Slim Down for Summer with That's Fit
AOL Tech

Hackers use Windows Update to download malicious code

HackersMicrosoft's Windows Update has a component called Background Intelligent Transfer Service (BITS) that downloads updates while you're busy doing other things with your computer. If you get disconnected, the update will pick up where it left off when you get back on the network.

Sounds great, right? Well, generally it is. But since BITS is part of your operating system, your firewall doesn't really check to see what it's downloading. And while there is pretty much no risk of automatically downloading a virus or trojan through Windows Update under normal circumstances, hackers are starting to use BITS to download code to computers that have already been affected.

Say you click that file attachment in an email from an unknown source, expecting to see compromising photos of a young starlet. Turns out there's no photo, so you shrug and move on. Next thing you know, you're computer's trying to download all sorts of files to capture your passwords. Normally your firewall would help protect your computer from such attacks, but since BITS can fly under the radar, you may be out of luck.

According to a Symantec researcher there's no way to prevent hackers from using BITS right now, but Microsoft could redesign BITS to require a higher user level in order to work. Or Microsoft could only allow BITS to download files from trusted sources.

Reader Comments (Page 1 of 2)

Download Squad Features


Geeking out on the squadcast. Tune in and then tune out.

View Posts By

  • Windows Only
  • Mac Only
  • Linux Only
Categories
Audio (830)
Beta (328)
Blogging (688)
Browsers (21)
Business (1362)
Design (808)
Developer (928)
E-mail (514)
Finance (127)
Fun (1736)
Games (546)
Internet (4759)
Kids (130)
Office (491)
OS Updates (574)
P2P (176)
Photo (460)
Podcasting (167)
Productivity (1305)
Search (249)
Security (536)
Social Software (1091)
Text (436)
Troubleshooting (51)
Utilities (1915)
Video (1011)
VoIP (138)
web 2.0 (741)
Web services (3323)
Companies
Adobe (184)
AOL (48)
Apache Foundation (1)
Apple (467)
Canonical (35)
Google (1299)
IBM (28)
Microsoft (1304)
Mozilla (457)
Novell (19)
OpenOffice.org (43)
PalmSource (11)
Red Hat (17)
Symantec (14)
Yahoo! (351)
License
Commercial (667)
Shareware (194)
Freeware (1955)
Open Source (897)
Misc
Podcasts (13)
Features (381)
Hardware (167)
News (1108)
Holiday Gift Guide (15)
Platforms
Windows (3586)
Windows Mobile (422)
BlackBerry (44)
Macintosh (2058)
iPhone (83)
Linux (1571)
Unix (78)
Palm (177)
Symbian (122)
Columns
Ask DLS (10)
Analysis (24)
Browser Tips (294)
DLS Podcast (5)
Googleholic (196)
How-Tos (97)
DLS Interviews (19)
Design Tips (14)
Mobile Minute (125)
Mods (68)
Time-Wasters (374)
Weekend Review (38)
Imaging Tips (32)

RESOURCES

RSS NEWSFEEDS

Powered by Blogsmith

Sponsored Links

Advertise with Download Squad

Most Commented On (60 days)

Recent Comments

Urlesque Headlines

BloggingStocks Tech Coverage

More from AOL Money and Finance

More Tech Coverage

Weblogs, Inc. Network

Other Weblogs Inc. Network blogs you might be interested in: