www.broadbandreports.com
::Register or
  
  News » The Mother of All MS Exploits? - 'Biggest exploit yet' sat unpatched for six months

Search for:

including ZIP


icon key

Not visiting daily? Visit recent news summary
(also see most discussed news over the last three months)
Microsoft apparently sat on a serious Windows OS vulnerability for six months before announcing the availability of a fix today. One analysts calls the latest exploit one of the "most serious Microsoft vulnerabilities ever released". "The breadth of systems affected is probably the largest ever," says Marc Maiffret of eEye Digital Security, the firm that first discovered the vulnerabilities. "This is something that will let you get into Internet servers, internal networks, pretty much any system."

The Microsoft advisory warns that a ASN.1 (abstract syntax notation) vulnerability could allow remote code execution on versions of the company's XP/NT/2000 operating systems. While there are no documented cases of attacks yet, security experts expect hackers to take advantage of the vulnerabilities in a matter of weeks or less. They also warn that the exploit's severity (and the potential in some cases for attackers to bypass firewalls) could make worms like Nimda and Code Red look like heavily sedated kittens compared to what's coming.

Maiffret tells the Associated Press the 6 month delay after the group notified Microsoft was "just totally unacceptable" because Windows users were left vulnerable. Microsoft security executive Stephen Toulouse says the company "took the steps to make sure our investigation was as broad and deep as possible." The patch is available via Windows Update. The exploit may bring renewed debate over whether or not making Windows Update an automatic feature is a good idea.

Posted now See: security trouble

Forums » News articles » The Mother of All MS Exploits?
forum
info
view:·topics·flat·text·nest 
Article reminder: Microsoft apparently sat on a serious Windows OS vulnerability for six months before announcing the availability of a fix today. One analysts calls the latest exploit one of the "most serious Microsoft vulnerabilities ever released". "The breadth of systems affected is probably the largest ever," says Marc Maiffret of eEye Digital Security, the firm that first discovered the vulnerabilities. "T..
Logic Wins Again
Mike
Forum Mod
Joined 09-17-2000
Location: Pittsburgh, PA
Stargate
Host of:
Campus Broadband Chat, Site Tools, DirecTV DSL, DSLi,
logic?
It's nice of all these hundreds upon hundreds of windows exploits are finally surfacing.

The question is, how many people were farked because of it?

It's like KDE having over 10,000 bug fixes / tweaks / optimizations to the GUI. How many people really noticed all of them?
--
Everyone is entitled to their opinion. Of course, they're entitled to be blithering idiots at the same time.
What this country needs is a good five dollar plasma weapon.
» | 2004-02-10 17:37:59 | · Reply to this
Got Boost?
GNXPower

Joined 12-18-2003
Location: Huntington Beach, CA
Verizon west (ex G..
Re: logic?
I agree, it's one of those if a tree falls in the woods kinda things.

There is a big difference between an exploit and an exploited exploit.
--
Don't have it?!? Demand it!!! The Anime Network »www.theanimenetwork.com
» | 2004-02-10 18:13:42 | · Reply to this
Eno Eht
enOehT
(P)
Location: Philadelphia, PA
RoadRunner

edit: Tuesday February 10th, @05:39PM

Holy crap!
I just ran windows update and it says there is nothing for me to update. OMG! I am a sitting duck. Please, help!
--
» | 2004-02-10 17:38:34 | · Reply to this
Jesus Rocks
exocet_cm

Joined 03-23-2003
Location: Slidell, LA
Charter Pipeline
Holy Panties Batman!!!
quote:
company's XP/NT/2000 operating
If your not running one of those OS's, then your good to go. Otherwise, your screwed.

Although I do wish you the best of luck!
Cheerio!

--
He that feeds a disease, feeds an enemy. Some diseases are starved. Starve your sins by fasting and humiliation. Either kill your sin, or your sin will kill you. - Thomas Watson Harmless as doves 131
» | 2004-02-10 17:40:16 | · Print · Reply to this
Eno Eht
enOehT
(Premium)

Joined 05-17-2003
Location: Philadelphia, PA
RoadRunner
Ohh man! I'm SOOOO Screwed!
When my boss finds out about this I am going to lose my job! Please help me patch this thing up before all the worms and trojans come running in!

SOS!

This ship is going down nose first!
--
» | 2004-02-10 17:44:44 | · Reply to this
Look Mom, I'M Flying With No Hands
WedgeAntilles250
MVM

Joined 05-24-2000
Location: Cleveland, OH
EarthLink

edit: Tuesday February 10th, @05:49PM

Re: Ohh man! I'm SOOOO Screwed!
  • Microsoft Windows NT® Workstation 4.0 Service Pack 6a – Download the update.

