Quantcast
PCWorld.com is upgrading some back-end systems. Some site features, such as user registration, may be temporarily unavailable.

Are Windows Broadband Users at Risk?

Attackers may be targeting home users with high-speed access.

David Legard, IDG News Service

  • 0 Yes
  • 0 No

The CERT Coordination Center security organization based at Carnegie Mellon University in Pittsburgh has seen an increase in exploitation of weak administrator passwords on systems running Microsoft's Windows 2000 or Windows XP operating systems, the organization said Tuesday.

Attacks are being particularly--though not exclusively--targeted at home broadband users running those operating systems, according to CERT/CC.

The weakness specifically refers to nonexistent or easily discovered passwords on SMB (Server Message Block) file shares, with thousands of systems being compromised in this way, CERT/CC said in an advisory.

Windows uses the SMB protocol to share files and printer resources with other computers. The two versions of the operating system referred to in the CERT bulletin transfer information via TCP/IP. These systems are vulnerable to attacks using tools such as W32/Deloder, GT-bot, sdbot, and W32/Slackor. Older operating systems which share SMB information differently are not vulnerable, according to CERT/CC.

Possible Problems

According to CERT/CC, attackers who gain access in this way could:

  • exercise remote control;

  • expose confidential data;

  • install other malicious software;

  • change or delete files;

  • install or support tools for use in distributed denial-of-service attacks against other computers.

The scanning activities of these tools may also generate high volumes of traffic, causing the performance of some Internet-connected hosts or networks to deteriorate, CERT/CC said.

CERT/CC said that users should review their password procedures to create strong passwords, run antivirus programs, and not download or open material from an untrusted source.

  • Recommend this story?
  • 0 Yes
    0 No
 
Learn more about the Windows Phone PCWorld Gift Guide

People who read this also read:

  • 15 Minutes to a Secure Business Get the Secure in 15 toolkit starting with the "15 Minutes Month-at-a-Glance" calendar. McAfee will send you additional tools and tricks to stay protected around the clock.
  • A Buyer's Guide to Data Protection Implementing data protection products and processes can be daunting. Make the right decisions by exploring what is available and what makes sense for your organization. Use this simple guide to evaluate different vendor offerings.

Sponsored Links