Welcome | Sign In
TechNewsWorld.com
Security

Trojan Horse Is Newest Windows Vulnerability

Print Version
E-Mail Article
Reprints
Trojan Horse Is Newest Windows Vulnerability

Microsoft on Monday announced a new security vulnerability in Windows that allows hackers to take over a PC remotely and which also could introduce a back door Trojan Horse to a user's system. Concurrently, security vendor Symantec upgraded the threat level of this vulnerability while Microsoft, on its Windows security Web site, downplayed the possible risk to users.


Think you have to compromise on security to save on costs? Think Again. Trend Micro™ Enterprise Security, powered by the Trend Micro Smart Protection Network™, can lower your content security management costs by up to 40%. Find out just how much you’ll save with our TCO Impact Calculator.

A new security vulnerability in Windows could allow cybercriminals to hijack a user's machine and divert Web traffic through a malicious proxy server, Microsoft (Nasdaq: MSFT) announced on Monday.

Hackers can send e-mail Increase Customer Sales with Email Marketing -- Free Trial from VerticalResponse messages linked to a malicious payload hosted on a remote Internet server, which could trick recipients into clicking on the link and deliver a backdoor Trojan Horse virus to a Windows Vista-based PC.

"The Backdoor Trojan has become increasing popular lately, and, if you don't know it's there, can do a lot of damage," Laura Didio, an analyst with the Yankee Group, told TechNewsWorld.

The resulting damage includes anything from the deletion of files to the replication of files, data and other items that can chew up storage space, according to Didio.

"It can be very, very nasty," she said.

Threat Ratings

Security firm Symantec (Nasdaq: SYMC) issued a warning about the vulnerability and increased its threat rating from 6.8 to 7.5, confirming the bug was exploitable remote code.

The flaw could also allow an attacker to introduce malware onto a compromised computer via Windows Mail -- the successor to Outlook Express.

"An attacker can deliver an e-mail message containing a malicious link that references a local executable," according to Symantec. "If the victim clicks on this link, the native program is executed with no further action required. For instance: an attacker could achieve the execution of the local file 'winrm.cmd.'"

Malicious Files

Internet Explorer, for example, uses the Web Proxy Automatic Discovery (WPAD) protocol to locate the file that enables a Web browser to configure its proxy settings.

The current flaw makes it possible to place a configuration file that routes Internet traffic through a malicious proxy server, according to Microsoft's security bulletin Web site.

A malicious WPAD.dat file can then be placed in the Domain Name System (DNS) or the Windows Internet Naming Service (WINS), Microsoft said.

Administrators can configure DNS and WINS on their servers to help prevent these "malicious registrations" of WPAD files, according to Microsoft. The fix works with Windows Server 2003 and Windows 2000 Service Pack 4.

Not a Big Threat?

Over the past decade, Microsoft has reduced the number of hacks into its Windows operating system by two-thirds, but the company's ubiquitous nature makes its operating system the world's top target for hackers.

"These hacks can be delayed, but a lot of the responsibility now has to be shifted to the end users," said Didio, noting that IT managers and individual users ultimately need to keep their systems updated against these threats.

Microsoft's Security Response Center team is downplaying the potential risks from the vulnerability, stating on its Web site, "Microsoft is not aware of any attacks attempting to use the reported vulnerability or of customer impact at this time."

Both Symantec and Microsoft are suggesting that users should not click links in any unsolicited e-mails, while also recommending that users should disable HTML within Windows Mail.


Print Version E-Mail Article Reprints More by Tim Gray


More by Tim Gray

Blockbuster Lowers Subscriptions Rates
June 13, 2007
Blockbuster will now offer a new plan allowing customers to place online orders to rent three movies at a time for $16.99, a dollar less than its previous top-tiered offering, called Total Access. The movies are mailed to the customer. Blockbuster is losing money on the online business but says it will be profitable next year as orders rise.
Toshiba Slashes HD DVD Sales Targets
June 12, 2007
Toshiba now expects to sell 44 percent fewer HD DVD players than forecast this year. The slump comes at a critical time for the company, as the market still has not shown which high definition disc player format will dominate. Blu-ray Disc technology, rival of the HD DVD format, already has a foothold in 170 major companies.
Jobs: We Also Make Computers
June 12, 2007
Apple provided at its annual developer conference a peek at some of the 300 new features of "Leopard," the company's latest operating system, which is slated for October release. The computer maker will also make its Safari Web browser available for users of Microsoft's Windows operating system.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network