Version: 2008

Comments on: Conficker infected critical hospital equipment, expert says

Hundreds of PCs and medical devices at hospitals in the U.S. were found to be infected with the Conficker worm recently, a security expert says.

Add a Comment (Log in or register) (26 Comments)
  • prev
  • 1
  • next
by monkeyfun14 April 23, 2009 4:37 PM PDT
This is gonna turn into one big ol MS bashing fest.
Reply to this comment
by Lerianis3 April 23, 2009 6:45 PM PDT
Most likely, yeah. It shouldn't be an MS bashing fest, considering that a patch was out nearly a YEAR before Conficker even showed up.
by seven7dust April 24, 2009 2:39 AM PDT
wats so wrong with that ?
it's partly Microsoft's fault afterall
who cares about patches etc.
when your paying for something you expect it to work and yo don't get that with Microsoft I'm afraid !
by rapier1 April 24, 2009 7:18 AM PDT
@Seven7Dust,

So is it okay if I get pissed off at Apple when they release security updates and patches for their offerings? I mean, I paid for this mac and I expect it to just work. Why should I have to patch it ever? They must use lousy developers.
by Random_Walk April 24, 2009 8:37 AM PDT
Nah - but it does make one wonder at why they have Windows attached to such critical equipment...

Most equipment of this type (I happen to know more than a few biomedical engineers) can't simply be patched due to a lot of factors:

* custom app software that needs to be rigorously tested more than most
* the constant use of the equipment makes downtime far harder to schedule and put to use
* the vendor of the equipment may not allow in-house patching (often enforced by contract) due to the desire/need to have the vendor do the servicing (and charge obscene amounts of cash for doing so).
* The version of Windows used is often the embedded version with a ton of custom drivers, which complicates things a bit more than your typical Dell. ;)

Hope that helps a little, kids.
by Dalkorian April 24, 2009 10:26 AM PDT
Deservedly.
by tm_anon April 24, 2009 7:17 PM PDT
@Lerianis3

The problem with your argument is that the computers infected were "too old" to be patched. Meaning it doesn't matter if the patch is out or not.
by ikramerica--2008 April 23, 2009 4:46 PM PDT
If only those heart monitors hadn't navigated to a file sharing site, downloaded a cracked version of iWork, and entered their login password, this never would have happened.

Oh, wait, that lazy equivalency doesn't work when you apply it to the real world.
Reply to this comment
by Lerianis3 April 23, 2009 6:56 PM PDT
Actually, most likely someone had Conficker on a USB stick, plugged it into one of the network computers, and it propogated over all the computers in said network!
I am willing to bet 5 million bucks and my balls that this happened like that.
by tm_anon April 24, 2009 7:20 PM PDT
Or you could read the article where the reason for the infection was given. I'll quote it for you. "...the network was connected to one that has direct Internet access and so they were infected, he said."

I don't see anything about a USB stick in there, do you?
by Vegaman_Dan April 23, 2009 5:16 PM PDT
"in a local area network that was not supposed to have access to the Internet, "

Well, there you go. There's the problem.
Reply to this comment
by ikramerica--2008 April 23, 2009 5:31 PM PDT
But how can the radiology tech check his facebook page if his computer's not connected?
by Lerianis3 April 23, 2009 6:53 PM PDT
Well, that is a big problem, and the question they should be asking: why did a network that wasn't supposed to have access to the internet get this on the computers? Answer: USB key or disc someone brought in, I am willing to bet you 5 million bucks.
by Seaspray0 April 23, 2009 9:47 PM PDT
The article said it was connected to a network that did have internet access.
by rapier1 April 24, 2009 7:20 AM PDT
@Lerianis3,
"The computers are older machines running Windows NT and Windows 2000 in a local area network that was not supposed to have access to the Internet, however, the network was connected to one that has direct Internet access and so they were infected, he said."

I'll send you an address for the check and your heuvos.
by pentest April 24, 2009 7:28 AM PDT
Not too be snarky, but Windows is not built with Internet access in mind. It is the only possible explanation.
by n3td3v April 23, 2009 6:14 PM PDT
Too much generalisation as usual with these scare reports, not enough hard fact and evidence and no name of hospitals.

The security community gets sleepier the more of these reports come out that anyone could make up and nobody is believing.

