On BNET: 3 worst things about the iPhone 3G S
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Aug 5, 2005 1:34:00 AM

Virus writers are targeting a new Microsoft tool that will be part of Windows and is set to ship as part of the next Exchange e-mail server release.

A virus writer has published the first examples of malicious code that targets Microsoft's upcoming command-line shell, code-named Monad, according to Finnish antivirus maker F-Secure. If the technology is included in Windows Vista, these could be one of the first viruses to target the new operating system formerly known as Longhorn, F-Secure said Thursday.

Monad, also known as MSH, is the replacement for the simple command shell in the current versions of Windows. A shell, also called a command line interface, allows a user to give a computer textual commands either from a keyboard or from a script. Monad has much more functionality, similar to shells in competing products such as Bash in Unix. However, by adding the ability to run more-complex scripts, Microsoft could possibly open another door to attackers.

Monad will support Windows Server 2003, Windows XP and Windows Vista, Microsoft representatives said in a Web chat late last year. However, the software maker has not disclosed how it will deliver the tool.

Related Audio
CNET News.com podcast
Security reporter Joris Evers talks
about the potential risk to new OS.

The examples that made it to the Web would cause little harm but could be modified, according to Mikko Hypponen, director of antivirus research at F-Secure.

Hypponen warned that if Microsoft ships Monad with Vista and it is enabled by default this could lead to an "outbreak of scripting viruses." Microsoft may choose to ship the tool as an add-on or disable it by default to reduce the risk, he added.

Microsoft initially planned to include Monad in Vista, formerly known by its Longhorn code-name. However, company representatives have said the tool would first ship as a feature of Exchange 12, due in the second half of 2006. Monad will ship in Windows after that, they said.

Monad is available to testers but is not part of the first Windows Vista beta, which Microsoft released last week, a company representative said Thursday. The shell tool also is not included in the beta of Windows Server 2003 R2, an update to Windows Server due later this year, the representative said.

"At this time, these reports pose no risk for Microsoft customers," the Microsoft representative said.

Microsoft has yet to announce how it will deliver Monad in the Windows operating system. A source familiar with Microsoft's plans said it is too early to say whether the new shell will make it into later beta versions of Windows Vista or the final product. Windows Vista is due on store shelves by the end of 2006.

Microsoft also could offer Monad as a downloadable add-on for Windows.

A Microsoft developer in a blog posting on Thursday criticized the F-Secure report. "It's a misleading title, as it's an issue that affects any vehicle for any executable code on any operating system," wrote Lee Holmes, who works on the team building Monad.

"The fact that MSH is used as the execution vehicle is really a side-note, as it does not exploit any vulnerabilities in Monad," Holmes wrote. "The guidance on shell script viruses is the same as the guidance on all viruses and malware: protect yourself against the point of entry, and limit the amount of damage that the malicious code can do."

In a December online chat session with developers, Microsoft representatives specifically addressed the topic of script attacks. The company is taking measures to prevent those. For example, Monad will run only scripts that are digitally signed by a trusted person. Additionally, it won't be possible to double click on a script and have it run, according to a transcript of the session.

The possibility of viruses being aimed at Microsoft's new shell was discussed at the Virus Bulletin event last year. Eric Chien of Symantec said at the antivirus industry event that the new tool could allow the creation of both classic viruses as well as e-mail worms.

