Stories
Slash Boxes
Comments

News for nerds, stuff that matters

FBI, Pentagon Talk to MS about XP Hole

Posted by timothy on Sat Dec 22, 2001 08:33 AM
from the step-inside-the-circle-of-trust dept.
(eternal_software) writes: "The Associated Press is reporting that the FBI and Defense Department are talking to Microsoft about the serious flaws found in the XP operating system. As we all know, the most recent flaw allowed any XP machine to be hijacked simply by connecting it to the internet. The government is getting involved because of growing U.S. concerns about risks to the 'net as a whole." In fact, the FBI would like you to go a bit beyond the MS patch. davecl points out the updated page put out by the National Infrastructure Protection Center about this vulnerability as well.
This discussion has been archived. No new comments can be posted.
Display Options Threshold:
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • Just a thought (Score:4, Interesting)

    by peripatetic_bum (211859) on Saturday December 22 2001, @08:37AM (#2741074) Homepage Journal
    First we hear rumors that al-queda may have hacked into windows,

    now we see the Gov't take a special interest in

    the latest XP hole.

    Dont know about you, but I am really dont know what to think?

  • Printer Friendly Version by Tryfen (Score:1) Saturday December 22 2001, @08:41AM
  • hmmm...interesting (Score:4, Insightful)

    by metrix007 (200091) on Saturday December 22 2001, @08:41AM (#2741082)
    the fact remains, ms code *can* be secure, obviously just not xp, good to see them getting their act togethor
    • 1 reply beneath your current threshold.
  • XP patch is broken (Score:5, Funny)

    by Anonymous Coward on Saturday December 22 2001, @08:43AM (#2741083)
    MS XP patch disabled network card on my computer!

    I guess the computer is really safe now.
  • did anybody notice this.... (Score:3, Interesting)

    by Merik (172436) on Saturday December 22 2001, @08:43AM (#2741084) Homepage
    "Microsoft explained that a new feature of Windows XP can automatically download the free fix, which takes several minutes, and prompt consumers to install it. "

    thats really messed up that and scary

    (Hmmm.. magic latern)
    • Re:did anybody notice this.... by sporty (Score:3) Saturday December 22 2001, @09:24AM
    • by Alien54 (180860) on Saturday December 22 2001, @09:26AM (#2741177) Journal
      "Microsoft explained that a new feature of Windows XP can automatically download the free fix, which takes several minutes, and prompt consumers to install it. "

      Nevermind that such an exploit could also be used to do just the same thing and send people off to download a "patch" form a psuedo MS site.

      Suddenly people are taking seriously the idea that MS can present a problem for national security, when this was dismissed as a trollish comment before.

      The fantasy is the unlikely end result with Bill Gates and buddies being arrested for treason for the software. yes it is just a fantasy. ,p.But isn't Xmas the time of year for dreams? ;)

      [ Parent ]
    • Re:did anybody notice this.... by mESSDan (Score:3) Saturday December 22 2001, @09:32AM
    • Re:did anybody notice this.... by Corgha (Score:2) Saturday December 22 2001, @10:03AM
      • Re:did anybody notice this.... by Scooby Snacks (Score:1) Saturday December 22 2001, @10:17AM
        • Re:did anybody notice this.... (Score:5, Insightful)

          by TandyMasterControl (136043) on Saturday December 22 2001, @12:36PM (#2741607) Homepage
          Not that I necessarily think that the XP auto-updater is a bad thing; I haven't come to a conclusion for myself yet.

          Whenever you log in on your XP system (of course, no password in XP-home at least) a flurry of packets fly off to Mord- er Microsoft and to the OEM you bought the system from. You have no way of knowing the content of that communication. Since it's all closed source,no one can comb through it for vulnerabilities or trojans like they could for the code for apt or rpmfind. A typical user has no way of knowing that the communication is even taking place at all unless they are running something like tcpdump on the network.

          Does that help?
          Basically, when you buy XP you are wittingly or unwittingly complicit in your own surveillance. You have given your consent in principle, to be spied upon because you were sipping your morning coffee while XP talked to the higher authorities about you. You looked away and sipped instead of yanking the cat5 out. I say in principle because we've seen that all the consent required for this government to violate your Constitutional rights is that you and others do not resist it with force. Though no one posting here can say for certain what passes through this security hole now, neither can anyone deny that, with a hole like this opened in your systems, a hole which everyone is being conditioned to accept as normal, a feature of their OS, there is literally NO LIMIT to the severity of your insecurity. While you're sipping that coffee, the convenient updater can convert your computer system into a telescreen into your private thoughts, business plans, governmental policies, and so on without end, no matter where you live and what flag you salute. It used to be that spyware was an annoyance foisted on the public sporadically by marketers. Now with XP, spyware connects a government approved monopoly to your most trusted communications and private papers. You don't have to be an anticapitalist socialist or a government hating libertarian to understand that at some level the distinction between a government approved monopoly and an agency of that government is essentially null, or so small it's not worth discussing. (Or maybe someome could point out examples to me where ATT told the government it would not cooperate in its counterintelligence efforts against antiwar protestors and civil rights leaders in the 1960's)

          Between the 2 of them, Windows XP users have poor Goatse-man beat by a painful mile for the infinite elasticity of their holes. I have no doubt that the Feebs and Dept.of Deathdance have a million things they'd like to talk over with MS in that regard.

          [ Parent ]
        • Re:did anybody notice this.... by Corgha (Score:1) Saturday December 22 2001, @12:47PM
        • Re:did anybody notice this.... by Herstel (Score:1) Saturday December 22 2001, @01:42PM
        • Re:did anybody notice this.... by Herstel (Score:1) Saturday December 22 2001, @02:25PM
        • 1 reply beneath your current threshold.
    • 5 replies beneath your current threshold.
  • But they don't see MS as the problem, I bet by MagikSlinger (Score:2) Saturday December 22 2001, @08:43AM
  • Trust us! (Score:4, Interesting)

    by robinjo (15698) on Saturday December 22 2001, @08:46AM (#2741090)

    Microsoft has known for five weeks that XP had a serious security hole. They didn't do anything to warn customers who bought XP during that time. They just kept telling how XP is so secure.

    It's unbeliavable what Microsoft can get away with. I don't think the hole and the patch are the important issues here. I'm shocked how Microsoft can lie to the whole world for five weeks and people still trust them.

    Microsoft should have withdrawn XP and fixed it. Expecially as they don't even have any serious competitors. What they showed was that they don't care about the safety of their customers. They just want to make money no matter what.

    • Re:Trust us! (Score:5, Interesting)

      by uchian (454825) on Saturday December 22 2001, @09:07AM (#2741134) Homepage
      Microsoft should have withdrawn XP and fixed it. Expecially as they don't even have any serious competitors. What they showed was that they don't care about the safety of their customers. They just want to make money no matter what.

      In my opinion they should _STILL_ withdraw it and fix it.

      By this, I mean that they should recall every vulnerable CD off of shelves, and send everyone who they know has bought one a new copy that is already patched.

      Computers bought with Windows XP preinstalled should have the offer of being recalled to have the patch applied, and everyone should be sent an updated recovery disk.

      Why? Because otherwise, 90% of computers out there, run by the technologically clueless population will never get this patch applied.
      [ Parent ]
      • Re:Trust us! by lseltzer (Score:1) Saturday December 22 2001, @09:12AM
        • Re:Trust us! by Toraz Chryx (Score:2) Saturday December 22 2001, @09:22AM
          • Re:Trust us! by Anonymous DWord (Score:2) Saturday December 22 2001, @04:24PM
            • Re:Trust us! by Toraz Chryx (Score:1) Sunday December 23 2001, @05:08PM
        • Does it? by barzok (Score:3) Saturday December 22 2001, @09:55AM
          • Re:Does it? by killthiskid (Score:2) Saturday December 22 2001, @09:42PM
          • Re:Does it? by Suppafly (Score:1) Monday December 24 2001, @02:13AM
          • Re:Does it? by void warranty() (Score:1) Saturday December 22 2001, @03:06PM
          • Re:Does it? by aka-ed (Score:1) Saturday December 22 2001, @05:43PM
          • 1 reply beneath your current threshold.
      • Re:Trust us! by Ken D (Score:1) Saturday December 22 2001, @09:25AM
        • Re:Trust us! by zummit (Score:1) Saturday December 22 2001, @11:53AM
      • Re:Trust us! (Score:4, Funny)

        by eggz128 (447435) on Saturday December 22 2001, @09:33AM (#2741188)
        Why? Because otherwise, 90% of computers out there, run by the technologically clueless population will never get this patch applied.

        Yes they will. Thats what the auto updater is for. It downloads the patch in background while the technologically clueless user is browsing, then prompts them to install it by asking them "We send you this update in order to have your advice".

        You can guess what the standard response will be.
        [ Parent ]
      • Re:Trust us! by Cygnusx12 (Score:1) Saturday December 22 2001, @10:00AM
      • Re:Trust us! by Weezul (Score:1) Saturday December 22 2001, @01:26PM
      • Re:Trust us! by Cyclone66 (Score:1) Saturday December 22 2001, @01:58PM
      • Re:Trust us! by dagashi (Score:1) Saturday December 22 2001, @05:30PM
    • Re:Trust us! (Score:5, Insightful)

      by Masem (1171) on Saturday December 22 2001, @09:08AM (#2741135)
      Remember that Microsoft wants to push a security model in which new bugs are reported only to the vendor and possibly a NDA-signed security group, and then in 'sufficient time' ( There's a part of me that says, ok, this type of reporting for a bug with this amount of security implications is probably a good thing, as if the bug was reported before the patch was available, you'd already have 'owned' XP boxes out there before MS had the patch. In the fashion they approached it, the amount of damage to XP (or other OSes) boxes will be minimized.

