Language Selection

English French German Italian Portuguese Spanish

Sysadmins taking brunt of blame

Filed under

Sysadmins are taking a big chunk of the blame for the latest worm attacks on Windows - said to have already infected 250,000 machines.

An online poll by security company Sophos had revealed that 20 percent of businessmen feel that the man dealing with the problem - the system administrator - is most to blame, for not patching systems fast enough.

The only consolation is that 35 percent of the 1,000 people polled blame Microsoft for the attacks, and a surprisingly low 45 percent, the virus writers themselves.

The attacks exploit a weakness in the plug-and-play element of Windows 2000 to attempt to gain control of PCs.

"What is most surprising is that so many people blame Microsoft for having the software flaw in the first place. Many respondents appear to be incredibly frustrated by the constant need to roll-out emergency patches across their organisations," commented Graham Cluley of Sophos.

An unknown number of businesses around the world have been hit by worms attempting to exploit the vulnerability, including, embarrassingly, a number of well-known media outlets such as CNN, ABC and The New York Times.

Sophos said it had detected another five such worms in the past 12 hours, taking the total number known to attempt exploits to 17 in all.

This has all happened at a time when Microsoft would rather users moved away from Windows 2000, evens so far as to remove mainstream support from the OS on June 30th of this year. Despite its evident unpopularity inside Microsoft, a recent survey discovered the uncomfortable fact that half of corporates still use it widely, four years after the introduction of its supposed replacement, XP.

Another recent survey by Sophos discovered that only 28 percent of those polled rated Microsoft as their most trusted operating system. Forty-seven percent reckoned Linux and Unix were more secure.

By John E. Dunn

More in Tux Machines

Security Leftovers

  • Friday's security updates
  • Researchers poke hole in custom crypto built for Amazon Web Services
    Underscoring just how hard it is to design secure cryptographic software, academic researchers recently uncovered a potentially serious weakness in an early version of the code library protecting Amazon Web Services. Ironically, s2n, as Amazon's transport layer security implementation is called, was intended to be a simpler, more secure way to encrypt and authenticate Web sessions. Where the OpenSSL library requires more than 70,000 lines of code to execute the highly complex TLS standard, s2n—short for signal to noise—has just 6,000 lines. Amazon hailed the brevity as a key security feature when unveiling s2n in June. What's more, Amazon said the new code had already passed three external security evaluations and penetration tests.
  • Social engineering: hacker tricks that make recipients click
    Social engineering is one of the most powerful tools in the hacker's arsenal and it generally plays a part in most of the major security breaches we hear about today. However, there is a common misconception around the role social engineering plays in attacks.
  • Judge Gives Preliminary Approval to $8 Million Settlement Over Sony Hack
    Sony agreed to reimburse employees up to $10,000 apiece for identity-theft losses
  • Cyber Monday: it's the most wonderful time of year for cyber-attackers
    Malicious attacks on shoppers increased 40% on Cyber Monday in 2013 and 2014, according to, an anti-malware and spyware company, compared to the average number of attacks on days during the month prior. Other cybersecurity software providers have identified the December holiday shopping season as the most dangerous time of year to make online purchases. “The attackers know that there are more people online, so there will be more attacks,” said Christopher Budd, Trend Micro’s global threat communications manager. “Cyber Monday is not a one-day thing, it’s the beginning of a sustained focus on attacks that go after people in the holiday shopping season.”

Openwashing (Fake FOSS)

Android Leftovers

Slackware Live Edition – Beta 2

  • Slackware Live Edition – Beta 2
    Thanks for all the valuable feedback on the first public beta of my Slackware Live Edition. It allowed me to fix quite a few bugs in the Live scripts (thanks again!), add new functionality (requested by you or from my own TODO) and I took the opportunity to fix the packages in my Plasma 5 repository so that its Live Edition should actually work now.
  • Updated multilib packages for -current
  • (Hopefully) final recompilations for KDE 5_15.11
    There was still some work to do about my Plasma 5 package repository. The recent updates in slackware-current broke several packages that were still linking to older (and no longer present) libraries which were part of the icu4c and udev packages.