Ingrid Marson of ZDNet UK contributed to this story.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 168 Talkback(s)
Script Bash
There is a potential problem with the script code.Please read the supplied removal instructions carefully.Undo the backplate on the pc towercase.Look for harddrive situated inside.Remove carefully.Ple... (Read the rest)
Posted by: Canario_z Posted on: 08/23/05 You are currently: a Guest | | Terms of Use
One week  wackoae | 08/04/05
RTFA  IT Scion | 08/04/05
Release of Beta  nucrash | 08/05/05
Ummm  IT Scion | 08/10/05
RE: One week  nightshade0143 | 08/05/05
They are TOO efficient.....  michael_t | 08/04/05
It is just easier to call you stupid.  IT Scion | 08/04/05
So IF I am 'stupid' as you claim you should be  michael_t | 08/04/05
Booyah!  Jeff Spicoli | 08/04/05
Funny.  IT Scion | 08/06/05
Welcome to the DefendMSwithFoamingattheMouthRage Club! Join  michael_t | 08/04/05
BWAHAHAHAHAHAHAHAHA!!!!!!!!  Jeff Spicoli | 08/04/05
Jeff, You Forgot Bitty  itanalyst | 08/05/05
Oh my!  Jeff Spicoli | 08/05/05
bittsnbites, shadetree  mactolinux | 08/09/05
All from a guy that believes in conspiracy theories with no evidence!  osreinstall | 08/05/05
Do you recall posting this;  ShadeTree | 08/05/05
SJVN at eWeek Knocks MS for NOT Including Monad  PMC-CON | 08/05/05
Dude, if I'm fictional..  Jeff Spicoli | 08/05/05
So, As I've Asked Before, How's Sean Penn Doing?  PMC-CON | 08/05/05
Rant, and rant, and rant and rant...  gardoglee | 08/05/05
Ha!  Jeff Spicoli | 08/05/05
Jumping the gun there mikey_troll  osreinstall | 08/05/05
RE: Jumping the gun there mikey_troll  nightshade0143 | 08/05/05
From experience  osreinstall | 08/05/05
RE: From experience  nightshade0143 | 08/06/05
I am glad you asked.  osreinstall | 08/06/05
If you are smart, then DARE you to  michael_t | 08/05/05
Step away from the kool-aid son!!  toadlife | 08/05/05
ALL systems can use scripting  michael_t | 08/05/05
Sendmail deja vu  hulse_kevin | 08/05/05
It seems this is an identical  michael_t | 08/05/05
How did they learn??  toadlife | 08/05/05
This is very educational there toady...  michael_t | 08/05/05
How is this different than Perl?  NonZealot | 08/05/05
I'll give you some time to think it over..... (nt)  michael_t | 08/05/05
Reading the article CAREFULLY...  Wolfie2K3 | 08/05/05
May not be a bad thing  rapson | 08/05/05
While I do agree  Michael Kelly | 08/05/05
I agree and see  michael_t | 08/05/05
Corrections  NonZealot | 08/05/05
Since when?  rapson | 08/05/05
COULDA, WOULDA, SHOULDA  zappattazz@... | 08/05/05
ZD Trolling?  frabjous | 08/05/05
Vista buncha Iconas and Wormas  michael_t | 08/05/05
I will type slower just for michael_t  zappattazz@... | 08/05/05
Then, dear viva Zappata, reply to HIM NOT to me...  michael_t | 08/05/05
Michael_t is responding?  zappattazz@... | 08/05/05
haha.. too many tackos today? Your blood left  michael_t | 08/05/05
Vista buncha Iconas and Wormas  wachin_flames | 08/05/05
Thanks, I'll keep you in mind for my spell-checking needs....  michael_t | 08/05/05
Thanks, I'll keep you in mind for my spell-checking needs....  wachin_flames | 08/05/05
This is ALWAYS TRUE for ALL OF US.  michael_t | 08/05/05
Could, Possibly, Maybe (Hype?)  John Zern | 08/05/05
Love these vapourware stories  Richard Flude | 08/04/05
Newsflash Richard!  toadlife | 08/05/05
Yup happy  CobraA1 | 08/05/05
Real pipes vs. DOS pipes.  hulse_kevin | 08/05/05
Re: Real pipes vs. DOS pipes.  node357 | 08/05/05
piping is one  michael_t | 08/05/05
thanks for mentioning those books  Jeff Spicoli | 08/05/05
I am just trying to imagine the  michael_t | 08/05/05
pipe / redirects  dwest_z | 08/05/05
oh and...  dwest_z | 08/05/05
ahhhh good'ol UNIX shell scripting. What a beauty  michael_t | 08/05/05
Another one who does get windows.  toadlife | 08/05/05
(nt) Whoops, I meant *doesn't* get Windows  toadlife | 08/05/05
hehehe .... my point exactly .... toady ;;;-)  michael_t | 08/05/05
Again the misunderstanding continues  Richard Flude | 08/06/05
Vaporware?  Loverock Davidson | 08/05/05
beta product  dwest_z | 08/05/05
Thats nice  Loverock Davidson | 08/05/05
I'd agreee  dwest_z | 08/05/05
hey vaporbrain...  cicuta | 08/05/05
Wait a sec  NonZealot | 08/05/05
No it's a target..  Jeff Spicoli | 08/05/05
RE: TalkBack 59 of 131:  nightshade0143 | 08/05/05
Well, then the potential virus is vapor as well  Boot_Agnostic | 08/05/05
Well, Let's Be Careful....  gamahucheur | 08/05/05
Will we get a pre-emptive patch from MS?  Prognosticator | 08/05/05
I don't blame ZDNet for this type of story  Otto_Delete | 08/05/05
Message has been deleted.  nucrash | 08/05/05
I outgrew this in 6th grade  frgough@... | 08/05/05
I wouldn't...  bill@... | 08/05/05
Good for you  nucrash | 08/05/05