      But I feel there MUST be some preannouncement on such bugs, even if the details are minimal. Whenever you work on something, you cannot expect that someone else in the world is not also working on the same thing, but not for the same purposes. In the case here, eEye, the group that found the bug, was looking for it for purposes of good, but I would not expect that someone else, maybe a malicious group, was also narrowing in on the bug 5 weeks ago when eEye reported it to MS. (And then you have to add cyber-espionge that might have garnered that info for themselves?). In the 5 weeks it took MS to verify the bug and develop and test the patch, that other group might have caught up and started 'owning' boxes already. A preannouncement of the bug, simply outlining the effects, and any short-term security measures, would have prevented that group from having any significant harm on the boxes if they did exist.

      I know from a previous discussion that many sysadmins, when a new bug is discovered, want to know all the details up front so they can test the bug before and after fixing on their systems. This is understandable, but I think in the cases of bugs that can affect a significant large number of systems, such as this XP bug, that limited disclousure is better. I think a key step that could be done is institute a small group of trusted security people; bugs that are found are reported to the vendor and to this group. A person(s) from the group verifies the bug and puts out a digitalled signed statement that this bug exists, and that certain steps can be taken to correct it. Because of the status of these people, if they claim to have verified the fix, then that should be considered to be truthful, and thus limiting the need of sysadmins having to have full details to test it themselves. After a short period (no more than 6 weeks), the full details should be released, regardless if a patch from the vendor was available or not. That way, the limited disclosure lets the sysadmins know there's something going on and there's step they can take to prevent problems, and it gives the vendor time to fix the problem before that information falls into the hands of malicious people.

      [ Parent ]
      • Re:Trust us! by budgenator (Score:2) Saturday December 22 2001, @10:56AM
        • Re:Trust us! by Tony-A (Score:1) Saturday December 22 2001, @06:55PM
      • Re:Trust us! by EWTHeckman (Score:1) Saturday December 22 2001, @01:32PM
        • 1 reply beneath your current threshold.
      • Re:Trust us! by Some Dumbass... (Score:1) Saturday December 22 2001, @04:51PM
      • Re:Trust us! by lazy_greenhouse_gas (Score:1) Saturday December 22 2001, @07:19PM
    • Re:Trust us! by kresmoi (Score:3) Saturday December 22 2001, @09:22AM
    • Re:Trust us! by peripatetic_bum (Score:1) Saturday December 22 2001, @11:57AM
    • Legal Liability? (was Re:Trust us!) by aldheorte (Score:1) Saturday December 22 2001, @12:17PM
    • 2 replies beneath your current threshold.
  • Serious Stuff by smooc (Score:2) Saturday December 22 2001, @08:47AM
  • Why didn't the FBI.... by Kevinv (Score:1) Saturday December 22 2001, @08:48AM
  • Green Lantern? by cyplex (Score:1) Saturday December 22 2001, @08:50AM
  • Considering the focus on national security.... by Merik (Score:1) Saturday December 22 2001, @08:51AM
  • Yeah the gov prolly has a patch alright by HanzoSan (Score:1) Saturday December 22 2001, @08:51AM
  • Follow the EEC Lead. (Score:3, Offtopic)

    by Beautyon (214567) on Saturday December 22 2001, @08:53AM (#2741107) Homepage
    The British and German govermnents have both realized that Open Source software is the way to go for many reasons, and are now deploying these superior solutions (or planning to) across all departments.

    What the makers of Linux distributions must do is concentrate on usability (and by extension consistency) and further refining their installers so that anyone off of the street can choose and then run Linux as painlessly as they have done with all the different windoze generations.

    Ximian are the closest to making easy to use tools that even my Aunt Grace (70) can use. A fully blown distribution from Ximian would be "most welcome" to use parliamentary language.

  • Microsoft's in trouble . . . by Anonymous Coward (Score:2) Saturday December 22 2001, @08:53AM
  • all rightey then! (Score:4, Interesting)

    by Jburkholder (28127) on Saturday December 22 2001, @08:54AM (#2741110)
    Microsoft explained that a new feature of Windows XP can automatically download the free fix, which takes several minutes, and prompt consumers to install it.

    I must be living under a rock because this is the first I've heard of this. XP just starts downloading files without any action from the user? Does anyone beside me feel uncomfortable about that?
  • The Blue Nowhere by satanami69 (Score:1) Saturday December 22 2001, @08:59AM
  • the arrogance (Score:4, Insightful)

    by kubla2000 (218039) on Saturday December 22 2001, @09:00AM (#2741120) Homepage
    The arrogance of microsoft is astonishing.

    I honestly and truly hope that the US government brings them to their knees about this. That's wishful thinking, I know. However, two statements in particular in the Yahoo! article surprised me:

    1. Microsoft declined to tell U.S. officials Friday how many consumers downloaded and installed its fix during the first 24 hours it was available.
    2. Microsoft also indicated it would not send e-mail reminders to Windows XP customers to remind them of the importance of installing the patch.

    The reasons for point 1 are quite clear though. Acting on point 1 would indicate what a fiction the sales figures for XP really are.

    Point 2 is more difficult to fathom... perhaps they're hoping people won't notice? Why on earth, other than their disdain for non-corporate users, wouldn't they send out the reminder? Or even a reminder stressing the improtance of installing the auto-updater?

