Author Topic: WMF Attacks on British Parliament  (Read 7879 times)

0 Members and 1 Guest are viewing this topic.

Offline iago

  • Leader
  • Administrator
  • Hero Member
  • *****
  • Posts: 17914
  • Fnord.
    • View Profile
    • SkullSecurity
WMF Attacks on British Parliament
« on: January 23, 2006, 09:14:33 pm »
http://news.com.com/British+parliament+attacked+using+WMF+exploit/2100-7349_3-6029691.html?tag=nefd.top

Quote
The British Parliament was attacked late last year by hackers who tried to
exploit a recent serious Microsoft Windows flaw, security experts confirmed
on Friday.

MessageLabs, the e-mail-filtering provider for the U.K. government, told
ZDNet UK that targeted e-mails were sent to various individuals within
government departments in an attempt to take control of their computers. The
e-mails harbored an exploit for the Windows Meta File vulnerability.

The attack occurred over the Christmas period and came from China, said Mark
Toshack, manager of antivirus operations at MessageLabs, who added that the
e-mails were intercepted before they reached the government's systems.

"The attack definitely came from China--we know that because we log the IP
addresses. The U.K. Government was targeted but none (of the e-mails) got
through. No one was affected. They were attacked, but they (the government)
didn't know about it until we told them," Toshack said.

...
_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Offline Sidoh

  • x86
  • Hero Member
  • *****
  • Posts: 17634
  • MHNATY ~~~~~
    • View Profile
    • sidoh
Re: WMF Attacks on British Parliament
« Reply #1 on: January 23, 2006, 09:22:00 pm »
ROFL!!!  I'm so going to give Lihao shit tomorrow (he's the exchange student from China).

Offline iago

  • Leader
  • Administrator
  • Hero Member
  • *****
  • Posts: 17914
  • Fnord.
    • View Profile
    • SkullSecurity
Re: WMF Attacks on British Parliament
« Reply #2 on: January 23, 2006, 09:24:18 pm »
Well, China is the source for most online attacks.  I think people there are computer-idiots (or something), so they get exploited and become open proxies that attacks go through. 

Offline Sidoh

  • x86
  • Hero Member
  • *****
  • Posts: 17634
  • MHNATY ~~~~~
    • View Profile
    • sidoh
Re: WMF Attacks on British Parliament
« Reply #3 on: January 23, 2006, 09:42:15 pm »
Well, China is the source for most online attacks.  I think people there are computer-idiots (or something), so they get exploited and become open proxies that attacks go through. 

It could be that they have a lot of technology relative to the rest of the world, too.  Think about their population and also how technologically advanced they are.  Lihao brought a camera that was 7 megapixels.  That's about up to par with today's top-of-the-line hobbiest (not professional; his is a hobbiest camera too) digital cameras on the market in the US.  He said he has had it for about two years now.

Given those two facts, you're a lot more likely to find an insecure node in a WAN in China than you are in the US or Canada.

Offline Blaze

  • x86
  • Hero Member
  • *****
  • Posts: 7136
  • Canadian
    • View Profile
    • Maide
Re: WMF Attacks on British Parliament
« Reply #4 on: January 23, 2006, 10:07:18 pm »
I think they setup those proxies, because they don't care.  :P
And like a fool I believed myself, and thought I was somebody else...

Offline Sidoh

  • x86
  • Hero Member
  • *****
  • Posts: 17634
  • MHNATY ~~~~~
    • View Profile
    • sidoh
Re: WMF Attacks on British Parliament
« Reply #5 on: January 23, 2006, 10:18:14 pm »
I think they setup those proxies, because they don't care.  :P

Or don't know how to care or that they should care.  I think my hypothesis is more correct.

Offline Newby

  • x86
  • Hero Member
  • *****
  • Posts: 10877
  • Thrash!
    • View Profile
Re: WMF Attacks on British Parliament
« Reply #6 on: January 23, 2006, 11:49:01 pm »
Well, China is the source for most online attacks.  I think people there are computer-idiots (or something), so they get exploited and become open proxies that attacks go through. 

When I was @ M$ HQ, there was this poster with regions with most copies of illicit copies of Windows. China looked like a bright red dot.

So, since they can never patch their systems, they get infected easily. :)
- Newby
http://www.x86labs.org

Quote
[17:32:45] * xar sets mode: -oooooooooo algorithm ban chris cipher newby stdio TehUser tnarongi|away vursed warz
[17:32:54] * xar sets mode: +o newby
[17:32:58] <xar> new rule
[17:33:02] <xar> me and newby rule all

I'd bet that you're currently bloated like a water ballon on a hot summer's day.

