According to one outside analysis, SP2's Windows Security Center, the dashboard-like console that monitors and reports on the status of various security defenses -- from firewalls to anti-virus software -- can be spoofed by hackers into displaying false information, such as an enabled firewall or a even a totally bogus anti-virus package supposedly protecting the PC.
Security status could be faked, said the researchers, by a number of possible exploit avenues, including the drag-and-drop vulnerability in Internet Explorer that was made public last week. The possible goal by hackers: disable defenses but at the same time remain under the radar.
Many in-the-wild worms intentionally disable long lists of firewalls and anti-virus products. Recent variations of the Bagle worm, for instance, target almost 300 different pieces of protective software for termination. By combining that trait with this spoof, worms could infect a PC and yet remain undetected by the user.
Microsoft denied that Windows Security Center has a vulnerability. "In order for an attacker to spoof the Windows Security Center, he or she would have to have local administrator rights on the computer," Microsoft said in an e-mailed statement.
True, but that may not be much of a defense, since home users in particular often run Windows in Administrator Mode. Enterprises, wary of the total control that mode gives end users, typically sets up PCs to run in Limited Mode.
The Redmond, Wash.-based developer also claimed that even if a system was compromised -- perhaps by other malicious code that gave attackers administrator rights -- any exploit of the console was the least of users' worries.
"Criminal actions the attacker could pursue include many that are far more interesting than spoofing the Windows Security Center," Microsoft said.
This defense -- that the bigger security holes in Windows are the real honeypots for hackers, and thus smaller flaws can be safely ignored -- is a new one from Microsoft.
BP seeking Regional Desktop Coordinator in Houston, TX
Agilent Technologies seeking Marketing Manager in Melbourne, AU
Advancement Project seeking Junior Web Developer in Los Angeles, CA
Johns Hopkins Univ Carey Business School seeking Asst Dean for IS in Baltimore, MD
City of Westland seeking MIS Director in Westland, MI
For more great jobs, career-related news, features and services, please visit our Career Center.
Web Reputation Filters Battle the Latest Web Malware Threats
IronPort Web Reputation Filters™ are designed to combat the dynamic nature of malware. Today’s threats are no longer found as an email attachment. Instead, they are well orchestrated – utilizing social engineering techniques and target legitimate websites. As the first line of malware defense, IronPort Web Reputation Filters analyze more than 5 billion Web transactions daily – blocking up to 70 percent of malware at the connection level, prior to signature scanning. By leveraging its global footprint of URL traffic data IronPort’s Web reputation system is able to offer an industry-leading 60 percent higher malware catch rate than traditional signature scanners.

NOTE: Offer valid for U.S., U.S. possessions, & Canada only