Advertisement
Promo

Security threats Toolkit

Microsoft investigating fake security email

Munir Kotadia ZDNet Australia

Published: 30 May 2006 09:40 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft is investigating an email that pretends to be a security warning from the software heavyweight which patches a vulnerability in the "WinLogon Service".

The email has a spoofed "from" field so it looks like it has been sent from patch@microsoft.com. In reality it is most likely being mass spammed from an army of PCs that have been compromised and are under the control of a cybercriminal group.

A Microsoft spokesperson said on Monday morning that the vulnerability the email warns of does not exist, and that users should ignore the email.

"Microsoft advises users to ignore an email currently circulating which claims to provide a patch to a 'vulnerability in the WinLogon service' and implies it has been sent by Microsoft.

"This email is not from Microsoft Corporation and the claimed vulnerability and patch do not exist... Microsoft is currently investigating this fraudulent email," the spokesperson said.

If users have already been duped into clicking on the link, the spokesperson advised users to "immediately scan their computer using antivirus and antispyware tools".

Three years ago, the Swen worm (also known as Gibe.F) posed as a Microsoft security bulletin, and managed to infect millions of unpatched PCs.

The success of this led to numerous copycat messages, but none have so far managed to replicate Swen's success.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
143 out of 325 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:













Video icon

Video

Sentry Posts Blog

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Beware of keeping your head in the clo...

Information security professionals can look forward to a deepening appreciation for their skills as security continues to be recognised as an essential element for doing business in... More

1 comment

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters