March 27, 2009 5:35 PM PDT

U.K. parliament computers get Confickered

by Elinor Mills
  • Font size
  • Print
  • 11 comments

You'd think the British government would be up on the latest and greatest security practices, but apparently even officials there have their problems.

The U.K. parliament's computer network has been infected with the Conficker worm, according to the Dizzy Thinks blog.

In his own blog post, Trend Micro security researcher Rik Ferguson questioned the security practices that could have allowed Conficker onto such hallowed turf. "Dear Parliament, if you are having trouble cleaning this up, give us a call, we'll come and do it for nothing," he offers.

Below is the text of the e-mail that Dizzy says was sent to users of the infected official network:

To: All users connecting directly to the Parliamentary Network

The Parliamentary Network has been affected by a virus known as conficker. This virus affects users by slowing down the Network and by locking out some accounts. We are continuining [sic] to work with our third party partners to manage its removal and we need to act swiftly to clean computers that are infected.

We are scanning the Network and if we identify any equipment which we believe is infected with the virus then we will contact you to ensure that the device is either removed from the Network or cleaned and loaded with the correct software to prevent this infection reoccurring.

You can help us to contain this problem and prevent new infection by adhering to the following advice:

--We are unable to clean PCs and portable computers which are either not switched on or which are not authorised devices. We therefore ask that if you are running a PC or portable computer not authorised to be on the Network that you take it off immediately.

--An additional characteristic of this virus is that for some types of files it can skip direct to the Network from a USB memory stick or other portable storage device (e.g. mp3 players) without hitting the virus checker software. We ask that for the time being you do not use memory sticks or any other portable storage devices on the Parliamentary Network.

--If you do identify a problem with the equipment you are running, please contact the PICT Service Desk on 020 7219 2001 when it reopens on Wednesday 25 March from 8am.

--If you are connecting using one of our remote access services, from a Constituency Office for example, a separate communication will be sent to you. Director of Parliamentary ICT.

Elinor Mills covers Internet security and privacy. She joined CNET News in 2005 after working as a foreign correspondent for Reuters in Portugal and writing for The Industry Standard, the IDG News Service, and the Associated Press. E-mail Elinor.
Recent posts from Security
Web-based Lookout protects mobile devices, data
Hackers claim to crack Kindle copyright armor
Using Facebook and Twitter safely
Report: FBI investigating Citibank cyberattack
White House appoints cybersecurity chief
So, is it safe to tweet now?
Twitter hijacked by 'Iranian Cyber Army'
Firefox, Adobe top buggiest-software list
Add a Comment (Log in or register) (11 Comments)
  • prev
  • 1
  • next
by rayzoredge March 27, 2009 5:56 PM PDT
What I don't understand is why people are still getting infected, even after all of the bad press about Conficker. Does M$'s hotfix not work, or are people just retarded and/or live under a rock?
Reply to this comment
by tm_anon March 27, 2009 8:26 PM PDT
It's a little of both actually. The hotfix was made to stop the installation in the way it originally manifested. Now it's possible to get infected with a fully patched machine through a USB drive as well. I'd think Parliament would have switched to Linux by now.
by viper396 March 27, 2009 9:02 PM PDT
@Tm_anon. Are you so naive and arrogant to think that if the world switched to Linux, hackers and virus writers will suddenly stop doing what they do? Linux is just another OS with just as many bugs and problems. Nothing would really change and there would still be people like you imply that some other alternative OS is secure.
by tm_anon March 27, 2009 10:32 PM PDT
@viper396

Are you so naive and arrogant to think you know what's going on in my head?

Servers across the internet run Linux. Actually, the majority of servers run Linux in one form or another. Yet, Windows has more malware written for it. It's a fact that every OS has vulnerabilities. It's a fact that every browser and every piece of software has vulnerabilities just because of how imperfect the designer of that software are.

There are enough reasons to write exploits for Linux just in how many servers there are, yet nothing has been written, even on a small scale, that will run.

Besides, the EU hates MS. That's enough of a reason to stop using Windows in and of itself.

By the way, try doing a little research into Linux vulnerabilities before you leave a comment. Know what you're talking about and certainly start reading comments for what they are rather than what you think they are.
by Hunnter2k3 March 28, 2009 4:39 AM PDT
@viper396
Not really, he is right.
The way the Linux base (Unix and somewhat MacOS) is designed helps prevent a large number of virii from being created so easily.
The large number of Linux web-servers prove such. (only ones being hacked are ones ran by idiots using root)

Microsoft made an attempt at trying to fix this with UAC, and failed it quite badly. (one virus was able to get straight by it if i remember correct)
I'm not sure how they are going about it in Win7 yet, but for everyone's sake, i hope they do well...
by JCPayne March 29, 2009 1:07 PM PDT
Many places don't patch as they should because Microsoft has this habit of installing new bloatware with serious critical patches. And many times their new "features" or bloatware in the patches end up breaking other office applications or other stuff. Then when you realise it broke something and you want to un-install the new "feature" that is tied to a patch it then has the nerve to tell you "You cannot un-install this." Thus you have to reformat and begin all over again. (minus the patch)
by massfat March 31, 2009 3:00 PM PDT
@ppl above who think linux servers are better
It's not that linux servers are more secure, it's the difference between a PC and a server that is the difference. Servers are maintained all the time with top notch security, whereas PCs get neglected by users that don't know much about it. That is the issue here. Another issue is related to the way hackers think. If they can get around dealing with the servers that are maintained well, and instead go for creating a mass network via exploiting individual PCs without nearly as much security as servers, then they'll probably go for the PCs.
by JCPayne March 29, 2009 12:25 PM PDT
Bets.... After Windows 7 is released how many days will it be until the first serious 'round-the-world' again Virus????
Reply to this comment
by JCPayne March 29, 2009 12:26 PM PDT
err worm...
by hugociss March 30, 2009 1:53 AM PDT
darn, hope it doesnt get to Singapore...
Reply to this comment
by bridge solution April 1, 2009 11:28 AM PDT
amidst the endless rants msft vs appl vs linux vs....whatvvver.... does anybody ever notice that these exploits are often >>coming from<< servers?
the first virus i ever got (out of 3 in 13 years..1998)..came from attachments from a business partner with a mac, who swore of course that macs can't get virusus.. her machine became a carrier after being connected to a solaris based lan during a meeting. she managed to infect a dozen or more machines before she could be convinced that her mac was the vector.
plague carriers don't have to be sick to spread plague.
if i'm writing an exploit to create a bot or other net, the last thing i want is for it to be visible to linux: i want it to intereact with the p2p buildable by whatever system is dominant at the edge of the net, which is windows.
Reply to this comment
(11 Comments)
  • prev
  • 1
  • next
advertisement

15 sites that went kaput in 2009

Web sites launch all the time, but they also shut their doors. We highlight 15 that bit the dust this year.

Top 10 news stories of the decade

Let the debate begin: Was the iPhone more important than iTunes? Was anything bigger than Google finding a great business model? CNET offers its list of the 10 most important stories of the '00s.

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right