Slashdot Log In
How Much Harm Can One Web Site Do?
Posted by
timothy
on Wed Nov 24, 2004 12:58 PM
from the depends-on-what-os-you're-running dept.
from the depends-on-what-os-you're-running dept.
Ben Edelman has written extensively on issues including censorship and spyware. He's got a very interesting piece on his site now about who profits from spyware, and how much spyware can be installed on a Windows XP machine when the user simply visits a single Web site using Internet Explorer.
This discussion has been archived.
No new comments can be posted.
How Much Harm Can One Web Site Do?
|
Log In/Create an Account
| Top
| 501 comments
(Spill at 50!) | Index Only
| Search Discussion
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
not much... (Score:5, Informative)
Re:not much... (Score:4, Informative)
(Last Journal: Thursday April 10 2003, @03:01AM)
Re:not much... (Score:5, Informative)
(http://www.gnolaum.com/)
I'm running SP2 and nothing has broken thus far. Normally when people complain about SP2 breaking stuff (like a game that will not play online after patching to SP2) it has to do with the upgraded firewall. Tweaking the firewall is all that is needed to get your game (and 9 times out of 10 X app)running agian.
All in all, I think Microsoft did a good job with SP2. The security center is something that should have been in the control panel to begin with. Its good to have some centralized location.
But yeah, SP2 fixed a lot of things in Windows and it really didn't *break* things, it just tighten some bolts that then required the user to go and loosen what he/she wanted to use. (instead of leaving the whole damn computer open)
Re:not much... (Score:5, Funny)
No network, no spyware!!!
Re:not much... (Score:4, Funny)
(Last Journal: Wednesday August 25 2004, @10:14AM)
Re:not much... (Score:5, Informative)
(http://slashdot.org/)
Re:not much... (Score:4, Insightful)
On the other hand, requiring absolute security is not an appropriate standard. This standard does not apply anywhere else; your home insurance probably does not cover you for some "acts of nature or God". You cannot say that a meteorite will not fall on you and kill you; you have no absolute security in your daily life. I agree that "Security is a process, not a product." However, experience so far suggests that runing Linux would be much more secure than running Windows.
Re:not much... (Score:5, Interesting)
(http://www.mwatt.com/index.html | Last Journal: Friday February 11 2005, @02:43PM)
I am personally responsible for the software on 67 windows computers at a university. I am jointly responsible for almost 400 of same.
On the image I created and support, there are 93 applications loaded on top of a base XP install. These range from silly stuff like DivX player to Pro/Engineer. I had to test each and every one of them for SP2 compatibility.
A grand total of 4 applications wouldn't work at all. 2 or 3 more had minor problems. Every one of those with problems were corrected by getting updated versions of said app.
Any other usability problems are strictly a function of the firewall and if you (being a
Re:not much... (Score:4, Informative)
(http://www.vandaliersheart.com/)
It isn't a real hard thing to do most times as long as you know what you are looking for and the machine doesn't touch any form of a network during cleaning.
Yes, it takes awhile. Then again, would you upgrade an OS on a virus infested machine? Of course not!
Re:not much... (Score:5, Funny)
(http://www.afp548.com/ | Last Journal: Monday October 28 2002, @11:31PM)
You guys on the "don't install SP2!" bandwagon need to wise up.
You straight up office/cube/lab support guys need to wise up. There's more to life than IE/Outlook/Office. Where I work, we use PCs to analyze genomic data and communicate and control robotic devices that gather DNA information. Often, esp the control software, is written specifically for a version of Win2K, let alone be able to update to XP S2. You heard me right--there's still lots of instances of NT, and even some Mac OS 7.5.3. In many cases, the original vendor is non-existent, hard to reach, or they specifically recommend against updating to a newer version. Often, security updates will break functionality that these applications depend on.
So thanks for the info. I'm sure XP SP2 makes a good kiosk. However, the guy that decided to run a $300K sequencer off a $700 Dell using some bastardized version of Java, and also can't be upgraded to XP or anything reasonably secure needs to have their head examined. I'm looking at you, ABI.
Re:not much... (Score:5, Interesting)
virgin install (Score:5, Interesting)
(http://www.fishdan.com/ | Last Journal: Monday April 16 2007, @02:26PM)
It bothers me that some people still install windows while connected to the internet.
Re:not much... (Score:5, Insightful)
Some of us don't install SP2 because we're not using Win/XP or Win/XP Professional. I am currently running Win/2000 Professional when I am on the Windows side of this machine.