That analogy doesn't even make sense.  Why would a water balloon be especially bloated on a hot summer's day? For your sake, I hope there wasn't too much logic testing on your LSAT. 

Offline Sidoh

  • x86
  • Hero Member
  • *****
  • Posts: 17634
  • MHNATY ~~~~~
    • View Profile
    • sidoh
Re: WMF Attacks on British Parliament
« Reply #7 on: January 23, 2006, 11:50:44 pm »
When I was @ M$ HQ, there was this poster with regions with most copies of illicit copies of Windows. China looked like a bright red dot.

So, since they can never patch their systems, they get infected easily. :)

That's pretty funny.  What'd you go to the Microsoft Headquarters for?

Offline Warrior

  • supreme mac daddy of trolls
  • Hero Member
  • *****
  • Posts: 7503
  • One for a Dime two for a Quarter!
    • View Profile
Re: WMF Attacks on British Parliament
« Reply #8 on: January 24, 2006, 12:50:26 am »
Linux Missionary trip.
One must ask oneself: "do I will trolling to become a universal law?" And then when one realizes "yes, I do will it to be such," one feels completely justified.
-- from Groundwork for the Metaphysics of Trolling

Offline Ergot

  • 吴立峰 ^_^ !
  • x86
  • Hero Member
  • *****
  • Posts: 3724
  • I steal bandwidth. p_o
    • View Profile
Re: WMF Attacks on British Parliament
« Reply #9 on: January 24, 2006, 01:06:00 am »
Hahaha. Silly Chinese.
Who gives a damn? I fuck sheep all the time.
And yes, male both ends.  There are a couple lesbians that need a two-ended dildo...My router just refuses to wear a strap-on.
(05:55:03) JoE ThE oDD: omfg good job i got a boner thinkin bout them chinese bitches
(17:54:15) Sidoh: I love cosmetology

Offline Blaze

  • x86
  • Hero Member
  • *****
  • Posts: 7136
  • Canadian
    • View Profile
    • Maide
Re: WMF Attacks on British Parliament
« Reply #10 on: January 24, 2006, 01:26:25 am »
Linux Missionary trip.
[/quote

Hah, my Engineering teacher said they based Vista off of Unix?  I'm not going to use it so *shrug*.
And like a fool I believed myself, and thought I was somebody else...

Offline Sidoh

  • x86
  • Hero Member
  • *****
  • Posts: 17634
  • MHNATY ~~~~~
    • View Profile
    • sidoh
Re: WMF Attacks on British Parliament
« Reply #11 on: January 24, 2006, 02:40:05 am »
Hah, my Engineering teacher said they based Vista off of Unix?  I'm not going to use it so *shrug*.

False... we had an argument about that on IRC yesterday.  Newby didn't even go as far as to claim it was based on UNIX, but he did say there was a UNIX subsystem.  TehUser asked for documentation and Newby was unable to find anything supporting his claim directly.

Vista is not based on UNIX.  Tell your engineering teacher he's wrong! :)

Offline iago

  • Leader
  • Administrator
  • Hero Member
  • *****
  • Posts: 17914
  • Fnord.
    • View Profile
    • SkullSecurity
Re: WMF Attacks on British Parliament
« Reply #12 on: January 24, 2006, 08:53:55 am »
When I was @ M$ HQ, there was this poster with regions with most copies of illicit copies of Windows. China looked like a bright red dot.

So, since they can never patch their systems, they get infected easily. :)

You can still download security patches with illegal copies of Windows. 


False... we had an argument about that on IRC yesterday.  Newby didn't even go as far as to claim it was based on UNIX, but he did say there was a UNIX subsystem.  TehUser asked for documentation and Newby was unable to find anything supporting his claim directly.

Vista is not based on UNIX.  Tell your engineering teacher he's wrong! :)
It has a lot of UNIX-style elements, I'm told. 

In any case, TehUser was on IRC?  I thought he went away this week :-/

Offline Blaze

  • x86
  • Hero Member
  • *****
  • Posts: 7136
  • Canadian
    • View Profile
    • Maide
Re: WMF Attacks on British Parliament
« Reply #13 on: January 24, 2006, 03:40:26 pm »
By based, I'm sure he didn't mean code wise, he probably ment based on how they do things... but I don't know much about this so I'll drop the argument. :P

Yes, my other versions of windows are less then legit and they're up to date on everything.
And like a fool I believed myself, and thought I was somebody else...

