Windows XP Help attacks on the rise - gHacks Tech News

Windows XP Help attacks on the rise

Update: Microsoft has patched the issue and it is no longer a problem provided that Windows users have patched their system with the most recent security updates provided by the company.

An unpatched bug in the Windows XP Help and Support system is being increasingly used in attacks by virus and malware writers reports the BBC.

Microsoft reported it's seen more than 10,000 PCs hit by the attack so far and that it has not been able to find a fix for the problem.

A successful exploit of the issue gives hackers complete control over the PC.  It initially came to light when a Google Engineer discovered it was possible to exploit Windows XP's ability to send and receive remote help from another computer.

Microsoft said it only saw "innocuous" attacks by a few researchers first but discovered later on that hi-tech criminals are exploiting it as well.

Writing on the Microsoft Security Centre blog, Holly Stewart said it had started seeing "seemingly-automated, randomly-generated" web pages that host the exploit.

A senior security researcher at Trend Micro, Rik Ferguson, said  "It's certainly very serious and is now being actively exploited by what appears to be several different groups as you can see form the multiple payloads being delivered." and Carole Thierault, senior security consultant as security firm Sophos described the attacks as a "nightmare".

Microsoft is still working on a fix for the problem but Engadget have reported that...

Microsoft says the only current work around to the issue is to Unregister the HCP Protocol which disables hcp:// style links

The vulnerability does not affect Windows Vista or Windows 7. Users should avoid clicking on links that begin with hcp as that is the requirement for an successful attack on the user system.

Windows XP and Windows Server 2003 users can read the following guide to find out how to protect their system from the attack: Windows XP And Windows Server 2003 Zero-Day Vulnerability





  • We need your help

    Advertising revenue is falling fast across the Internet, and independently-run sites like Ghacks are hit hardest by it. The advertising model in its current form is coming to an end, and we have to find other ways to continue operating this site.

    We are committed to keeping our content free and independent, which means no paywalls, no sponsored posts, no annoying ad formats (video ads) or subscription fees.

    If you like our content, and would like to help, please consider making a contribution:

    Comments

    1. dan said on July 1, 2010 at 5:20 pm
      Reply

      It would be helpful to supply a link to the ghacks blog entry that supplied a registry fix to this vulnerability.

      1. Martin said on July 1, 2010 at 5:50 pm
        Reply

        You are right, done that.

    2. Chris said on July 1, 2010 at 5:49 pm
      Reply

      What is the point of the BBC and this article?

      The fix was posted by M$ weeks ago:
      http://support.microsoft.com/kb/2219475

      1. Martin said on July 1, 2010 at 5:49 pm
        Reply
    3. Mike J said on July 3, 2010 at 5:06 pm
      Reply

      Couldn’t a person just disable the Help and Support service, and be safe? Who ever uses it?? Outside of a business context, I suppose.

    4. Windows XP Help said on July 15, 2011 at 8:29 pm
      Reply

      pretty crazy, it is probably worth switching to Windows 7 just to avoid this

    Leave a Reply