On BNET: IE users envy Firefox no more
BNET Business Network:
BNET
TechRepublic
ZDNet

By Tom Espiner, ZDNet (UK)
Posted on ZDNet News: Nov 13, 2007 6:56:00 AM

A Microsoft executive calls the ease with which two British e-crime specialists managed to hack into a Windows XP computer as both "enlightening and frightening."

The demonstration took place Monday at an event sponsored by Get Safe Online--a joint initiative of the U.K. government and industry. At the event, which was aimed at heightening security awareness among small businesses, two members of the U.K. government intelligence group Serious Organized Crime Agency connected a machine running Windows XP with Service Pack 1 to an unsecured wireless network. The machine was running no antivirus, firewall, or anti-spyware software and contained a sample target file of passwords to be stolen.

The SOCA officials wished to remain anonymous. One of them, "Mick," remained behind a screen while carrying out the hack into the unpatched computer of a fellow officer, "Andy."

"It's easy to connect to an unsecured wireless network," said Mick. "You could equate Andy with being in his bedroom, while I'm scanning for networks outside in my car. If I ordered or viewed illegal materials, it would come back to Andy."

Mick used a common, open-source exploit-finding tool he had downloaded from the Internet. SOCA asked ZDNet UK not to divulge the name of the tool.

"You can download attack tools from the Internet, and even script kiddies can use this one," said Mick.

Mick found the IP address of his own computer by using the XP Wireless Network Connection Status dialog box. He deduced the IP address of Andy's computer by typing different numerically adjacent addresses in that IP range into the attack tool, then scanning the addresses to see if they belonged to a vulnerable machine.

Using a different attack tool, he produced a security report detailing the vulnerabilities found on the system. Mick decided to exploit one of them. Using the attack tool, Mick built a piece of malware in MS-DOS, giving it a payload that would exploit the flaw within a couple of minutes.

Getting onto the unsecured wireless network, pinging possible IP addresses of other computers on the network, finding Andy's unpatched computer, scanning open ports for vulnerabilities, using the attack tool to build an exploit, and using the malware to get into the XP command shell took six minutes.

"If you were in (a cafe with Wi-Fi access), your coffee wouldn't even have cooled down yet," said Sharon Lemon, deputy director of SOCA's e-crime unit.

Mick then went into the My Documents folder and, using a trivial transfer protocol, transferred the document containing passwords to his own computer. The whole process took 11 minutes.

A SOCA representative said that the demonstration was "purely to point out that, if a system hasn't had patches, it's a relatively simple matter to hack into it." SOCA stopped short of recommending small businesses move to Vista; a SOCA representative said that applying Service Pack 2 to XP, with all the patches applied, and running a secured wireless network is "perfectly sensible way to do it."

Nick McGrath, head of platform strategy for Microsoft U.K., was surprised by the incident.

"In the demonstration we saw, it was both enlightening and frightening to witness the seeming ease of the attack on the (Windows) computer," said McGrath. "But the computer was new, not updated, and not patched."

McGrath said that having anti-spyware installed was not as important as having the software updated. He added that Microsoft works closely with original equipment manufacturers to encourage the preloading of antivirus and anti-spyware on a 30-day trial basis. McGrath also said that Service Pack 2 for XP had a firewall and that Vista was not as "accessible to the average hacker" due to "operating system components."

Tom Espiner of ZDNet UK reported from London.

©2007 CNET Networks, Inc. All rights reserved. CNET , CNET.com , and the CNET logo are registered trademarks of CNET Networks, Inc. Used by permission.