  • Microsoft Windows NT Server 4.0 Service Pack 6a – Download the update.

  • Microsoft Windows NT Server 4.0 Terminal Server Edition Service Pack 6 – Download the update.

  • Microsoft Windows 2000 Service Pack 2, Microsoft Windows 2000 Service Pack 3, Microsoft 2000 Windows Service Pack 4 – Download the update.

  • Microsoft Windows XP, Microsoft Windows XP Service Pack 1 – Download the update.

  • Microsoft Windows XP 64-Bit Edition, Microsoft Windows XP 64-Bit Edition Service Pack 1 – Download the update.

  • Microsoft Windows XP 64-Bit Edition Version 2003, Microsoft Windows XP 64-Bit Edition Version 2003 Service Pack 1 – Download the update.

  • Microsoft Windows Server™ 2003 – Download the update.

  • Microsoft Windows Server 2003 64-Bit Edition – Download the update.

  • --
    WedgeAntilles250
    » | 2004-02-10 17:46:30 | · Print · Reply to this
    Logwind

    Location: Logwind

    Re: Ohh man! I'm SOOOO Screwed!
    I think he's being sarcastic guys. Jesus. Everyone knows it's cool to hate MS. Get with the program.
    » | 2004-02-10 18:00:53 | · Reply to this
    Look Mom, I'M Flying With No Hands
    WedgeAntilles250
    MVM

    Joined 05-24-2000
    Location: Cleveland, OH
    EarthLink
    Re: Ohh man! I'm SOOOO Screwed!
    Fool around with this exploit? YEAH RIGHT! I don't think that we should be kidding around with this.

    I for sure am going to be making a few CDs up tonight with SP1 and this patch on it to give to a few n00bs I know.
    --
    WedgeAntilles250
    » | 2004-02-10 18:03:25 | · Reply to this
    Logwind

    Location: Logwind

    Re: Ohh man! I'm SOOOO Screwed!
    That went so far over your head, it was hijacked and flown into a major landmark.
    » | 2004-02-10 18:14:29 | · Reply to this
    Got Boost?
    GNXPower

    Location: Huntington Beach, CA
    Verizon west (ex G..
    LOL, finally someone who got it.
    » | 2004-02-10 18:09:30 | · Reply to this
    yabos

    Location: Ingersoll, ON

    Re: Ohh man! I'm SOOOO Screwed!
    His first post sounds like a legitimate post because the same thing really DID happen to me. But I just downloaded it from MS's website instead.
    » | 2004-02-10 18:22:14 | · Reply to this
    Eno Eht
    enOehT
    (Premium)

    Joined 05-17-2003
    Location: Philadelphia, PA
    RoadRunner
    2 legit, 2legit 2 quit!
    The part about it not being available on Windows update is totally legit! I downloaded it from the link provided by you here: »www.microsoft.com/technet/treeview/def..

    Thanks for the link!

    As for the losing my job, that was to add to the drama. But you did provide me what I was looking for.
    --
    » | 2004-02-10 18:28:49 | · Print · Reply to this
    b2thad
    (P)
    Location: Alexandria, VA
    Verizon Online DSL

    Check your install history on Windows Update. If KB828028 shows up, then you're fine.
    » | 2004-02-10 17:47:25 | · Reply to this
    cablemoose

    Joined 06-25-2001
    Location: Herndon, VA

    I would worry about that Eno Eht. This is just another classic example of Microsoft's laziness and ineptness in fixing there products. Product deadline (it certainly is NOT quality) seems to be there main concern. I'm "preaching to the choir" about the rest. Nuff said.

    Lars
    » | 2004-02-10 18:18:02 | · Reply to this
    seaman

    Location: Seattle, WA

    Re: Holy crap!
    I noticed that too. It hasnt been posted to WU yet but you can find the patches here-
    »www.microsoft.com/technet/treeview/def..
    » | 2004-02-10 17:48:27 | · Reply to this
    yabos

    Location: Ingersoll, ON

    Re: Holy crap!
    It was on there on some PCs I patched, but not others.
    » | 2004-02-10 17:50:13 | · Reply to this
    Grand Groove
    JollyStomper
    (Premium)

    Joined 03-16-2003
    Location: Pompano Beach, FL
    Strange...

    I got the updates from WU a couple of hours before this article even broke out.