Unfortunately, Windows/2000 Professional is vunerable to these exploits and there is no patch available. I have a fully patched system, run the latest version of Norton's, and sit behind a Linksys router/switch. If I use IE or Outlook I run the risk of getting spyware, viruses, and trojan horses. There are no patches.
Fortunately, I do not use IE on Windows/2000 except to check my web authoring. I do not use Outlook in any form. In fact, I do not read mail on my Windows/2000 side.
However, I have real problems with all of this. As far as I know, Windows/2000 Professional has not reached end of life. I didn't find any information on the Microsoft web site, but you never know. Until Windows/2000 Professional hits end of life, I expect to have at least the same level of security that the latest patched Windows/XP Professional has.
I am comfortable using alternate tools, and in fact I prefer them (Firefox, Thunderbird, OpenOffice, etc.). However, I do not think that having my computer exposed to malware that I can do nothing about is reasonable, esepcially when the same fixes are available for Windows/XP Professional.
I know that one solution is to upgrade to Windows/XP Professional. There are really no advantages to me in upgrading to Windows/XP Professional. I can test ASP.NET, develop C#, run Tomcat/Apache, write Perl, and use MySQL or PostgreSQL quite nicely on Windows/2000 Professional. For my $200 retail price I get an OS with a bigger footprint, menus that purposely hide non-Microsoft software, and a host of other impediments to computer usage.
Ah . . . but I do get the latest security upgrades from Microsoft, many of which are not available for Windows/2000. This is true even though Windows/2000 Professional is a fully supported product.
An average user is not going to be aware of these considerations when using a computer. An average user will not be aware that while Windows/XP SP2 is patched properly, the same diligence will not suffice for Windows/2000.
A lot more can be said about Microsoft's marketing, planned obselence, and deceptive business practices, but that would probably be off-topic.
Re:not much... (Score:5, Funny)
How much harm? (Score:5, Funny)
In Case It Gets Slashdotted... (Score:5, Informative)
Re:In Case It Gets Slashdotted... (Score:5, Insightful)
(Last Journal: Monday November 28 2005, @12:21PM)
If you can install 1 piece of spyware you can install 1000 or 1000000. Once you're pwned you're pwned, "how much" is entirely irrelevant.
Umm... (Score:5, Funny)
Re:Umm... (Score:5, Insightful)
("warning! you're in danger! all you do with computer is stored forever in your hard disk
OK, if you're going to make fun of someone's English, don't turn the Latin word sic into an acronym. Super Intelligent Comment? Sick Internet Creep? Silly Immature Cretin? Sadly Impoverished Credibility?
Windows XP? (Score:5, Funny)
(http://xyfer.blogspot.com/ | Last Journal: Tuesday July 24, @09:00AM)
how much spyware can be installed on a Windows XP machine when the user simply visits a single Web site using Internet Explorer.
Am I safe if I am on a win2k machine?
Re:Windows XP? (Score:4, Funny)
What was the actual web page? (Score:5, Insightful)
(Last Journal: Thursday June 17 2004, @10:02AM)
I mean, I'm guessing most people would visit a reputable search engine, or the default MSN page when they first installed Windows and opened up IE, instead of what I'm guessing must be a fairly dodgy site in order to install so much spyware.
That's not to discredit what he's done - I'm sure novice users would easily get onto these sort of spyware laden pages by mistake pretty quickly...I'm just interested, that's all.
Re:What was the actual web page? (Score:5, Informative)
Re:You could always use a Mac. (Score:5, Informative)
No, IE runs under whatever user you are logged in as. One should definately learn to manage users. No argument there.
, but I am of the opinion that users have every right to be stupid,
Yet we all own cars... If you are too stupid to add oil to your car and you burn out your engine... It's not the manufacturers fault. There's a certain level of responsibility the users should bear as well. Users have a right to be stupid, but should pay up when they screw their computers up the same way car owners should pay if they don't maintain their vehicle or use it correctly.
. If XP needs all of these security patches just to keep going, where a mac or linux box could stand like a column of basalt for years
Again, Bullshit! There's security holes in Linux and FreeBSD. That's why we have utilities in Fedora like up2date, portupgrade, etc. So you can automate the patching of those security holes.
Re:You could always use a Mac. (Score:5, Insightful)
(Last Journal: Tuesday April 12 2005, @11:12PM)
The main defense is their structural strenght, i.e. being thinked from the basis as multiuser, where you have very separated the system admin (the one that have some permission over i.e. what programs are installed) over the user that browses internet.
And dont forget that here the blame goes both for the operating system author (Microsoft) and the browser author (Microsoft again), both good examples of what happens when security is the least priority.
