Microsoft shuts down giant Rustock spamming network
blog.seattlepi.com
blog.seattlepi.com
They probably found it pretty simple after shutting down Waledac earlier. Same team, different target.
"However, Rustock’s infrastructure was much more complicated than Waledac’s, relying on hard-coded Internet Protocol addresses rather than domain names and peer-to peer command and control servers to control the botnet."
Read the whole thing at http://blogs.technet.com/b/microsoft_on_the_issues/archive/2...
Well, it's nice that this was not the case.
I can assure you the zillions of Linux servers you see sitting unattended for years on very fat pipes are really attractive targets. Yet, you don't hear about server botnets... There must be a reason for that.
Market share is all that matters here, not technology at all.
According to your reasoning, IE6 is the most secure browser because it has the most security patches. If you have fewer vulnerabilities to start with, you'll end up with fewer, simpler (and thus more reliable) security mechanisms.
Windows has improved a lot. I suppose 2008r2 is reasonably secure and should be able to stay secure when exposed to the net, but the internal complexity of its security mechanisms is huge and, therefore, a lot can go wrong.
Since XP SP2, Windows has led the way in protecting code itself. Linux is largely on par these days, with OS X trailing way behind (they're playing catch-up now).
As far as complexity, I strongly recommend you actually look at the protections in place. Those on Windows are significantly simpler (and more effective) than those on Linux, as of Windows Vista. The new heap, the simplified ASLR, etc all made things considerably simpler and harder to attack.
They are. It's an unavoidable fact of life for the kind of computer we use (read x86 PC). But don't confuse being potentially vulnerable to a type of attack to actually being vulnerable to a specific attack of this type. In order to be vulnerable, you not only have to, say, allow a user-mode program to write on a page marked as executable (something I remember some high-end processors from the late 80's could prevent) but you actually must have a buffer overflow to go with it. Unless both conditions are met, you are not at risk.
As far as actual complexity of the implementations are concerned, I can't evaluate Microsoft's, as the implementation is secret. I cannot, however, imagine how the Windows implementations can be simpler, for Windows is a much more complex operating system than either Linux or *BSDs. As alexandros pointed out, a larger surface means more to defend.
Thank you Microsoft for helping to clean up your mess!
That said, most botnets consist of old unpatched Windows computers or spreads via third-party software (e.g. Flash/Acrobat Reader), and MS' market share means that it will be targeted even if it their security is no worse than their competitors'. Windows security still could be better, but I don't think blaming Microsoft is as justified as it was before e.g. XP SP2.
Look for future malware to be spread using the biggest rarely updated smartphone platform (currently Android).
So, the only reason are actually 3?
The only thing that may come to their aid is that telcos have a power over the phones that connect to them no PC OS maker has. Well... Maybe Apple will get there...
And, BTW, once phone manufacturers realize they need to provide security updates for the life of the phones, they will trim their lineups down to very manageable levels.
I still believe Windows comes next.