    • Re:the arrogance (Score:5, Insightful)

      by hacker (14635) <anonymous@nonpublic.info> on Saturday December 22 2001, @12:13PM (#2741547) Homepage
      1. Microsoft declined to tell U.S. officials Friday how many consumers downloaded and installed its fix during the first 24 hours it was available.

      The reasons for point 1 are quite clear though. Acting on point 1 would indicate what a fiction the sales figures for XP really are.

      Or that 2 million copies were sold, and 9 million people required the patch.

      Point 2 is more difficult to fathom... perhaps they're hoping people won't notice? Why on earth, other than their disdain for non-corporate users, wouldn't they send out the reminder? Or even a reminder stressing the improtance of installing the auto-updater?

      I can give you several reasons:
      • The longer a problem exists, the more support calls they will get to address it. Support calls to Microsoft are not free. Read: coffers.
      • The longer a problem exists, the more time they have to sell product that is vulnerable to it (see 1. above)
      • The longer a problem exists, they more they can milk their training program and create a new MCSE test for "Securing the Enterprise", or some such drivel.
      • They can't probably email everyone that purchased XP, because the piracy for it has gone through the roof. Every-single-person I've spoken to (more than 2 dozen) that have XP installed tell me that they pirated it. Nice going, Microsoft, that was a good plan.
      • Wasn't the whole point of XP and the "online ease of installation" supposed to automatically send you fixes?
      [ Parent ]
    • Re:the arrogance by Jucius Maximus (Score:1) Saturday December 22 2001, @12:48PM
    • Re:the arrogance by tcc (Score:2) Saturday December 22 2001, @12:55PM
    • Careful what you wish for by Gorimek (Score:2) Saturday December 22 2001, @01:22PM
    • Re:the arrogance by evilmrhenry (Score:1) Saturday December 22 2001, @01:49PM
    • Re:the arrogance by J. J. Ramsey (Score:1) Saturday December 22 2001, @03:31PM
    • ...declined to tell... by allism (Score:1) Saturday December 22 2001, @05:41PM
    • 1 reply beneath your current threshold.
  • The gaping hole in internet security is... by darkov (Score:1) Saturday December 22 2001, @09:02AM
  • Monopoly has serious security implications by CatherineCornelius (Score:1) Saturday December 22 2001, @09:03AM
  • Huh? by Fat Casper (Score:2) Saturday December 22 2001, @09:06AM
    • Re:Huh? by jsarek (Score:2) Saturday December 22 2001, @09:32AM
      • 1 reply beneath your current threshold.
  • by ackthpt (218170) on Saturday December 22 2001, @09:09AM (#2741136) Homepage Journal
    Utterly fascinating that the DoJ (FBI) is looking into these flaws for the difficulty exploits could cause people, after basically letting M$ off the hook in the monopoly punishment phase. Hope the states prevail, and if you haven't written your opinion in (to the court), here's another reason why monopoly for a universally adoptedand used O/S is bad.

    Public comment is invited within 60 days of the date of this notice. Such comments, and responses thereto, will be published in the Federal Register and filed with the Court. Comments should be directed to Renata Hesse, Trial Attorney, Suite 1200, Antitrust Division, Department of Justice, 601 D Street NW, Washington, DC 20530; (facsimile) 202-616-9937 or 202-307-1545; or e-mail microsoft.atr@usdoj.gov. While comments may also be sent by regular mail, in light of recent events affecting the delivery of all types of mail to the Department of Justice, including U.S. Postal Service and other commercial delivery services, and current uncertainties concerning when the timely delivery of this mail may resume, the Department strongly encourages, whenever possible, that comments be submitted via email or facsimile.

    After all the blather and FUD from Redmond, they again pushed a product out the door with great media hype which is again unsecure. It would be so ironic if Microsoft were punished for this kind of negligence after getting a slap on the wrist. I don't expect that to happen though.

  • "You guys promised us..." (Score:4, Funny)

    by Jacco de Leeuw (4646) on Saturday December 22 2001, @09:14AM (#2741149) Homepage
    "... that this backdoor would not be found for at least 2 years after this Bin Laden thing blows over!!"

    "Yeah, but those eEye guys didn't want to be on our Security-Through-Obscurity team! And we had all these great goodies for them!"

  • It's to be expected... (Score:3, Informative)

    by jmichaelg (148257) on Saturday December 22 2001, @09:18AM (#2741155)
    ...that security will suffer when you make an os too easy to use. It's an age-old tradeoff: security vs. ease of use. Moreover, with more features comes more complexity and with more complexity come more security holes.

    Don't want to check to see if there's a patch needed for your OS? Don't worry, we'll have the OS check for you. We can't guarantee that your computer will be talking to our servers when it downloads the patches but hey! it'll be automatic! Come to think of it, we can't even secure our own servers so we're not too sure what you'll be downloading even if you are talking to our servers but hey! - it's automatic!

    I can't think of a better argument for limiting the services an os provides than this fiasco.
  • FBI might have warned them.. by jsse (Score:2) Saturday December 22 2001, @09:22AM
  • by weave (48069) on Saturday December 22 2001, @09:26AM (#2741175) Journal
    I haven't seent his mentioned much, but UPNP is all about handling NATed devices. There is a UPNP SDK developed for Linux, but until someone builds a useful kernel module out of it, Linux users are SOL (or maybe they are fortunate).