Re:You could always use a Mac. (Score:4, Insightful)
How much damage can one web site do? (Score:3, Funny)
(http://192.168.0.255/)
How much harm can ONE site do?!! (Score:5, Funny)
(http://www.interfix.net/ | Last Journal: Thursday November 15 2001, @02:44PM)
Apparently we're forgetting the word "slashdot" as a verb.
No surpises here. (Score:5, Insightful)
(http://www.trilobite.org/)
s.i.c. (Score:5, Funny)
"warning! you're in danger! all you do with computer is stored forever in your hard disk
Anyone else find the improper spelling of "sic" (used by an editor to mark improper spelling or usage in a quoted piece of text) to be humorous, or is it just me?
Re:s.i.c. (Score:4, Funny)
Why not a site "death sentence" (Score:3, Insightful)
Why can't this be done?
Just cut them off entirely.
The big players need to get together on this.
Not impressed (Score:4, Insightful)
This is akin to throwing matches at a tub of gasoline and writing an expose' when it catches fire. Either this guy had too little to write about, had too much time on his hands, or had to win a bet and is trying to slip this one by someone.
Even he admitted his lousy methodology in his last sentence.
This isn't news. It's just a bone thrown out to keep the resident "gotta flame microsofties" happy with a fix for the day.
You're missing both points (Score:5, Insightful)
(http://www.orion-com.com/)
If I leave my door unlocked, I'm an idiot, but if you then walk in and steal my TV while I'm gone and sell it at the local pawnshop you're still just as much a criminal as if you smashed a steel door in with an APC: an unlocked door is not in itself an invitation to enter and make oneself at home. The same principle applies here: the sites and software authors are not the legitimate businesspeople they try to convince everyone they are.
Re:Not impressed (Score:4, Insightful)
Basically, the guy was loading and emulating what is probably 80% of the internet users out there (think AOLers
Gnome + spyware? (Score:4, Interesting)
(http://www.livejournal.com/users/k4_pacific | Last Journal: Tuesday May 25 2004, @10:16PM)
Rhetorical? (Score:4, Funny)
Again, sensationalism trumps truth (Score:5, Insightful)
(http://judahgabriel.blogspot.com/)
Note that the latest version of Internet Explorer, as patched by Windows XP Service Pack 2, is not vulnerable to the installations shown...
In other words, he's running all this on an unpatched XP machine.
Now, before the Slashdot horde stabs me repeatedly with a big sharp knife for being a Microsoft apologist, consider this situation. I've got an old version of Firefox with a few exploits in it. I report the exploit, and the response I get is that these exploits are already patched. Yet I decide to write a story about the horrific exploits, post it to Slashdot, and stir up a raucus about how bad FireFox's security is.
What I'm proposing is that Slashdot report it's stories with less sensationalism and more professionalism. Put in the story that all this was run on an unpatched machine, and that the said security holes have already been fixed.
Thank you.
Re:Again, sensationalism trumps truth (Score:5, Insightful)
(http://slashdot.org/ | Last Journal: Wednesday October 02 2002, @10:14PM)
The same problem happens on:
A patched Windows 2000 Machine
A patched Windows XP SP1 Machine
A patched Windows XP Machine
A patched Windows 98 Machine
To get browser security from Microsoft requirs a user of Windows 98 to spend $100 to get XP and then spend the next two days trying to install it and getting it to work right with his scanner/fax/printer.
Or our Winodws 98 friend could just download Firefox.
Why Microsoft wont realease a standaline Internet Explorer for its old systems is obvious: The want to suck more money out of people. And they suck.
If Slakware can update thier browser - why in the fuck cant one of the largest companies in the world do the same?
Regarding the Video... (Score:3, Informative)
Glad I didn't have the boss watch it with me in an attempt to convince her of the need to take better anti-spyware measures.
Another good write-up here: (Score:5, Informative)
(http://www.saintaardvarkthecarpeted.com/blog | Last Journal: Monday March 05 2007, @11:58PM)
- Part 1 [sans.org]
- Part 2 [sans.org]
- Part 3 [sans.org]
Part 4 is coming Real Soon Now (tm). The ISC handler's diary is required daily reading; always a lot of good stuff to be found. (And every now and then, there's a tale that'll make your blood run cold [sans.org]...)Does he have a lawyer? (Score:3, Interesting)
(http://www.geekazon.com/)
I would love to see somebody slap some criminal charges against the site owner. Hiding behind an obfuscated EULA is bad enough, but installing software without any permission whatsoever has to be illegal, doesn't it?