Hard, facts and evidence or ****.
Reply to this comment
by ti99_forever April 23, 2009 6:44 PM PDT
Yep, our hospital recently had a rash of conficker infections. Not aware of any critical systems, but since they are all on the network, I can't say...
Besides, the definition of critical, in this era of new software to replace paper, has morphed into a "gray area". We commonly get calls from floors unable to get meds for their patients, and a first response I always give is "don't let the computer prevent you from performing your job!".

Apparently, that is not part of the training...
Reply to this comment
by Lerianis3 April 23, 2009 6:48 PM PDT
You are forgetting something: if the computer doesn't have in it that the patient had gotten their medicines, the patient might get double or even more dosages! It SHOULD prevent them from doing their jobs until the thing is fixed, unless there is an urgent need to disregard the computerized system.
Anyway, how damn complicated is it..... I worked in a hospital (Johns Hopkins) that was one of the first to go to computerized prescriptions, and it was 'punch in amount of pills, punch in dosage of pills, get doctor to sign off.... DONE!"

Then the pills were delivered in foil covered small trays with the patients name printed on the bottom of the tray, with the bottom facing up!
by zeroplane April 23, 2009 8:09 PM PDT
Perhaps this thing called security should be put on the hospital's network.. you know something from way the last 20 years would do.. or maybe have active sweeps of computers to detect misconfigurations.. My sister works in the medical industry and the "solutions" provided by technology consultants is shameful. Too bad the cost of the "solution" is not in par with the actual services rendered.

And people wonder why medical services are so expensive.
Reply to this comment
by ERK107 April 23, 2009 9:06 PM PDT
I Just find that shocking that anything that has to deal with patient lives is not handled better with precautions such as a separate isolated network with no access whatsoever to the outside.
Reply to this comment
by dargon19888 April 24, 2009 5:29 AM PDT
This is what happens when you get a bunch of non-technical people trying to run IT. They don't know enough to be paranoid and the staff being hired isn't properly trained to do the jobs.

Oh wait, its not just hospitals, but all of IT.

The bean counters save a couple of bucks a year, but at what cost? How much did TJX has to shell out? How much do you think a medical malpractice suit will cost when a piece of equipment fails and someone dies? Oh there's more, but then again, looking at our government, their top CIO was a political hack who couldn't run a city's IT dept....
Reply to this comment
by huckleberry2 April 24, 2009 6:15 AM PDT
The cause of the NE blackout was determined and discussed ad nauseam.

The alarming subsystem failed in a unix-based scada system used by the utility company in Akron, OH (FirstEnergy). The problem persisted for over an hour. During this time, FirstEnergy?s system operators where unaware of the condition of their electric system and allowed transmission lines to overheat and sag into trees (due in part to FirstEnergy?s poor tree trimming practices). The instability of the electric system in Ohio caused overloads in adjacent services areas, which caused automatic protection systems on undamaged equipment to isolate itself from the grid. The cascading events moved north into Canada, around in the great lakes, and back into the northeast US, with the majority of the blackout occurring in ~9 seconds.

Specific software bugs were identified in the GE XA/21 scada system (used by FirstEnergy) which caused the initial failure of the alarm/event subsystem.

The cause of the blackout is known and was not related to an Internet worm. Please stop perpetuating this falsehood.
Reply to this comment
by pentest April 24, 2009 7:26 AM PDT
Who in the hell relies on Windows from critical systems?

If it is a critical system, it needs to be reliable, stable and secure. Three things Windows is not and never will be.
Reply to this comment
by willdryden April 25, 2009 8:59 PM PDT
I have found windows to be reliable and stable (except win ME). NO computer can be made secure if there is any human access. The only thing you can hope for is that your human resources dept. can weed out the people that will hurt your company and keep the system backed up just in case.

It only took me 2 hours to hack a VMS system one night when our stupid system manager edited the system startup file incorrectly and left town for the weekend. I got the call because I knew more about the OS than anyone else in the company.
Reply to this comment
by fwjs28 April 30, 2009 4:30 PM PDT
somebody most likely sent a dos attack to the servers, and Microshit is trying to cover it up, and blame it on the ****** servers...DUH!
Reply to this comment
(26 Comments)
  • prev
  • 1
  • next
advertisement

15 sites that went kaput in 2009

Web sites launch all the time, but they also shut their doors. We highlight 15 that bit the dust this year.

Top 10 news stories of the decade

Let the debate begin: Was the iPhone more important than iTunes? Was anything bigger than Google finding a great business model? CNET offers its list of the 10 most important stories of the '00s.

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement