Article

Does Microsoft Show Hackers How To Attack?

Written by For More Free Resources visit www.greateducationonline.com

Topic: Internet MarketingPublished February 15, 2008
No ratings yet893 viewsSign in to rate

After another security hole recently surfaced in Microsoft's
Windows operating system, the software giant released a npatch this past Friday to plug the possibly devastating
"back door" which allows hackers to potentially seize ncontrol of any pc running Windows.

The latest threat, "Download.Ject," infiltrates computers nafter users surfing with Microsoft's "Internet Explorer" web nbrowser visit websites infected with the virus.

This newest security patch covers Windows XP, 2000, and
Windows Server 2003.

Several factors make this latest development more disturbing nthan past discoveries of security problems with Internet
Explorer, currently the most dominant web browser on the nmarket.

First, it demonstrates very clearly that criminals ndiscovered they can use the power of viruses to very nprofitably steal important bank, personal, and credit data nfrom people on a large scale.

Second, it took Microsoft what many would consider a very nlong time to come up with a patch for this problem.

Before a fix appeared, Microsoft told everyone who uses
Internet Explorer to stick their finger in the dyke by nputting their web browser security settings on high, nrendering it impossible to view or use features on many nwebsites and web-based services.

Third, expect this to happen again as new holes open in the nfuture when Microsoft makes Windows more complicated, adds nlayers of code, and generally makes the operating system nmore complex.

This may sound like business as usual, however, I think nthis story actually points to a much deeper problem, one for nwhich I'm not sure a simple solution exists.

Though free and reasonably reliable, many people do not nautomatically update their Windows operating system through nthe update service on Microsoft's website. (I won't even get ninto how many people don't operate up-to-date anti-virus nprotection.)

Whenever Microsoft publishes a security update, especially nfor a highly publicized and obviously widespread security nbreach, thousands of people will not immediately download nthe update.

In fact, tens-of-thousands of users will not download these nsecurity updates for days, weeks, even months (if ever).

So let me ask what seems like a very elementary question: By npublishing security updates that point out very obvious nflaws in their system, doesn't Microsoft also point the way nto exactly where the holes exist?

Let me put it another way.

Doesn't this rate the same as discovering that the local nbank vault won't lock and then announcing the details on the nfront page of the paper along with the dates and times no nbank guard will be on duty?

After all, if tens-of-thousands of users won't immediately nget the Microsoft Security Patch, don't those patches show nhackers exactly which holes get plugged (and which, nlogically, must already be open without the patch)?

It doesn't take a hacker with more than a basic set of nskills to recognize where and what holes got fixed and then nreverse-engineer how they can get into computers that don't nget updated.

Now, do I have a concrete, 100% bullet-proof answer to this nproblem? Unfortunately, I don't have more than a common- nsense answer...

At this point, your best defense rates staying current on nthe latest threats and how to defend against them.

Keep your anti-virus software current, your firewall up, and nyour Windows software updated with the latest security npatches.

Though not a perfect solution, at least you'll have a nfighting chance to prevent, or at least minimize, any npossible threats.