    I heard about the exploit while watching Fox News (Neil Cavuto) and immediately checked Windows Update. Sure enough, they were there. Updated my XpPro boxen and my W2K server box (That had two).

    cheers...
    --
    "As I was sayin' buster, this planet ain't big enough for the two of us so... OFF YA GO!"
    » | 2004-02-10 18:18:36 | · Reply to this
    DSL4Brains
    (P)
    Location: Portland, OR
    Verizon Online DSL

    Re: Holy crap!
    I'm still not seeing it on WU. Perhaps they found a major glitch in the patch.
    » | 2004-02-10 18:28:01 | · Reply to this
    yabos

    Location: Ingersoll, ON

    Download from here.

    It didn't show up on my home PC running XP Pro, but 2 work PCs it showed up.
    » | 2004-02-10 17:49:13 | · Reply to this
    Eno Eht
    enOehT
    (Premium)

    Joined 05-17-2003
    Location: Philadelphia, PA
    RoadRunner
    TOO Late! :-(
    Too late! I wasn't quick enough. :-( All the data is gone, all infected. Why would they announce it and then not provide the patch right away?

    Where is that extra pair of under ware, I know I put them around here somewhere?
    --
    » | 2004-02-10 18:01:33 | · Reply to this
    Jesus Rocks
    exocet_cm

    Joined 03-23-2003
    Location: Slidell, LA
    Charter Pipeline
    Screw it...
    I don't care anymore. Once I get infected I'll format my HD and install windows 3.1. You never hear of many security problems with windwos 3.1. I'll just die away in peace...

    --
    He that feeds a disease, feeds an enemy. Some diseases are starved. Starve your sins by fasting and humiliation. Either kill your sin, or your sin will kill you. - Thomas Watson Harmless as doves 131
    » | 2004-02-10 17:38:41 | · Reply to this
    bsr500
    (P)
    Location: MD
    Millennium Digital..

    Re: Screw it...
    why not linux if your going to go with an incompatible os.
    » | 2004-02-10 17:43:50 | · Reply to this
    Got Boost?
    GNXPower

    Location: Huntington Beach, CA
    Verizon west (ex G..
    Re: Screw it...
    Uh oh...the nerd nest is stirring.
    » | 2004-02-10 18:10:40 | · Reply to this
    Iceman4u2

    Location: Rochester, NY

    That is just what we expect from $soft!!!
    It is one thing to work towards a fix, but it's another thing to leave the exploit open and do nothing. This is along the line of the URL in the browser being able to be changed
    » | 2004-02-10 17:39:27 | · Reply to this
    What Happens When I Do This
    TuxNT
    (P)
    Location: Chicago, IL
    Ameritech - SBC
    i guess
    my idea of staying one os behind microsoft apparently isnt going to cut it
    » | 2004-02-10 17:44:35 | · Reply to this
    DSL4Brains
    (Premium)

    Joined 08-26-2003
    Location: Portland, OR
    Verizon Online DSL

    Does anybody out there have a Commodore 64
    ...they want to sell me? I can't deal with this pain anymore. I'm going to call my attorney and start a law suit against Micro$oft for emotional duress. I'm losing weight, I'm drinking heavily and...and...and I kicked my POOR DAMN DOG TODAY over this.

    I've gone over the edge emotionally. I'm completly mental.
    » | 2004-02-10 17:49:48 | · Reply to this
    Karl
    News guy

    Location: Error
    RoadRunner

    Re: Does anybody out there have a Commodore 64
    Attachments:


    I just switched back to the Apple 2gs. I have an extra one if you want.

    PRODOS is where it's at!
    » | 2004-02-10 17:54:03 | · Reply to this
    DSL4Brains
    (P)
    Location: Portland, OR
    Verizon Online DSL

    Re: Does anybody out there have a Commodore 64
    How about a TRS80? Got one of those babies? LOL!
    » | 2004-02-10 18:00:11 | · Reply to this
    All Your Base Are Belong To Us
    ZoboFlobby
    (P)
    Location: Omaha, NE
    Cox HSI
    Do you have Zany golf?

    Is it the WOZ Edition with a Sound Blaster?

    Oh I would love one!
    » | 2004-02-10 18:02:35 | · Reply to this
    Karl
    News guy

    Joined 03-02-2000
    Location: Error
    RoadRunner
    Host of:
    PC gaming GAMES, Broadband Politics and Legislation, Road Runner,

    Re: Does anybody out there have a Commodore 64
    In reality I do have it still packed up with a mountain of err....less than legit software someplace....(did I say that out loud)

    I can still hear the BBS members taunting me for the lack of color ANSI.
    » | 2004-02-10 18:10:33 | · Reply to this
    DSL4Brains
    (Premium)

    Joined 08-26-2003
    Location: Portland, OR
    Verizon Online DSL

    Re: Does anybody out there have a Commodore 64
    said by Karl See Profile:
    In reality I do have it still packed up with a mountain of err....less than legit software someplace....(did I say that out loud)

    I can still hear the BBS members taunting me for the lack of color ANSI.