  • Talkback
  • Most Recent of 247 Talkback(s)
RE: Microsoft exec calls XP hack 'frightening'
Unrealistic - who today uses an unprotected PC? (Read the rest)
Posted by: quark@... Posted on: 01/17/08 You are currently: Logged In | Log out
Pity that... kriskl   | 11/13/07
i doubt it ehansen9   | 11/13/07
Well, Gee lets see Crestview   | 11/14/07
Are you for real? will.hunt.007@...   | 12/26/07
Reeks of trying to promote Vista PI_z   | 11/15/07
I went Gnu/Linux Ubuntu instead Free-BooteR   | 11/15/07
Then obviously you have missed the whole point. GuidingLight   | 11/15/07
That would be the cover story of choice but who Knows! - NT raycote   | 11/15/07
Windows has bulletproof security ... fr0thy   | 11/16/07
Last Hurrah? clivebrookes@...   | 11/19/07
Reeks of trying to promote Vista ronw1@...   | 11/28/07
Vista or... mscir@...   | 12/08/07
The reason they tried SP1 unpatched... Boomslang   | 12/17/07
Hack Vista ceh4702   | 01/03/08
Service Pack 1 ? magcomment   | 11/13/07
I think they are trying to see that the majority of PCs are setup like this Been_Done_Before   | 11/13/07
i disagree... brokndodge@...   | 11/13/07
WIFI Bandits ceh4702   | 01/03/08
Very poor demo? Not as bad as ... netuzer   | 11/13/07
FUD ajv123   | 11/16/07
McRosoft security video fr0thy   | 11/16/07
But of course... Qbt   | 11/13/07
Clueless? davidsarmstrong   | 11/13/07
Look internally for your hacker. dbisse@...   | 11/14/07
url? mscir@...   | 12/08/07
url? Hyperion1961@...   | 01/04/08
As one of your so-called "Clueless Ones".... drprod@...   | 11/14/07
BY JOVE, SOMEONE FINALLY GOT IT!!! mac0252   | 11/15/07
Some people can't read. Rndmacts   | 11/16/07
Sure ajv123   | 11/16/07
I agree jtew@...   | 12/18/07
All your systems belong to ... apparently anyone! nomoremicrosoft   | 11/13/07
See George's post below (nt) ShadeTree   | 11/13/07
re: All your systems Badgered   | 11/13/07
Any unpatched system is worthless. tracy anne   | 11/15/07
Evidently you don't know much about Windows timmeh64   | 11/14/07
Unpatched tracy anne   | 11/15/07
You should actually READ the story Crestview   | 11/14/07
No he probably loves his dog fr0thy   | 11/16/07
If you knew my dog... davagain   | 11/28/07
Your comment jtew@...   | 12/18/07
Not exactly a fair test Chad_z   | 11/13/07
that's why you gotta be... ehansen9   | 11/13/07
Indeed tracy anne   | 11/15/07
Crying all the way Yagotta B. Kidding   | 11/13/07
Dood... dracolich_prgrm   | 11/13/07
Amen, Amen, Amen. Tubaplayr   | 11/14/07
Disgruntled employees jtew@...   | 12/18/07
Exactly.... wrong Crestview   | 11/14/07
Subtlety must be foreign to you... Rbust0   | 11/15/07
which part of this is a news to anybody? vgrig   | 11/13/07
Publicity Stunt, you bet xrxca   | 11/13/07
huh... no one in my neighborhood seems to know it... brokndodge@...   | 11/13/07
Fully patched Mac hacked this year georgeou   | 11/13/07
Not news, it's history magcomment   | 11/13/07
Yes, but the hole was plugged and there are no active exploits... olePigeon   | 11/13/07
olePigeon how do you know that real hacker don't tell everything SO.CAL Guy   | 11/13/07
don't be too sure of yourself! ehansen9   | 11/13/07
Curious how you equate that to news? ju1ce   | 11/13/07
Bad Post George TheBoyBailey   | 11/13/07
Ou is "The New Dvorak"! dropzone@...   | 11/14/07
Becauuuuse, it's about as much "news" John E Wahd   | 11/13/07
After they 'relaxed the rules' RealNonZealot   | 11/13/07
How do you think most exploits come through? georgeou   | 11/13/07
haha iMouse   | 11/13/07
IF you're not an Apple Fanboy... 1stcyberian   | 11/15/07
Go easy on M$ fanbois like Ou... comp_indiana   | 12/06/07
Windows XP systems, firewall quandries . . . Computer_User_1024   | 11/13/07
Building awareness HooNoze   | 11/13/07
Even when hiring experts.. ju1ce   | 11/13/07
RE: Microsoft exec calls XP hack 'frightening' Loverock Davidson   | 11/13/07
Flawed Article and Flawed Research? ju1ce   | 11/13/07
Yes Loverock Davidson   | 11/13/07
Maybe true for Windows ... davidsarmstrong   | 11/13/07
And true for other OS's Loverock Davidson   | 11/13/07
thats what firewalls on the router are for!!!(NT) brokndodge@...   | 11/14/07