SP2 is immune (Score:3, Insightful)
simulating spyware installs (Score:3, Interesting)
My e-mail to the TwainTec Legal Dept (Score:3, Insightful)
My letter (to which I got no reply)
Hello there. As you can see, I have had to take steps to insure my identity remain secret.
Due possibly to an oversight on my part (leaving the security level in the internet zone in IE on Low, then going to an untrusted site), I have been infected with your adware. The uninstall procedure on your website does not work -- your software is not listed in add/remove programs. The twaintec.dll in my windows directory is currently being used, however I have removed all permissions to this file so it will not load after I reboot.
I was infected with this as well as a myriad of other spyware (toolbars, programs, browser hijackers... I didn't bother to make a list but you should see all the pornographic bookmarks I now have, it's very impressive) by simply going to an internet site. I didn't accept any requests, I didn't read any privacy policies, and now I have your program.
While your privacy policy attempts to divert responsibility by claiming not to allow this, your failure to insure in software that this actually happens makes your company morally, if not legally, complicit. In short, you could have written software that did this, but instead you put the onus on others to ensure that your software was installed on end-users' computers responsibly. Not surprisingly, many third parties do not do this, and privacy policy be damned, *you profit from it*. You acknowledge this by putting, in your privacy policy, instructions to contact your legal department if one should find examples of abuse of your software. I believe that a person of moral integrity would take steps to ensure that your software was not abused, and that by not doing so, you lack moral integrity.
But I'm not here to put you down. I would like you to stop distributing the software, shut down your servers, destroy the source, and find another job. A company that can produce this software could, instead, produce something like, say, PestPatrol, that would make peoples' lives better, not worse. But the purpose of this e-mail is not to request that.
What I want from you is simple. I want you to write me back with instructions on unregistering that DLL. I don't know who wrote this program, but this should be a simple task for someone with programming knowledge, such as must have been required to write the program. If you can do this for me, your moral obligation to me may be considered fulfilled. There is still the greater issue of this software, but one that I'll let you deal with on your own time. If you reply to help me fix what your software has broken, I will forgive you.
If you promise to take steps to ensure that your software is not abused or that you do not profit from it if it is (charitable donations?), I will applaud you.
But I will never trust you.
David
---
Protect yourself from spam,
use http://sneakemail.com
Win2K is just as bad. (Score:5, Interesting)
(http://www.dnull.com/~sokol | Last Journal: Saturday December 04 2004, @12:44PM)
I also killed all the services. and it never ran a web browser. Just mysql. I didn't have any antivirus software on it.
So after placing it on an unfirewalled connection in a locked room, withing 2 hours there were over dozens of virus, worm and spyware installed on the system till it crashed and couldn't even boot. Coming up with 100's of DLL errors!
Again we never open a single web page.
Specificaly some of what was installed was:
alte.exe
beird.exe
c.bat
clonzips.ssc
clsob
cvqaikxt.apk
cult.exe
cygwin1.dll
dgss
dual.exp
emoti.bat
enotxa2.exe
explorx.
ger.exe
gt.x
hosts was altered
knlps.exe
knlps.sys
ksat.bat
medo.dl
nonzipsr.noz
ntcnsl.dll
orrl.exe
Odi
repcale.exe
riqa
scheduler.exe
sysm
svcshost.exe
titlex.exe
w.e
wshield.e
winguard.exe
ymnz.exe
unmt.exe
vnicmon.exe
a qsws directory
zippedsr.piz
Re:Win2K is just as bad. (Score:4, Insightful)
(Last Journal: Saturday October 26 2002, @11:59PM)
You might as well have blessed it with the wave of your hand.
You must visit windows update to get the post SP4 patches or the very least enable auto-update.
You probably got all this stuff from the lsass and rpc vulnerabilities which SP4 does not address.
Reminds me of passthison.com (Score:3, Informative)
My mom (Score:5, Insightful)
While so many are quick to point out that he used an unpatched machine, that he should know better, that he's just doing it to be difficult, that he can fix it. He know's he should install SP2, he knows he should have his firewall set up. He knows he should practice safe surfing....but my mom doesn't know this stuff.
For every computer whiz (like most of us that visit /.), there's a thousand users like my mom who know that you turn on the box, move the little mouse around, and she can type emails to the whole family every day. Then she surfs around on the internet, types something in wrong, clicks on the wrong site, and now can't send the emails to the family and can't order my Christmas presents from Amazon.
Spyware is a pain in the ass for us, but its a nightmare for the computer novices!
Stupid Spyware Companies. (Score:3, Interesting)
(http://tsfraser.googlepages.com/index.html)