    Why care? Well, I found out after installing MSN Messenger that most of the features are useless behind a NATed network unless your router/firewall understands UPNP. Of course, Microsoft ICS and Servers understand it. I was getting frustrated since I couldn't use MSN messenger except for messages behind my home linux firewall. ICQ features like file transfer work fine by port forwarding the necessary ports or using a kernel module for it.

    So, here's the interesting bit. UPNP works by telling the other client on the other end what your private IP address is. Microsoft's docs say this is necessary for the other client to be able to find out how to talk back to you. I think this is stupid. The other end of an MSN connection just needs to look at the source IP in the packets it receives and just send there and hope the owner of the IP knows what to do.

    However, UPNP apparently knows how to handled multiple chains of NAT networks, kinda like I guess an old fashioned UUCP bang path. Problem is, it seems like one can modify that "bang path" to route return packets to false places. Can you say DDOS?

    So I sent a rant to my friends about this on December 10, and about how UPNP is a security hole waiting to happen according to posts I read out of google searches...

    Here's my rant...

    I read the tech article about msn messenger and NAT devices. In order to do pretty much anything beyond chat, you can't be behind a NAT device unless that NAT device is a Microsoft device.

    Basically, it suggests installing Windows ICS for home users and corporate users should use a 2000 server for NAT and msn's extra features will work.

    Fuckers...

    ICQ works just fine behind a NAT. They are basically just trying once again to leverage one product to sell another....

    Their explanation is that the client must send its IP address to the other user so it knows where to send files, audio, video, etc, and since it's got a private IP, it screws up. So it needs to query the NAT device for what ITS IP is. But that's really stupid since there is already a connection open for chatting and all the other client has to do is look at that connection for the source IP and use that instead and everything else would just work....

    Someone on a newsgroup said this is another security hole waiting to happen. Basically, it's trusting client for security. I send a connection to your msn messenger client and tell it what IP to send its stuff to? What if I send it the IP address of someone I am trying to DOS? Arrgh...

    They'll never learn...

    Microsoft claims UPNP is a universal open standard. It'd be interesting to learn more about its origins and who is really controlling development of it, security of it, etc. Microsoft claims all manner of peripheral vendors will be supporting it.

    Is the concept itself as flawed as it seems, or is this just yet another case of Microsoft's implementation of something being flawed?

  • Seeing as i-net update is unsafe by A_Non_Moose (Score:1) Saturday December 22 2001, @09:27AM
  • I don't understand how you all think this - by Typingsux (Score:1) Saturday December 22 2001, @09:29AM
  • An analogy with the biological world (Score:5, Insightful)

    by Ryu2 (89645) on Saturday December 22 2001, @09:34AM (#2741192) Homepage Journal
    In epidemiology, one of the mitigating factors of the spread of any disease is simply the diverse genetic makeup of the targeted population.

    The opposite to this is what's called a monoculture, where one particular genetic structure is present in the large majority of the population. Such situations will usually not last long, beacuse once something is found that affects that population, it spreads quickly and decisively.

    With Windows having such a large share of the market as it is, could this be considered the electronic equivalent of a monoculture? Would one major virus or security flaw cause much more damage to the net than otherwise would have happened, because of the homogenity of the net's computer systems in terms of OS?

    Whether the king is Linux or Windows or MacOS, or..., is having a near monopoly market share ofany one OS a good thing in light of this philosophy? Hmm. GFood for thought.
  • Maybe MS and FBI are working together? by Ryu2 (Score:1) Saturday December 22 2001, @09:39AM
  • Cracking spree holidays? (Score:3, Insightful)

    by Zarathustra.fi (513464) on Saturday December 22 2001, @09:39AM (#2741209)
    I'm thinking new computers that have been bought this Christmas as presents. I wonder how many of these computers are preinstalled with Windows XP. As we speak, these computers are all wrapped in gift papers; who will patch them? Do people even have time to do anything else except get prepared for the big day? And are people aware of the severe security flaw?

    Probably quite many of those computers go to people who are going to have it as their first computer. And what are they going to do first? Turn it on. And probably, go online with it..

    And the crackers will be waiting for the easy prey.
  • by wift (164108) on Saturday December 22 2001, @09:44AM (#2741215) Journal
    where Burns and Smithers goes through high security steel doors, scanning stations, gates and end up in the control room that has a old screen door to the outdoors in it allowing a stray dog in. Seems to me that sums up Microsoft's entire security structure.

    bonus karma points to anyone who correctly identifies the show number.

    "Oh for christ sake"- Montgomery Burns after discovering a stray dog in his XP like high security control room.
  • You know (Score:3, Interesting)

    by ASIO (193653) on Saturday December 22 2001, @09:46AM (#2741219) Homepage
    This would be a damm good way to get Magic Lantern on a whole lot of systems.