Funny davidsarmstrong   | 11/14/07
TElnet davidsarmstrong   | 11/14/07
No putt1ck   | 11/14/07
LOL! thx-1138_@...   | 11/15/07
I can't believe I'm defending MS! davagain   | 11/28/07
Telnet in Linux Computer_User_1024   | 11/14/07
Further more re: Linux ports. . . Computer_User_1024   | 11/14/07
Obviously knows nothing about Linux tracy anne   | 11/15/07
hacking voska   | 11/13/07
You have not! ShadeTree   | 11/13/07
huh? voska   | 11/13/07
Were you in the room when it happened? mdemuth   | 11/13/07
I've done it myself, it's simple voska   | 11/13/07
Just to point out voska   | 11/13/07
VMware appliance johnf76@...   | 11/13/07
i've done it too! ehansen9   | 11/13/07
Ours were hacked davidsarmstrong   | 11/13/07
Netcat The Swiss Army Knife Of Hacking chessmen   | 11/14/07
Yea U think so Krazyken39   | 11/14/07
People like you Crestview   | 11/14/07
And in another demo... RocketEater   | 11/13/07
Yeah, what he said!... Media-Ted@...   | 11/14/07
Reverse power surge THEE WOLF   | 11/13/07
Err... dracolich_prgrm   | 11/13/07
shouldn't be too hard... brokndodge@...   | 11/14/07
Reverse power surge - how to get??? serioussam2x4@...   | 12/30/07
Pity they didn't try an OS from the last 5 years No_Ax_to_Grind   | 11/13/07
Astonishing though it is... bmerc   | 11/13/07
the point is ... brokndodge@...   | 11/14/07
Fools abound, that is true. No_Ax_to_Grind   | 11/14/07
Wouldn't matter voska   | 11/13/07
Interesting saggy   | 11/14/07
Not new OS but used OS sysop-dr   | 11/13/07
Has nothing to do with Vista No_Ax_to_Grind   | 11/14/07
Or ... thx-1138_@...   | 11/14/07
"hourse whipped"? nizuse   | 11/19/07
How to Secure Ubuntu7.10 mscir@...   | 12/08/07
Yep thx-1138_@...   | 11/15/07
Disagree on one point CobraA1   | 11/28/07
Message has been deleted. itanalyst   | 11/13/07
Message has been deleted. No_Ax_to_Grind   | 11/14/07
Message has been deleted. itanalyst   | 11/14/07
Wow, shocking... NOT! Larsix   | 11/13/07
Fighting the last war tigerg2002us@...   | 11/13/07
Requiring Antivirus... TucsonGuy   | 11/13/07
RE: Microsoft exec calls XP hack 'frightening' Basel 101   | 11/13/07
RE: This is not news :P ehansen9   | 11/13/07
Not very useful info davidr69   | 11/13/07
RE: Microsoft exec calls XP hack 'frightening' Don't Ask Me   | 11/13/07
no!!!!! i never wanted to be a slave! ehansen9   | 11/13/07
Newly installed OS mcaprio_z   | 11/13/07
Plan ahead TucsonGuy   | 11/13/07
No Firewal!?!?!?!?! byronldowell@...   | 11/13/07
With or Without, doesn't matter davidsarmstrong   | 11/13/07
Well... dracolich_prgrm   | 11/13/07
Sounds to me.. 3D0G   | 11/14/07
Admin davidsarmstrong   | 11/15/07
So in other words... 3D0G   | 11/15/07
So why only the Windows Boxes? davidsarmstrong   | 11/21/07
Users don't run as root in Linux. CobraA1   | 11/28/07
Yes and no CobraA1   | 11/28/07
Typical when you run as Root or Administrator... Boomslang   | 12/17/07
Microsoft exec calls XP hack 'frightening' morph000   | 11/13/07
Sussed Dr.C   | 11/14/07
RE: Microsoft exec calls XP hack 'frightening' Farrell.McGovern   | 11/13/07
Wowing the idiots with the phrase SCRIPT KIDDIES MOUSE_OVER_THIS   | 11/13/07
RE: Microsoft exec calls XP hack 'frightening' eagleau2003@...   | 11/13/07
RE: Microsoft exec calls XP hack 'frightening' excrementologist@...   | 11/13/07
PDF ceh4702   | 11/13/07
Duh! fr0thy   | 11/16/07
LOL kokuryu   | 11/13/07
Wireless...with ABSOLUTELY NO protection ?:| ....... btljooz   | 11/13/07
Huh? dracolich_prgrm   | 11/13/07
If you REALLY have to ask btljooz   | 11/14/07
re: wireless with no protection... Computer_User_1024   | 11/14/07
That's precisely WHY btljooz   | 11/14/07
Yes SP1 hisfool@...   | 11/13/07
XP SP1 Computer_User_1024   | 11/14/07
Simple solution to Granny's ignorance: btljooz   | 11/14/07
re: "Granny's Ignorance" Computer_User_1024   | 11/14/07
Are you talking about btljooz   | 11/15/07
The "Granny" Computer_User_1024   | 11/28/07
Paranoia??? I'd rather be paranoid than btljooz   | 11/29/07
RE: Microsoft exec calls XP hack 'frightening' walkerjian@...   | 11/13/07
Solution to patching off-line Computer_User_1024   | 11/28/07
SP1 still alive and well... jrf2027@...   | 11/13/07