seriously..  Jeff Spicoli | 08/05/05
I tried, but...  nucrash | 08/05/05
But did you ever wind up..  Jeff Spicoli | 08/05/05
It sits on my desk  nucrash | 08/05/05
Bwahahaha!!  Jeff Spicoli | 08/05/05
nice acronyms  woot! | 08/05/05
Well, some how I offended ZDnet.  nucrash | 08/05/05
Nucrash, Please Repost What Was Deleted  itanalyst | 08/05/05
Hahah, My first deleted Message...  nucrash | 08/05/05
If this is accurate then  michael_t | 08/05/05
Straight from MS R&D  nucrash | 08/05/05
Incidentally, MS Research has hired truely bright people  michael_t | 08/05/05
They like my ideas...  nucrash | 08/05/05
RE: link deleted  iwish40 | 08/05/05
Nothing top secret there  nucrash | 08/05/05
(nt)9.9 - hilarious happy  toadlife | 08/06/05
9.9 LUV the New Acronym (nt)  tbbrickster_z | 08/08/05
I am offended  nucrash | 08/05/05
I wouldn't sweat it  slingzenarrowzuvowtrayjissforchin | 08/05/05
MS plans to release a kit to ensure...  robgroh | 08/05/05
Right On  nucrash | 08/05/05
Thank God it's Friday....  robgroh | 08/05/05
Something to add...  nucrash | 08/05/05
First potential virus risk for Windows Vista found  Loverock Davidson | 08/05/05
I read the article  nucrash | 08/05/05
Look at the bright side  TrueSpeak | 08/05/05
You should hear about the other features  nucrash | 08/05/05
You MIGHT have read the entire article  zappattazz@... | 08/05/05
I understand  nucrash | 08/05/05
well it was an expected response  ~doolittle~ | 08/05/05
Real Sysadmins vs. pretenders.  hulse_kevin | 08/05/05
I agree that since  michael_t | 08/05/05
defintely looking in the mirror today dude  Monkey_MCSE | 08/05/05
I have no idea what you are saying (NT)  Loverock Davidson | 08/05/05
you seem to not know much of anything  Monkey_MCSE | 08/05/05
again you are not making sense  Loverock Davidson | 08/05/05
Where's the beef?  vdraken | 08/05/05
The Industry Calls It A Virus, Microsoft Calls It "Innovation"  itanalyst | 08/05/05
Obviously, we hear from another of the unknown  John Zern | 08/05/05
Huh?  CobraA1 | 08/05/05
Don't worry, it won't stop the fools from buying it.  HypnoToad | 08/05/05
Windows is Great for the un-educated  BuckRogers_z | 08/05/05
Except that  Hugh Jass | 08/05/05
darned tooten  Hrothgar - PCLinuxOS User | 08/06/05
What a surprise!  jgmsys@... | 08/05/05
Where does it say..  vdraken | 08/05/05
A real shell  node357 | 08/05/05
Ya just GOTTA laugh...  realitycheck101 | 08/05/05
Ya just GOTTA laugh...  skipplummer | 08/06/05
Only runs digitally signed scripts?  Jon Greer | 08/05/05
well then...  skipplummer | 08/06/05
If you all had atken the time to read and comprehend ...  ShadeTree | 08/05/05
ShadeTree  node357 | 08/05/05
I agree...  skipplummer | 08/06/05
Good grief  reconrad | 08/05/05
Good point  skipplummer | 08/06/05
Once again, ZDnet using "Enquirer" style headline  John Zern | 08/05/05
How I learned to live with the bomb and love it.  Awf Tin Wong | 08/05/05
Exactly...  skipplummer | 08/06/05
Dear Vista lofing people PROVIDE the PROS of this platform wrt Win XP  michael_t | 08/05/05
IF Vista is available for FREE....  zappattazz@... | 08/05/05
Hmmm.. the gray matter function is deteriorating...  michael_t | 08/05/05
Dear Vista...  skipplummer | 08/06/05
I have to laugh...  kokuryu | 08/05/05
No problem here  zmud | 08/05/05
This is BETA, right?  crash89 | 08/05/05
BETA or not  DarthRidiculous | 08/05/05
you're right...  skipplummer | 08/06/05
"95 %"  brian ansorge | 08/05/05
Nice try  slingzenarrowzuvowtrayjissforchin | 08/05/05
The lonely 5%  TN-Limey | 08/05/05
Completely off topic..  cicuta | 08/05/05
come back in 2 days  Airwolph | 08/05/05
OSS not ISS... my bad. (nt)  Airwolph | 08/05/05
Monad is Bad Idea for Microsoft -- Attack Surface  PMC-CON | 08/05/05
probably best point yet...  skipplummer | 08/06/05
A few "assets" I want removed.  Nekow42 | 08/06/05
Before SP1....  nucrash | 08/08/05
Let's keep the memory alive for the IMPORTANT issues here  michael_t | 08/05/05
MicroInfected  gamerzworld | 08/05/05
if they didn't...  skipplummer | 08/06/05
hmmm .... nice code!  Reverend MacFellow | 08/12/05
Script Bash  Canario_z | 08/23/05

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

Smartphones

  • Last year, many businesses deferred the purchase of new laptops in favor of smartphones, and why not? Offering phone, calendar, email, IM and Web access, they're arguably the most practical business tools. Check out the latest CNET Reviews of Blackberry devices for all the knowledge you need to make an intelligent choice.
  • Designed for
    bold living.
  • blackberry bold
  • Edit Word docs, check email, even listen to iTunes® playlists. Do more and do it faster with the BlackBerry® Bold™.Learn more
  • blackberry logo
advertisement
Click Here