    This was mentioned earlier, but now the FBI is pushin it as well, Coincedence??
  • frustrated FBI (Score:3, Insightful)

    by WildBeast (189336) on Saturday December 22 2001, @09:55AM (#2741233) Journal
    They failed to protect the country from terrorists and now they're trying to rebuild their reputation among the population by getting involved in the Internet. Th

    Looks like MS isn't the only one with good marketers :)
  • Automatic update by alfredo (Score:1) Saturday December 22 2001, @10:13AM
  • by AdamBa (64128) on Saturday December 22 2001, @10:20AM (#2741289) Homepage
    There was two bugs reported here. One in SSDP that makes it possible to use XP to launch denial of service attacks, one that is reported as a buffer overflow.

    So what is up with those buffer overflows...do Microsoft developers hate users and not care about quality? Well, no. It only takes one buffer overflow in the whole system that hundreds of developers have worked on, to make it vulnerable.

    At Microsoft the ultimate way people are valued is at review time when bonuses, stock options, and raises are awarded. Do developers get hosed for leaving buffer overflows in? Well, not as of when I left (April 2000). But maybe that will change, slowly.

    Eventually you have to stop accepting excuses like "Gee code is really complicated and I thought I was being careful" or "we really tried to think through this design" and recognize that essentially every buffer overflow comes from being lazy as a developer, or not accounting for what kind of garbage packets can come in off the net. If Microsoft starts emphasizing that you can be fired for leaving a buffer overflow in, then things might change. Of course it's a little unfair, there is no doubt lots of clunky code in there that just doesn't happen to expose an externally exploitable buffer overflow (and merely crashes the system or something), but you start emphasizing the necessity to go over things with a fine-tooth comb to prevent buffer overflows, it will improve all the code.

    Because although there may be a few cases where someone really tried to check boundary conditions and just did it wrong in the code, in most cases developers are just being lazy about writing the code robustly to begin with. Plus if you have some code to prevent this and you write it wrong, you haven't tested your code properly anyway.

    More ruminations at this osopinion article [osopinion.com].

    - adam

    • by satch89450 (186046) on Saturday December 22 2001, @12:17PM (#2741558) Homepage

      So what is up with those buffer overflows...do Microsoft developers hate users and not care about quality? Well, no. It only takes one buffer overflow in the whole system that hundreds of developers have worked on, to make it vulnerable.

      It takes only one buffer overflow in the whole system that any number of developers, from one to one million, have worked on to make it vulnerable.

      It doesn't matter how careful you are. Zero defects at the individual level is a pipe dream. The goal of software quality assurance is that you test code to determine whether it conforms to the specifications with no astonishing side effects. Structured implementation (use of safe libraries, re-use of validated code) can reduce the effort and increase the quality of code.

      Want to eliminate buffer overflow? It's easy. Just write a routine ONCE that sucks up characters and puts it into a buffer, debug the corner cases ONCE to ensure you can't go beyond the boundaries, and use that routine for all your work, without exception. Not even when marketing comes in and says "Hey, you didn't come out on top in performance when HAL Magazine ran their tests!" Oh, and your QA people have to actually try to execute some kind of buffer overflow as one part of their suite of test cases...

      When a buffer overflow is discovered "in the wild," you find out the source of the buffer overflow and take appropriate action -- against the coder and against QA as well. You have to show these people that you MEASURE them by this sort of stuff.

      By the way, don't forget that code should check for attempts to go "outside the box" by using unusual character sequences like ".." in URLs, too. Again, write a single block of code that does the job right, test the hell out of the corner cases, and use that code, without exception.

      A Google search yields some interesting approaches. I would like to see the adoption as part of the ANSI definition of the C language an extension to the STR* library routines that are length-safe, such as the STRL* routines found in NetBSD; see the man page [openbsd.org] and the discussion in the Secure Programs HOWTO. [linuxpowered.com]

      Don't kid anyone. Buffer overflow can be avoided, by putting in place the proper process and discipline to do the job right.

      [ Parent ]
    • yes, there are some tools by AdamBa (Score:2) Saturday December 22 2001, @05:34PM
    • OK, bad example by AdamBa (Score:2) Monday December 24 2001, @12:14AM
    • 3 replies beneath your current threshold.
  • Lesson from virology by f00zbll (Score:1) Saturday December 22 2001, @10:39AM
  • Is the net part of the national infrastructure? by filtersweep (Score:1) Saturday December 22 2001, @10:56AM
  • Why Many Hate Microsoft... (Score:4, Insightful)

    by weave (48069) on Saturday December 22 2001, @11:03AM (#2741374) Journal
    The reason many hate Microsoft is because they are just so damn arrogant. You can't put yourself up on a pedestal and not expect people to look at you closely. It's the same phenomenan as some of those televangelists. They are casting themselves as holy men all the while fleecing their followers and screwing teenage secretaries.

    I remember when NT 4.0 came out (they were fairly low key with NT 3.x) and Microsoft claiming it was far more secure than UNIX and you wouldn't have buffer overflows because the source was closed and people couldn't find them even if they existed.

    I also remember many years ago them claiming NT was more secure and showing the number of submissions of security holes posted to Bugtraq (before NTbugtraq) there were for UNIX vs NT (back when nothing serious ran on NT and no one really cared less about it to look for holes).