    Ahhh...remember Cracker Jack? Me and my buddy would sit around and trade software, without actually trading software. We giggled like teenaged girls. That must've been the actual beginnings of software piracy. Of course those days are over and I'd never do that now. Remember the Commodore 1541 5-1/4" 180k disk drives? I pulled a small cooling fan out of an old Wang and duct taped it to the top of it so it'd blow through the vents to keep the drive from overheating. Yes, those were the days.
    » | 2004-02-10 18:19:10 | · Print · Reply to this
    RapidLok (Unregistered) client.comcast.net
    Re: Does anybody out there have a Commodore 64
    Oh, man, here come the memories.... I have four CPUs and about six 1541s, 2 1581s.... I lived about 100 miles north of where you could walk in and buy Cracker Jax!
    » | 2004-02-10 18:28:58 | Reply to this
    DSL4Brains
    (Premium)

    Joined 08-26-2003
    Location: Portland, OR
    Verizon Online DSL

    Re: Does anybody out there have a Commodore 64
    said by RapidLok:
    Oh, man, here come the memories.... I have four CPUs and about six 1541s, 2 1581s.... I lived about 100 miles north of where you could walk in and buy Cracker Jax!

    I think we bought our copy of it right out of a Commodore magazine.

    Do you remember 'notching' the 180k disks so as to get 360k out of them? I used a steak knife to do it until somebody marketed a disk notcher. Technology at its finest.
    » | 2004-02-10 18:35:55 | · Reply to this
    JoshCloud9

    Location: Atlanta, GA

    Download patch here
    It's availkable here:
    »www.microsoft.com/downloads/details.as..
    » | 2004-02-10 17:49:50 | · Reply to this
    DSL4Brains
    (Premium)

    Joined 08-26-2003
    Location: Portland, OR
    Verizon Online DSL

    Re: Download patch here
    How do I know that link isn't some weird re-direct or something? I'm afraid that when I do my Windows update, I may not really be at Microsoft, but at some strange Austrian web site owned by some 16 year-old kid who'll plant strange stuff on my PC.

    FWIW, how do I know this is really Broadband Reports? I could be hijacked right now!

    Where's my Zoloft?
    » | 2004-02-10 17:59:07 | · Reply to this
    Long Strange Trip
    Lophophora

    Joined 06-11-2001
    Location: Thousand Oaks, CA
    DSL EXTREME.COM
    I run a different OS I'm safe - give me a break.
    Yeah if that 'other' OS you were running comprised of ~95%+ of the world market there would be just as many exploits. I'm just tired of reading the constant MS bashing. If you have a problem with them, and haven't already, switch your OS for "crying out loud".
    » | 2004-02-10 17:49:53 | · Reply to this
    Future Engineer
    ryri
    (P)
    Location: Berkeley, CA
    DSL EXTREME.COM
    Re: I run a different OS I'm safe - give me a brea
    Agreed for those who have the option.

    What about those who don't have control over their machines? All they have left is the complaining.
    --
    -Ryan
    The more you know the more you know how little you know,you know?
    » | 2004-02-10 18:00:07 | · Reply to this
    Don't Fight It...It's Inevitable
    Hangmn
    (P)
    Location: Philadelphia, PA
    Covad
    Re: I run a different OS I'm safe - give me a brea
    UM if they have no choice, then I guess its not their problem then is it?
    » | 2004-02-10 18:22:27 | · Reply to this
    Snacks, Food, And Tons Of Beer
    jhboricua

    Joined 06-06-2000
    Location: Minneapolis, MN
    Onvoy

    edit: Tuesday February 10th, @06:04PM

    Re: I run a different OS I'm safe - give me a break.
    said by Lophophora See Profile:
    Yeah if that 'other' OS you were running comprised of ~95%+ of the world market there would be just as many exploits. I'm just tired of reading the constant MS bashing. If you have a problem with them, and haven't already, switch your OS for "crying out loud".
    Hmm, a bit too sensitive today? Kindly point were in the previous posts to yours is something like what you're complaining about stated? I'm just as tired of reading the apologists, but is worse when they cry foul for no reason.
    --
    "Look, If I warm up my breasts with my hands, do you think they'll get bigger or smaller?" - Asuka on the subject of thermal expansion
    » | 2004-02-10 18:01:18 | · Print · Reply to this
    Logic Wins Again
    Mike
    Forum Mod
    Joined 09-17-2000
    Location: Pittsburgh, PA
    Stargate
    Host of:
    Campus Broadband Chat, Site Tools, DirecTV DSL, DSLi,
    Not all OSes are programmed alike.

