What is the BigBlueNetwork?

Go Back   BigBlueBall Forums > Computer Support > Computer Support Discussion

Join today and you won't have to look at these ads any more. Learn more.
Reply
 
LinkBack Topic Tools
  #1 (permalink)  
Old 02-12-2004, 08:51 PM
EvilSeph's Avatar
EvilSeph EvilSeph is offline
BigBlueBall Alumni
 
Join Date: Jul 2003
Location: Canada
Posts: 583
EvilSeph is a celebrity (300)EvilSeph is a celebrity (300)EvilSeph is a celebrity (300)EvilSeph is a celebrity (300)
Windows 2000 and NT source leaked!

Neowin.net is reporting that Windows 2000 and Windows NT source code has been leaked to the internet.

Quote from: Neowin.net
"Neowin has learned of shocking and potentially devastating news. It would appear that two packages are circulating on the internet, one being the source code to Windows 2000, and the other being the source code to Windows NT. At this time, it is hard to establish whether or not full code has leaked, and this will undoubtedly remain the situation until an attempt is made to compile them. Microsoft are currently unavailable for comment surrounding this leak so we have no official response from them at the time of writing.

This leak is a shock not only to Neowin, but to the wider IT industry. The ramifications of this leak are far reaching and devastating. This reporter does not wish to be sensationalist, but the number of industries and critical systems that are based around these technologies that could be damaged by new exploits found in this source code is something that doesn't bare thinking about.

We ask that for the wider benefit of the IT community that members and readers support Microsoft by forwarding anything they know about the leak to the Microsoft's Anti-Piracy department."

View:
Neowin.net Article

---------------------------------------------------

The world's biggest software company, Microsoft, says hackers have broken into its corporate computer network.

The hackers gained access to the source code, or blueprints, of Microsoft's Windows-based software, which is estimated to run on about 90% of the world's PCs.

But Microsoft's president and chief executive, Steve Ballmer, insisted they had not been able to tamper with any of the company's key programs.

He said: "It is clear that hackers did see some of our source code.

"I can assure you that we know there has been no compromise of the integrity of the source code; that it has not been modified or tampered with in any way."


Serious consequences

Microsoft's abuse of its near monopoly and refusal to share its source code have been at the centre of a long-running and bitter legal battle with the US authorities.

The security failure could create serious commercial problems for Microsoft if the hackers managed to download source code.

But more than this, if the hackers were able to tamper with the code, and Microsoft did not discover the changes, there could be problems for customers who might buy any affected products.

Earlier, Microsoft had been tight-lipped: "We recently became aware of a hack to our corporate network.

"Microsoft is moving aggressively to isolate the problem and ensure the security of our internal network."


Russian connection

While the firm's reluctance to say much is understandable, more details of the attack have been reported in New York's Wall Street Journal.

It says the security breach was discovered by staff on Wednesday. They detected internal passwords being sent remotely to an e-mail account in St Petersburg in Russia.

Electronic logs apparently showed that the passwords were being used to transfer source code.

Computer security experts say the hackers appear to have used a virus called Qaz to break into Microsoft's network.

They say Qaz first surfaced in China in July and is a "worm" virus, which makes copies of itself to spread throughout a network.


Secrets

Once installed, the Qaz program allows hackers unauthorised access to the network by, for example, relaying back to them passwords and other secret information.

It is also believed that the virus entered Microsoft's system within an inconspicuous-looking e-mail and, once inside, began replicating.

This kind of virus is known as a Trojan, after the Trojan Horse of Greek mythology, which was used to end the siege of Troy.

Astonishingly, the hackers are believed to have had access to Microsoft's network for three months before the breach was detected.

Microsoft says it has referred the attack to the US Federal Bureau of Investigation (FBI) and is working with the authorities to "protect its intellectual property".

View:
BBC News Article

---------------------------------------------------

Microsoft tracks possible Windows code leak
Microsoft is investigating the possibility that a file posted to several underground sites and chat rooms contains some protected source code to Windows 2000.

The 203MB file contains the code that appears to be from Microsoft's enterprise operating system, but the code is not complete, said Dragos Ruiu, a security consultant and the organizer of the CanSecWest security conference, who has examined the file listing.

"It was on the peer-to-peer networks and IRC (Internet relay chat) today," Ruiu said. "Everybody has got it; it's widespread now."

The 203MB file expands to just under 660MB, he said, noting that the final code size almost perfectly matches the capacity of a typical CD-ROM. The entire source code, he said, is believed to be about 40GB, meaning that the file circulating Thursday would be only a fraction of the full code base--if it is authentic.

Ruiu, who has seen the file, believes it to be authentic. "It looks real," he said. "You can't build Windows, however. It's just a bunch of chunks of the operating system."

Microsoft said it is looking into claims that file traders were swapping its proprietary source code.