    Now they want their code running in everything, including acting as firewall devices. I find this so fucking funny I could just split a gut. You're going to protect machines running code "x" by installing a device running much of the same code "x" to protect those machines from the world?

    I just find it a bit frightening. The entire world running on code from one manufacturer that is not open to public review. I'm even more surprised that foreign governments are so trusting of it.

    You know what's scary? We just bought an EMC disk array and had to give it an IP address for management. Did a port scan on it. WTF? It's listening on netbios ports. Use smbclient to take a gander at it and low and behold....

    Domain=[AZBYCXDWEVFU] OS=[Windows NT 4.0] Server=[NT LAN Manager 4.0]

    Workgroup Master
    AZBYCXDWEVFU CLARIION_SPB

    I call EMC and they say "Oh, the new clariions run a stripped down NT kernel in their service processors." :-( Joy... my SAN is now trusted to that super sekure Microsoft code. At least I can block it from the world through my router which, for now, is running non-Microsoft code...

    Can you imagine the harm one could do with a hole in THAT? The financial world survived WTC through redundancy and real-time mirrors of data kept in far flung locations. There are disaster recovery data centers where entire warehouses are filled with machines just waiting to kick in during a crisis. So now you have your storage area networks themselves controlled by Microsoft code. Just exploit the hole-of-the-week to get your code inside a corporate or government firewall, seek out these storage networks running NT kernel code, trash them, take out the primary and backup locations. Chaos.

  • Surprised this happened now by phillymjs (Score:2) Saturday December 22 2001, @11:09AM
  • I watch too much Law and Order... by weave (Score:2) Saturday December 22 2001, @11:32AM
  • A good incentive... by adeptux (Score:1) Saturday December 22 2001, @11:33AM
  • by lildogie (54998) on Saturday December 22 2001, @11:47AM (#2741484)
    Even the FBI is crying "buffer overflow," following in Microsoft's footsteps to divert attention for a designed-in security flaw.

    It makes sense, from the perspective of a defensive Microsoft. "Buffer overflow? Who hasn't slipped up once or twice and had a buffer overflow bug? We have our code scanners routing out the last one or two of these bugs, they'll all be gone soon and we'll all be safe."

    The bigger gaff is that they designed the OS to say "hack me" (or words to that effect) whenever some other device--any other device--asks to fondle, as it were, the OS's drivers. That this is a huge security exposure is obvious to anyone who is old enough to remember the early days of hacking. Some hotshot designers at Microsoft, (probably with degrees in marketing, not computing) designed this "hack me" feature into the OS intentionally.

    Now they have the attention of the NIPC/FBI. Even FBI agents (who, over the last 10 years, gave new meaning to the term "anti-intellegence") know that on Christmas day, millions of un-patched XP OS's are going on line, in the same 24-hour period. The hackers will be waiting to stick their electronic -er-fingers in those exposed UPNP ports and leave behind a little deposit.

    Maybe, maybe not, the FBI realizes that some of those systems will have time-delay bugs planted in the pre-patched OS's. Then, downloading the patch will produce the false security that keeps the spirit of the XP season alive throughout the coming year.

    The silver lining? Corporate PHB's, the holy grail of Microsoft marketing, will lose confidence in any of Mr.Bill's claims of reliability and security, once and for all. XP was supposed to be the one-size-fits-all OS, from palmtops to corporate web front-ends to data warehouses. (not that it was the first attempt at this unification by Microsoft, or even their competitors.) Even the golf-buddy execs are going to remember the day when the FBI started pushing patches to the monopolist's holey flagship.

    Did anybody notice, last year, when Bill Gates started to cut the cord to Microsoft? He did see the big fall coming, you know. Not as stupid as we make him out to be, eh?
  • This is getting crazy by SloWave (Score:1) Saturday December 22 2001, @12:12PM
  • Federal Criminal Charges.. by 3seas (Score:2) Saturday December 22 2001, @12:33PM
  • UPnP - the next IIS for exploits? by dreamquick (Score:1) Saturday December 22 2001, @12:40PM
  • Sophistication? by SIGFPE (Score:2) Saturday December 22 2001, @01:14PM
  • Cmon Bill... by NiftyNews (Score:1) Saturday December 22 2001, @01:17PM
  • No real risk with the patch now availible by davidstrauss (Score:1) Saturday December 22 2001, @01:24PM
  • M$ Security problems web log? by Gorimek (Score:2) Saturday December 22 2001, @01:26PM
    • 1 reply beneath your current threshold.
  • Built-in firewall protects? by SilentChris (Score:2) Saturday December 22 2001, @01:31PM
  • Buying a New PC by Senor Crappy (Score:1) Saturday December 22 2001, @02:08PM
  • MY earning power by GerardM (Score:1) Saturday December 22 2001, @02:12PM
  • RAW sockets by CAIMLAS (Score:2) Saturday December 22 2001, @02:16PM
    • 1 reply beneath your current threshold.
  • Fun with the patch... by gordguide (Score:1) Saturday December 22 2001, @02:30PM
  • The AG of MD by Ho-Lee-Cow! (Score:2) Saturday December 22 2001, @02:32PM
  • by roman_mir (125474) on Saturday December 22 2001, @02:38PM (#2741910) Homepage
    ``This is the first network-based, remote compromise that I'm aware of for Windows desktop systems,'' said Scott Culp, manager of Microsoft's security response center. ``Every Windows XP user needs to immediately take action.'' He called it a ``very serious vulnerability.''