Offline deadly7

  • 42
  • x86
  • Hero Member
  • *****
  • Posts: 6496
    • View Profile
Re: WMF Attacks on British Parliament
« Reply #14 on: January 24, 2006, 06:54:21 pm »
Well, I read on the M$ website that Vista will incorporate a lot of things Linux does, of course those were rumors released like, last spring.
[17:42:21.609] <Ergot> Kutsuju you're girlfrieds pussy must be a 403 error for you
 [17:42:25.585] <Ergot> FORBIDDEN

on IRC playing T&T++
<iago> He is unarmed
<Hitmen> he has no arms?!

on AIM with a drunk mythix:
(00:50:05) Mythix: Deadly
(00:50:11) Mythix: I'm going to fuck that red dot out of your head.
(00:50:15) Mythix: with my nine

Offline Sidoh

  • x86
  • Hero Member
  • *****
  • Posts: 17634
  • MHNATY ~~~~~
    • View Profile
    • sidoh
Re: WMF Attacks on British Parliament
« Reply #15 on: January 24, 2006, 11:02:41 pm »
By based, I'm sure he didn't mean code wise, he probably ment based on how they do things... but I don't know much about this so I'll drop the argument. :P

Yes, my other versions of windows are less then legit and they're up to date on everything.

No, he said that Vista would have a UNIX subsystem, as in reverse compatability with UNIX applications.  From the evidence I've seen, there's no such intention...

Offline Blaze

  • x86
  • Hero Member
  • *****
  • Posts: 7136
  • Canadian
    • View Profile
    • Maide
Re: WMF Attacks on British Parliament
« Reply #16 on: January 24, 2006, 11:41:21 pm »
By based, I'm sure he didn't mean code wise, he probably ment based on how they do things... but I don't know much about this so I'll drop the argument. :P

Yes, my other versions of windows are less then legit and they're up to date on everything.

No, he said that Vista would have a UNIX subsystem, as in reverse compatability with UNIX applications.  From the evidence I've seen, there's no such intention...

That's definitely not what he said. :)
And like a fool I believed myself, and thought I was somebody else...

Offline Sidoh

  • x86
  • Hero Member
  • *****
  • Posts: 17634
  • MHNATY ~~~~~
    • View Profile
    • sidoh
Re: WMF Attacks on British Parliament
« Reply #17 on: January 24, 2006, 11:56:33 pm »
That's definitely not what he said. :)

You were not present during the argument.  It was ergot, TehUser, newby and I.  We extended the conversation later, which is probably what you remember.

I sepcifically remember the word subsystem.

Offline iago

  • Leader
  • Administrator
  • Hero Member
  • *****
  • Posts: 17914
  • Fnord.
    • View Profile
    • SkullSecurity
Re: WMF Attacks on British Parliament
« Reply #18 on: January 25, 2006, 09:38:10 am »
Quote
Bill Hilf, the head of Microsoft's Linux lab, is planning to talk up during his LinuxWorld session on Wednesday the elements of Microsoft's Services for Unix subsystem that the company is integrating into R2. Hilf tipped his hand during a Q&A with Slashdot readers posted to the Slashdot Web site on Monday.
ADVERTISEMENT

"I can confirm that the next-generation of several components of Services for Unix are being integrated into Windows Server 2003 R2. The Network File System (NFS) client, NFS Server, User/Name Mapping, Telnet Server & Client, Password Sync and NIS Server components of Services for Unix are all present in the Windows Server 2003 R2 builds," said Hilf, in response to one of the Slashdot questioners. "In addition, a revamped POSIX subsystem, the 'Subsystem for Unix-based Applications' or 'SUA' is also available as an optional install in R2.
Source


Quote
Utilities and SDK for Subsystem for UNIX-Based Applications is an add-on to the Subsystem for UNIX-Based Applications (referred to as SUA, hence forth) component that shipped with Microsoft Windows Server 2003 R2.

This consists of the following components:

- Base Utilities
- SVR-5 Utilities
- Base SDK
- GNU SDK
- GNU Utilities
- UNIX Perl
- Visual Studio Debugger Add-in
Source


They have what they call a "UNIX Subsystem" for Windows 2003 (really, it just seems like it's POSIX compliance, but whatever, Microsoft can spin that however they want).  It seems pretty likely that they'd have it for Windows Retirement (err, Vista) too.