Friday, August 29, 2008   
  Search  
 
Register  Login  
Forums  
     Minimize  

Welcome to MeraWindows forums.

Thank you for being at the Microsoft Windows Community Site. You may have to register before posting in forums. It's absolutely free. After registering, you can get all the benefits available to our registered members, you can access our Downloads section, you can participate in contests, etc. You can post in forums in English as well as in Hindi, in fact we encourage you to use Hindi in your posts. If you have any problem with registration or login, please contact us.

     
  


 
  Microsoft Windows Forums  Security Center  Windows Updates  Malvare Hijacks Windows Update Component
Previous Previous
 
Next Next
New Post 5/15/2007 4:34 PM
User is offline Srinath Sadda
1230 posts
www.meraTechExplorer.com
MW Addict




Malvare Hijacks Windows Update Component 
Hackers are always finding new ways of compromising system security by hiding files in just about every file type possible but this is a relatively new concept which shows the increasing “intelligence” of the hacking community. Malware can now be delivered to an already compromised system through the use of the Background Intelligent Transfer service (BITS) which is a component of Windows Update. Is nothing sacred?

The reason this works is because ALL firewalls automatically trust BITS which makes it easy to piggyback malware onto files being transferred by BITS and this automatically grants the file unlimited access to network resources or the system itself. No file transferred by BITS is scanned for malware or virus infections, everything is automatically trusted.

Although BITS has been directly affected, there is no reason to suspect that the Windows Update Service itself has been compromised in any way. Computer World spoke with Oliver Friedrichs of Symantec’s Security Response group and he said, “There is no evidence to suspect that Windows Update can be compromised. If it has a weakness, someone would have found it by now.” That’s probably true.

In case you’re curious BITS is part of every modern operating system based on NT code which started with Windows XP, was included with Windows Server 2003 and yes Vista has it as well.

The idea is that once a system has an infected file on it, it will use BITS to download just about anything it wants and install it into the system and because this happens in the background, you won’t notice it. Of course, a quick check of Task Manager could tell you, if you know what to look for.

The same remains true, don’t download files from unknown sources, don’t open email attachments from people you don’t know, don’t click on unknown links and keep up to date security software even if it requires you to pay for it, just do it.

I can see it now, security vendors will being building in protection systems for BITS, I’m not saying it would be a bad thing but downloads are bound to take longer if each incoming file is checked for malicious code or behaviors.


 
New Post 5/16/2007 2:22 AM
User is offline Vishal Gupta
5944 posts
www.AskVG.com
Ultimate Member








Re: Malvare Hijacks Windows Update Component 
grrr, yeh hackers bhi na, Microsoft walon ko chain nahi lene denge...

Microsoft Windows MVP

Tweaking with Vishal

How to Use Smiley Code in Forum?
Promote MeraWindows at Your Blog / Site
Read Forum Guidelines
 
Previous Previous
 
Next Next
  Microsoft Windows Forums  Security Center  Windows Updates  Malvare Hijacks Windows Update Component
   Get Your Own E-Mail Account @MeraWindows.com Minimize  
New Page 1 New Page 1
Show your cool quotient with @merawindows.com email account