    ``This is the most secure version of Windows we have ever released,'' said Culp, adding that complex software ``will always fall short of perfection.''

    http://dailynews.yahoo.com/h/ap/20011220/tc/micr os oft_hackers_7.html
  • Significance by 90XDoubleSide (Score:2) Saturday December 22 2001, @02:38PM
    • 1 reply beneath your current threshold.
  • Of course they're pissed at MS... by gordguide (Score:1) Saturday December 22 2001, @02:42PM
  • This is Par for the Course by dbCooper0 (Score:1) Saturday December 22 2001, @03:11PM
  • Gov shouldn't be using MS anyway (Score:3, Informative)

    by MrResistor (120588) <<petehoff> <at> <pacbell.net>> on Saturday December 22 2001, @03:15PM (#2741986) Homepage
    That statement isn't meant from the point of view of OSS zealotry (although I certainly have some feelings in that direction), but because the NSA has never rated an MS product as being secure in a networked environment. Part of the NSA's job is to issue information security recomendations, which other agencies are then supposed to use when putting together their systems.

    IIRC, NT at some point was rated secure when not networked.

  • by edunbar93 (141167) on Saturday December 22 2001, @03:54PM (#2742068)
    This is a really, really, really big one. It should be in the newspapers. Microsoft has claimed some time ago (free karma to the one who posts a link) that closed source, for-profit software and operating systems are more secure because the company can actually *hire* people to do security audits of the source code, whereas open source developers aren't motivated to do it because it's really boring, and there's no glory in it.

    Now, we all know that OpenBSD has proved them wrong, by proving not only that open source developers *want* to do hardcore security audits of the source code, but that doing hardcore security audits on source code prevents security holes from being released into the wild. OpenBSD [openbsd.org] hasn't had a remotely exploitable security hole in the default install in FOUR YEARS! Windows XP has been in release for for all of about two months, and already there's a major security exploit found.

    This proves by Microsoft's OWN ADMISSION, either they do not hire people to do the hardcore security audits they say they can, or if they do, they can't do it as well as the volunteers who "obviously" don't do it at all because there's no monetary motivation to do so.

    With lies like this, Microsoft couldn't get into a Better Business Beurau if they paid each of its members a billion dollars.
  • Maybe there's another bug.... by cathryn (Score:2) Saturday December 22 2001, @04:14PM
  • Consipracy theory. by agupta_25 (Score:1) Saturday December 22 2001, @04:20PM
  • And then there's open sockets.... by Sara Chan (Score:2) Saturday December 22 2001, @04:53PM
  • Al-quaeda sabotage? by ab315 (Score:1) Saturday December 22 2001, @05:10PM
  • Progress by DarkProphet (Score:1) Saturday December 22 2001, @05:38PM
  • One OS To RULE them all. by ImaLamer (Score:2) Saturday December 22 2001, @05:59PM
    • 1 reply beneath your current threshold.
  • I'm Surprised nobody else caught this.. by rongage (Score:1) Saturday December 22 2001, @06:00PM
  • Al-Qaeda inside by chris_sawtell (Score:1) Saturday December 22 2001, @06:34PM
  • confused by benjamindees (Score:1) Saturday December 22 2001, @06:56PM
  • Instructions for Fool Proof Protection by Anonymous Coward (Score:1) Saturday December 22 2001, @07:42PM
  • w1nd0wz sux0rZ 4nd l1nux r00lz by netwerk (Score:1) Sunday December 23 2001, @01:17AM
  • info: using linux means never having to say PLEASE by LifesABeach (Score:1) Wednesday December 26 2001, @03:50PM
  • Re:They need to mind their own buisness by ackthpt (Score:2) Saturday December 22 2001, @09:22AM
  • Ok, Let's think about this... by ackthpt (Score:1) Saturday December 22 2001, @09:34AM
  • Re:OK, M$ is getting stupider by WildBeast (Score:1) Saturday December 22 2001, @09:50AM
  • Re:Way to go FBI (Score:4, Funny)

    by Anonymous Coward on Saturday December 22 2001, @09:52AM (#2741227)
    Why buy a CD? Using this bug, you can install Mandrake remotely to all Windows XP systems connected to the internet.
    [ Parent ]
  • Re:I wonder if XP users can sue... by WildBeast (Score:1) Saturday December 22 2001, @10:00AM
  • Re:I wonder if XP users can sue... by Quazion (Score:1) Saturday December 22 2001, @10:23AM
  • Re:Can't get through? Different patch mirror sites by Ryokos_boytoy (Score:1) Saturday December 22 2001, @11:25AM
  • Re:Yet another link to MSNBC by Enahs (Score:2) Saturday December 22 2001, @11:32AM
  • Of course they can't by phillymjs (Score:2) Saturday December 22 2001, @11:55AM
  • 35 replies beneath your current threshold.