RE: Microsoft exec calls XP hack 'frightening' junkmail@...   | 11/13/07
Someone has to reach the old “pre ADSL” crippled machines. alvinfinch@...   | 11/13/07
FUD again tonymcs@...   | 11/13/07
That was the point I tried to make above :) btljooz   | 11/14/07
... dimonWar   | 11/13/07
RE: Microsoft exec calls XP hack 'frightening' americancryptid@...   | 11/13/07
RE: Microsoft exec calls XP hack 'frightening' jackofalltradesmasterofnone   | 11/13/07
XP-Intrusions jackofalltradesmasterofnone   | 11/13/07
Non issue? Disagree TG2   | 11/13/07
What is this? John Musbach   | 11/13/07
RE: Microsoft exec calls XP hack 'frightening' fourijm@...   | 11/13/07
What a good deal of Windows XP users don't realize . . Computer_User_1024   | 11/13/07
If you think THAT is bad, what do you think of this ?:| btljooz   | 11/14/07
re: NSA KEY Computer_User_1024   | 11/14/07
Are you really surprised? mscir@...   | 12/08/07
No. ...True. Highly Likely. No. N/T. btljooz   | 12/28/07
Wireless networks Computer_User_1024   | 11/14/07
RE: Microsoft exec calls XP hack 'frightening' kmashraf   | 11/14/07
RE: Microsoft exec calls XP hack 'frightening' atari8bit@...   | 11/14/07
RE: Microsoft exec calls XP hack 'frightening' Nannuu   | 11/14/07
Besides being informative Boot_Agnostic   | 11/14/07
Again ZDnet Krazyken39   | 11/14/07
This is news? DCMann   | 11/14/07
Encouraging Or Frightening Sickthing   | 11/14/07
Microsoft execs call XP Hack a great path to Vista! tim914   | 11/14/07
Can't WEP keys be cracked in just a few minutes now? mscir@...   | 12/08/07
Extremely Good point!!! Thank you. n/t btljooz   | 12/28/07
Not as unlikely as you think... Commochief   | 11/14/07
This all depends on your setup erniem1970@...   | 11/14/07
RE: Microsoft exec calls XP hack 'frightening' jackduffie   | 11/14/07
RE: Microsoft exec calls XP hack 'frightening' miles2go_2000@...   | 11/14/07
SERVICE PACK 1? Thats OLD !!! JABBER_WOLF   | 11/14/07
Scared to Death, yeah right gwbs4@...   | 11/14/07
Just a Designed Ploy to sell Vista support@...   | 11/14/07
I agree this is a problem. support@...   | 11/14/07
Frightening brichter   | 11/14/07
Ok I admit... dbisse@...   | 11/14/07
Vista to the rescue! jscarey   | 11/14/07
RE: Microsoft exec calls XP hack 'frightening' catseverywhere@...   | 11/14/07
Gut Reaction TSEG72351@...   | 11/15/07
Handicapped PC Axotls   | 11/15/07
Exactly! thx-1138_@...   | 11/15/07
RE: ROFL onedavester@...   | 11/15/07
RE: Microsoft exec calls XP hack 'frightening' Sheeva   | 11/15/07
You must have some very old apps willpd13   | 11/16/07
Wrong Sheeva   | 12/06/07
MS Calls Security Holes Frightening!!!!!! cam@...   | 11/15/07
A burn Louis.Ross@...   | 11/16/07
I think you are missing the big picture! Patrick_m   | 11/15/07
Microsoft is Scary amahanna   | 11/15/07
RE: Microsoft exec calls XP hack 'frightening' echodelta@...   | 11/15/07
The real revelation rotvic   | 11/15/07
Velly Intelesting vvbs@...   | 11/15/07
RE: Microsoft exec calls XP hack 'frightening' Vampyrick   | 11/15/07
Thanks for mentioning Clean Access mscir@...   | 12/08/07
Hacking an unpatched system with no anti-virus,firewall, etc....WHAT!!!!!! mikemc3@...   | 11/15/07
Currently relevant clb1017   | 11/15/07
Article Misnamed thx-1138_@...   | 11/15/07
Worthless Test! XweAponX   | 11/16/07
Deserves!! wez@...   | 11/18/07
My thoughts exactly* hidalgod@...   | 11/16/07
What does this say about the quality of MS software? FlatAffect   | 11/20/07
Never connect to unsecured wireless CobraA1   | 11/28/07
I agree Computer_User_1024   | 11/28/07
I've been using AVG and Spybot S&D. CobraA1   | 11/28/07
Router recommendation? mscir@...   | 12/08/07
Simple answer: btljooz   | 12/28/07
RE: Microsoft exec calls XP hack 'frightening' DWFRIEND@...   | 11/28/07
reads a lot merc2dogs`   | 11/28/07
Think first then speak denbid@...   | 11/28/07
Nice Post mscir@...   | 12/08/07
RE: Microsoft exec calls XP hack 'frightening' rinie@...   | 11/28/07
M$ ecex frightened? I'm frightened waldoalvarez00@...   | 12/04/07
They don't pay us enough to know those things Chiatzu   | 12/13/07
Ummmmm .... koala1515   | 12/13/07