    I'm personally tired of hearing *that* argument. I understand how you can formulate it. From the CS side, windows is different from unix. Different structure ENTIRELY.

    It's been tied, beaten, and smacked around a long time ago.

    »www.baltimoresun.com/technology/custom..
    »www.businessweek.com/technology/conten..
    Read those, what do you think?
    --
    Everyone is entitled to their opinion. Of course, they're entitled to be blithering idiots at the same time.
    What this country needs is a good five dollar plasma weapon.
    » | 2004-02-10 18:01:28 | · Print · Reply to this
    michaelpelo

    Joined 09-13-2002
    Location: Oaklyn, NJ
    Comcast

    Yea, true. Microsoft has 95% of the home users running their OS so sure they are gonna be the most attacked by hackers. Make sense? Its also not easy to program this software (OS) to be compatible with all the different hardware thats out there. Apply on the other hand can program their OS just to there hardware since Apples come with Apple hardware. That simplifies it a great deal.

    Microsoft Isnt perfect but its no easy task. Give them some credit where credits due. Realeasing a patch is a process that takes a ton of testing, cause you dont want to ruin 25 million PCs with a faulty patch.
    » | 2004-02-10 18:02:55 | · Print · Reply to this
    yabos

    Location: Ingersoll, ON

    That's a bad excuse. Apache runs most websites, and some form of Unix/Linux for most email servers but you don't see many security flaws for those.
    » | 2004-02-10 18:08:57 | · Reply to this
    Logwind

    Location: Logwind

    Patched.
    Thanks for the heads up. As for the IE phishing patch, I'll roam without it as I like my browser to recognize the "@" symbol in URLs.
    » | 2004-02-10 18:02:39 | · Reply to this
    Live By The Sword...Die By The Sword
    cobrakon
    (Premium)

    Joined 09-21-2002
    Location: Hialeah, FL
    EarthLink
    Re: Patched.
    "And it's a solid hit! A long drive to the left wall...Here comes Win2K rounding second...he's out! Here come's WinXP past 3rd...he's out! 98SE is trying for home plate...going...going...and....he's SAFE! Win98SE is SAFE!!

    lol

    Seriously though, I've been lovin my perfectly stable 98SE for some years now. I suppose my work PC is fooked though. I might get on XP by SP3-4...
    --
    -The Cobra
    "Heh, your broadband style is good grasshopper....but not good enough. Watch my Bellsouth style..."
    1180K download 218K upload (BS FastAccess 1.5M/256K @ 19,000ft!)
    » | 2004-02-10 18:20:35 | · Print · Reply to this
    Confusimus Completimus
    idonotexist

    Joined 01-25-2001
    Location: Oakwood, GA
    BellSouth
    hi i am a l33t linux g33k
    half the people that whine don't even know what they are whining about.

    you all got your dell computers preinstalled with xp and all you can do now is whine. seriously, stop it. bugs are there and will be. the ones that are patched have been found. so if something has been there since the release of a program 2 years ago but never found by those who do that for a living, chance is that well... you are pretty safe.
    » | 2004-02-10 18:05:53 | · Reply to this
    Ride Free
    kv5e
    (P)
    Location: Mesquite, TX
    Comcast
    Laissez Faire?
    M$ believes in $inning first and a$king for forgiveness later. Unbelievable to know this exploit and sit on it for six months.

    There should be a fine for this exposure, but we all know the gov's track record with the Monolith $tentorian!
    » | 2004-02-10 18:11:44 | · Reply to this
    mr_slick

    Joined 05-22-2003
    Location: Lynnwood, WA

    ...may bypass firewall
    and i thought i was fairly safe behind nat router and NIS and (most of all) "safe computing". looks like i'm going to have to build a linux box firewall to put in front of the router ---this site has made me a believer --amen!
    » | 2004-02-10 18:27:26 | · Reply to this
    add to the discussion..


    Want no ads here? find out how to block them


     
    Tuesday, 10-Feb
    18:38:59
    © 1999-2004 broadbandreports.com/dslreports.com.
    Terms of Use - Privacy Policy. Use signifies your agreement.
    Another Satisfied Customer of Net Access Corp. - DSL,Hosting & Co-lo. www.nac.net
     feedback for broadbandreports