"The rumor regarding the availability of Windows source code is based on the speculation of an individual who saw a small section of unidentified code and thought it looked like Windows code," Microsoft said in a statement provided to CNET News.com. "Microsoft is looking into this as a matter of due diligence."

Earlier Thursday, a source located a file purporting to be the code on a Web site, but the file was removed from the Internet before it could be completely downloaded.

The potential that the source code has been released has some security experts worried.

"It's definitely not a good thing if black hats have the source code," said Oliver Friedrichs, senior manager with antivirus company Symantec's security response center. If the source code as been released, "the underground can look at the code without legitimate security researchers being able to find vulnerabilities first."

But Microsoft downplayed any security issue.

In its statement the company said the main concern is the potential theft of its handiwork rather than the possible security threat that such a leak might pose.

"If a small section of Windows source code were to be available, it would be a matter of intellectual property rights rather than security," Microsoft said.

Microsoft jealously guards the source code to the various versions of its Windows operating system, sharing it only with universities and government agencies that sign agreements not to release the code. While working versions of Microsoft's operating system have occasionally leaked to the Internet, actual source code leaks have been rare

Although Microsoft Chairman Bill Gates has publicly bragged about the security of Windows, even Microsoft fears the release of its code. In testimony during the Microsoft antitrust trial, Jim Allchin, the company's senior vice president for Windows, said opening up the company's source code could be devastating for the operating system's security.

"The more (that) creators of viruses know about how antivirus mechanisms in Windows operating systems work, the easier it will be to create viruses or disable or destroy those mechanisms," Allchin testified during a May 2002 antitrust trial.

Allchin made the statements while defending the company against legal remedies supported by nine states that would have compelled Microsoft to giveaway the source code to Internet Explorer.

Allchin's fears are not misplaced, said Thor Larholm, senior security researcher with security consultancy PiVX Solutions.

"Just look at the amount of vulnerabilities that are discovered without the source code," he said. "The majority of Windows servers are still running Windows 2000. Furthermore, Windows 2000 has a lot of shared code that is still being used by Windows XP and Windows Server 2003."

However, other security experts believe that fears about a leak leading to the widespread discovery of vulnerabilities in the code are misplaced.

"Theoretically, to a good reverse engineer, all code is open source," said a Microsoft security consultant who asked not to be identified. He added that the size of the compressed file that was being passed around the Internet sounded about right.

In the end, however, the mistake that made Microsoft's code public might result in benefits similar to open-source code, Ruiu said.

"Short term, there might be problem (as bugs are found), but long term it might be good for them," he said. "Their code might become more secure."

View:
ZDNet News Article

---------------------------------------------------

This news surely is a shock to us. The majority of the world use Windows and this could pose a potential risk for all of us. However, further investigation has revealed otherwise.

Source:
Mentioned sources and Digital-Fanatic.com
Reply With Quote
  #2 (permalink)  
Old 02-12-2004, 10:26 PM
Charles's Avatar
Charles Charles is offline
Senior Member
 
Join Date: Mar 2003
Location: New Jersey
Posts: 538
Charles is on a distinguished road (10)
Send a message via AIM to Charles Send a message via MSN to Charles
The fallout of this will be devastating. This WILL be VERY VERY ugly. White hackers will be submitting actual 'bug reports' to MS. Black-hats will be writing new code to take advantage of these holes faster than ever. Time to start the Penguin Punk Prevention Plan on my server. (Linux)
Reply With Quote
  #3 (permalink)  
Old 02-12-2004, 11:18 PM
darkc0ne darkc0ne is offline
Senior Member
 
Join Date: Aug 2003
Location: er.....tri city, new york, USA.
Posts: 243
darkc0ne is on a distinguished road (10)
Send a message via AIM to darkc0ne
Eeeek... this could be bad for me...I run win2k..

Oh wait it only effects the people that would be buying 2k and nt..But that wont be many because MS is pushing XP and server 2003...Oh well i guess il just watch this unfold and see how many people flock to linux.. then how many flock back cause they cant install their printer

I may be beaten for this post
I fold for max OC
Do you?
Reply With Quote
  #4 (permalink)  
Old 02-12-2004, 11:50 PM
Charles's Avatar
Charles Charles is offline
Senior Member
 
Join Date: Mar 2003
Location: New Jersey
Posts: 538
Charles is on a distinguished road (10)
Send a message via AIM to Charles Send a message via MSN to Charles
I'll gladly help any of those users who choose linux install their printer. It isn't hard when the drivers are already with the OS. It gets a pain in the a$$ when you try and use a laptop video card. Ughh...won't go there. I say everyone is taught Linux and that all companies ship Linux with their computers. (or at least offer the option)
Reply With Quote
  #5 (permalink)  
Old 02-12-2004, 11:54 PM
David's Avatar
David David is offline
Senior Member
 
Join Date: Apr 2003
Location: Portland, OR
Posts: 5,283
David is a name known to all (400)David is a name known to all (400)David is a name known to all (400)David is a name known to all (400)David is a name known to all (400)
Send a message via AIM to David
Quote:
quote:Originally posted by Shizna69

I'll gladly help any of those users who choose linux install their printer. It isn't hard when the drivers are already with the OS. It gets a pain in the a$$ when you try and use a laptop video card. Ughh...won't go there. I say everyone is taught Linux and that all companies ship Linux with their computers. (or at least offer the option)
Here Here!

I'm going to try SuSE tomorrow.

David Amenta
Person Meets Profession - Dave Amenta .com
Reply With Quote
  #6 (permalink)  
Old 02-13-2004, 12:29 AM
Someguy03's Avatar
Someguy03 Someguy03 is offline
Senior Member
 
Join Date: May 2003
Location: Santa Ana, california, USA.
Posts: 2,337
Someguy03 will become famous soon enough (50)
Send a message via AIM to Someguy03 Send a message via MSN to Someguy03
Lol, I was bored and did a search for this on kazaa lite, got about 200+ results. I seriously would'dnt suggest anyone downloads the source though. Usually when files become very populer people attach trojans, viruses, or when the program is run, it deletes something important or corrupts something. I know this because when I wanted to reuse the Norton trial I needed to find a way to delete the hidden registry key that kept track of how long you have had the program. I got a little program off kazaa that was suggested by some people, and I found hundreds of diffrent ones. I downloaded one and when ran it deleted my entire registry and i was forced to reinstall windows. Just a warning.

And also, you must consider what other companys could do with the source if they happened to get it. They might gain a much better understanding of the inner workings of Microsoft's technology.
Reply With Quote
  #7 (permalink)  
Old 02-13-2004, 01:00 AM
Charles's Avatar
Charles Charles is offline
Senior Member
 
Join Date: Mar 2003
Location: New Jersey
Posts: 538
Charles is on a distinguished road (10)
Send a message via AIM to Charles Send a message via MSN to Charles
Quote:
quote:Originally posted by someguy03
And also, you must consider what other companys could do with the source if they happened to get it. They might gain a much better understanding of the inner workings of Microsoft's technology.
Why in God's name would ANY company want to understand these "inner-workings" of Microsoft "technology"? I didn't even know these such things existed...
Reply With Quote
  #8 (permalink)  
Old 02-13-2004, 01:39 AM
Someguy03's Avatar
Someguy03 Someguy03 is offline
Senior Member
 
Join Date: May 2003
Location: Santa Ana, california, USA.
Posts: 2,337
Someguy03 will become famous soon enough (50)
Send a message via AIM to Someguy03 Send a message via MSN to Someguy03
I mean figure out how Microsoft's programs work, maybe steal some features or something.
Reply With Quote
  #9 (permalink)  
Old 02-13-2004, 01:59 AM
Jeff's Avatar
Jeff Jeff is offline
Administrator
 
Join Date: Mar 2001
Location: Laguna Niguel, CA, USA
Posts: 8,973
Jeff has left a lasting impression (500)Jeff has left a lasting impression (500)Jeff has left a lasting impression (500)Jeff has left a lasting impression (500)Jeff has left a lasting impression (500)Jeff has left a lasting impression (500)Jeff has left a lasting impression (500)
Send a message via ICQ to Jeff Send a message via AIM to Jeff Send a message via MSN to Jeff Send a message via Yahoo to Jeff Send a message via Skype™ to Jeff
I know Microsoft would never do anything so sneaky, but what if they let it leak as a way of essentially coercing corporations into upgrading to XP? Many corporations are weighing the costs of switching to Linux, but if they had to make an immediate change, XP would be a much easier upgrade path. After the money is committed, the Linux question gets pushed back another three years.
Reply With Quote
  #10 (permalink)  
Old 02-13-2004, 11:46 AM
ShadowSlayer469 ShadowSlayer469 is offline
Senior Member
 
Join Date: Jul 2003
Location: USA.
Posts: 552
ShadowSlayer469 is on a distinguished road (10)
Hey, anyone who feels like they should swich to Linux I would like to suggest Knoppix. Knoppix is a free version of Linux that runs from a CD-ROM so that you dont have to partition your hard drive. You can dowload Knoppix at http://www.knoppix.net/ . Its about 699 MB so it might take a while, but try it, I did a long time ago and it works great.
Reply With Quote
Reply



Currently Active Users Viewing This Topic: 1 (0 members and 1 guests)
 
Topic Tools

Posting Rules
You may not post new topics
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

All times are GMT -5. The time now is 01:59 PM.
Return to the BigBlueBall.com homepageHome | Contact Us | Privacy Statement | Advertise | Top
Powered by vBulletin® Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0 RC6
Content Relevant URLs by vBSEO 3.0.0 RC6
©1999 - 2008 BigBlueBall.com All rights reserved.