The Inquirer-Home

Duqu infections are blamed on Microsoft Windows

Attacks are down to a zero-day exploit
Wed Nov 02 2011, 09:22

SOFTWARE FIRM Microsoft has been blamed for letting the Duqu virus loose upon the world.

The Duqu virus was discovered earlier this month but until now no one knew how it was infecting machines. According to a report by security firm Symantec that is based on work by the Budapest-based Laboratory of Cryptography and System Security (CrySyS), it spread because of a security hole in Windows, which, let's face it, probably should not have surprised anyone.

"The installer file is a Microsoft Word document (.doc) that exploits a previously unknown kernel vulnerability that allows code execution. When the file is opened, malicious code executes and installs the main Duqu binaries," writes Symantec on its security blog. "The Word document was crafted in such a way as to definitively target the intended receiving organisation."

The attacks were well targeted then, and Symantec says that there were neither best practices nor workarounds for any infected organisations to turn to.

"Unfortunately, no robust workarounds exist at this time other than following best practices, such as avoiding documents from unknown parties and utilising alternative software," it adds.

"Once Duqu is able to get a foothold in an organisation through the zero-day exploit, the attackers can command it to spread to other computers." So far infections have been spotted in a handful of countries including the United Kingdom, Austria and Hungary.

Microsoft has acknowledged the problem and on Twitter its security response team says that it is looking into it. "We are working to address a vulnerability believed to be connected to the Duqu malware," it says. µ

Share this:

Comments
Another Linux box hacked, Not surprising

Wow at the ignorance.

SUSE Linux 10, 3,500 vulnerabilties
Windows 2008 R2 Server, ~ 200 vulnerabilities.

(secunia.org)

So not surprisingly you are much more likely to be hacked running Linux than you are Windows:

http://www.zone-h.org/news/id/4737

posted by : TDR, 01 December 2011 Complain about this comment
Shouldn't be using MS Windows in the first place

Umm...it always amazes me that these outfits continue with Microsoft when its INsecurity record is so glaring and long-standing. They should've moved to a GNU/Linux or *BSD solution long ago. Well, this is an opportunity to do so.

posted by : Sum Yung Gai, 03 November 2011 Complain about this comment
Duh

But this is all worth it to have documents with kernel access. How else could one get such INNOVATIVE features as point and click and cut and paste?

posted by : Hucklebuck, 02 November 2011 Complain about this comment
kernel exploit?

kinda lumpy peanut butter exploit surely?

posted by : madtom1999, 02 November 2011 Complain about this comment
aboutus
Advertisement
Subscribe to INQ newsletters
Advertisement
INQ Poll

Facebook starts selling shares

Will you buy Facebook shares?