networks.


    Once it took hold on a Windows machine the Codoso malware sought to log what software the machine ran and to map networks to find other machines to compromise, Mr Hultquist explained


    "It's all about land and expand," he said.


    "They want to get in and stay in and be as persistent as possible and gather intelligence over a long period of time."


    No data was stolen from official US networks using this exploit, said Norm Laudermilch from Invincea.


    However, he said, analysis of the malware showedthat it had been used to get at various other sites and the sheer number of people visiting Forbes would suggest a lot had been caught out by it.


    Adobe patched the Flash bug on 9 December and Microsoft has now moved to close the other loophole found and exploited by Codoso.


    Mr Hultquist said the evidence suggested Codoso was no common-or-garden cybercrime group.


    "There are different motivations for hacker groups, but this one is about espionage and that, by definition, is not about making money," he said.


    China was not alone in setting up such groups and trying to gather data by hacking, he added.


    "We've seen dozens of them," he said.


    "It's a very inexpensive way to get an advantage over your adversaries."

    http://www.bbc.co.uk/news/technology-31381892
    NO AMNESTY

    Don't reward the criminal actions of millions of illegal aliens by giving them citizenship.


    Sign in and post comments here.

    Please support our fight against illegal immigration by joining ALIPAC's email alerts here https://eepurl.com/cktGTn

  2. #2
    Senior Member JohnDoe2's Avatar
    Join Date
    Aug 2008
    Location
    PARADISE (San Diego)
    Posts
    99,040
    Microsoft has also killed the Weather Desktop Gadget, and some other desktop gadgets to block flaws that allow access to hackers in Window 7 and Windows 8.
    NO AMNESTY

    Don't reward the criminal actions of millions of illegal aliens by giving them citizenship.


    Sign in and post comments here.

    Please support our fight against illegal immigration by joining ALIPAC's email alerts here https://eepurl.com/cktGTn

Similar Threads

  1. Microsoft Patches 33 Vulnerabilities in November Patch Tuesday Update
    By JohnDoe2 in forum Other Topics News and Issues
    Replies: 1
    Last Post: 11-12-2014, 02:07 PM
  2. Chinese teens 'like prisoners' in Microsoft tech factory
    By millere in forum General Discussion
    Replies: 5
    Last Post: 04-21-2010, 02:56 PM
  3. The image Microsoft doesn't want you to see: Chinese sweatsh
    By AirborneSapper7 in forum Other Topics News and Issues
    Replies: 3
    Last Post: 04-18-2010, 03:44 PM
  4. Windows pirates encouraged to install security patches
    By JohnDoe2 in forum Other Topics News and Issues
    Replies: 0
    Last Post: 02-01-2010, 12:56 PM
  5. Chinese computer hackers target US Commerce Department
    By 2ndamendsis in forum Other Topics News and Issues
    Replies: 1
    Last Post: 10-07-2006, 12:35 AM

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •