Personal computing discussed

Moderators: renee, Flying Fox, Ryu Connor

 
Igor_Kavinski
Minister of Gerbil Affairs
Topic Author
Posts: 2077
Joined: Fri Dec 22, 2006 2:34 am

Duqu detection

Thu Nov 10, 2011 7:12 am

I thought Windows 7 was re-written from scratch. If it had been, it wouldn't suffer from the same vulnerability in Windows XP that allows Duqu infestation. So much for Microsoft and their lofty claims. Now I am seriously concerned. Kaspersky seems to be the only one claiming Duqu detection. Why are things going so slow??? This rootkit was reported on 1st September, 2011 according to Wikipedia. And Microsoft has still to post a proper patch. I mean, WHAT THE HELL??? :evil:

And please don't post any references to the Duqu removal tools out there. I'm sure sifting through gigabytes of files looking for Duqu on hundreds of computers in a corporate environment might be fancied by some admins but I am certainly not one of them.
 
Ryu Connor
Global Moderator
Posts: 4369
Joined: Thu Dec 27, 2001 7:00 pm
Location: Marietta, GA
Contact:

Re: Duqu detection

Thu Nov 10, 2011 7:35 am

Igor_Kavinski wrote:
I thought Windows 7 was re-written from scratch.


Not sure where you got that idea from. 7 is wholly derivative of Vista. Vista had parts re-written from scratch, but even it carries over some old code.

Now I am seriously concerned. Kaspersky seems to be the only one claiming Duqu detection. Why are things going so slow??? This rootkit was reported on 1st September, 2011 according to Wikipedia. And Microsoft has still to post a proper patch. I mean, WHAT THE HELL??? :evil:


QA and regression testing take time.

Pllase don't post any references to the Duqu removal tools out there. I'm sure sifting through gigabytes of files looking for Duqu on hundreds of computers in a corporate environment might be fancied by some admins but I am certainly not one of them.


If you're that concerned about it then you should implement the official quick fix for the problem.

One also needs to put things into perspective. Day zero exploits represent less than 0.1 percent of the malware detected across six hundred million PCs per month according to the most recent bi-annual report.

Frankly given the vectors of vast success used in the past against business (such as the compromises of the RSA tokens) you should be more worried about making sure your Flash is updated.

3rd party software exploits are more popular than attacking the OS in these modern times.
All of my written content here on TR does not represent or reflect the views of my employer or any reasonable human being. All content and actions are my own.
 
just brew it!
Administrator
Posts: 54500
Joined: Tue Aug 20, 2002 10:51 pm
Location: Somewhere, having a beer

Re: Duqu detection

Thu Nov 10, 2011 7:54 am

Igor_Kavinski wrote:
I thought Windows 7 was re-written from scratch.

I don't recall MS ever claiming that. Either you imagined it, or you read something that was written by someone who did.

Ryu Connor wrote:
3rd party software exploits are more popular than attacking the OS in these modern times.

And social engineering attacks are becoming the infection vector of choice. User education is at least as important as keeping the OS and other software patched.
Nostalgia isn't what it used to be.
 
Ryu Connor
Global Moderator
Posts: 4369
Joined: Thu Dec 27, 2001 7:00 pm
Location: Marietta, GA
Contact:

Re: Duqu detection

Tue Dec 13, 2011 3:55 pm

All of my written content here on TR does not represent or reflect the views of my employer or any reasonable human being. All content and actions are my own.
 
ajackson
Gerbil In Training
Posts: 1
Joined: Thu Jan 05, 2012 4:40 am

Re: Duqu detection

Thu Jan 05, 2012 4:43 am

Symantec researchers examined two variants of Duqu. Once on a machine, the strains download a remote access tool, which allows the malware to take control of the computer and begin communication with a command-and-control hub. In the case of one of the variants studied, it installed an "Infostealer" trojan, designed to record keystrokes and map networks.

Who is online

Users browsing this forum: No registered users and 1 guest
GZIP: On