Hotmail Servers Shut Down by Code Red
An Anonymous Coward writes: "SF Gate has this story about Code Red taking down some of Microsoft's Hotmail servers. That's funny." So is Code Red a problem yet? Meanwhile my sircams have stopped, except for 2 people who mail me a hundred or more a day. Thank god for filters, but if I had a monthly bandwidth cap, I'd be pissed.
I just queried Netcraft What's That Site Running and it answers:
... I'm laughing as much as everyone!
The site www.hotmail.com is running Microsoft-IIS/5.0 on Windows 2000
I also tried the SSL Port 443 and it's also hosted on IIS5/Win2K. Hope this clears up any confusion *grin*
One thing to consider here folks: this is a classic case of Security Process falling down. It just so happens it's an Win2K hole in this instance. If Hotmail still ran BSD and there was a root exploit discovered, someone still needs to follow the process and plug the hole.
NB: I'm not excusing MS here
Who has losses that arise from code red?
ISP's and individuals/companies paying for bandwith used.
Who causes this mess?
People who haven't patched their software (gross negligence).
Who can sue who?
People who have losses because of gross negligence.
Micorosoft is shielded by a EULA that limits (or denies)liability (although this EULA might not be fully apllicable worldwide).
Back in the Dark Ages of corporate acceptance of Free Software (circa '97 or so) a common pointy-haired manager complaint was "Who do we sue?"
IE, if the software contained some fatal flaw that resulted in Actual Money being lost, the corporation could go after a commercial software house in the courts in an attempt to recover costs.
Free Software, being provided as a community service with no sue-able corporation behind it, lacked this perceived accountability.
Well, here we have a gold-plated example of a fatal flaw in a piece of commercial software, coupled to a lax attitude towards fixing it, that has without question resulted in the loss of Actual Money by a great deal of people. One would think then, that IS Managers across the world would be queuing up to sue Microsoft and recover their costs.
Anybody seeing any evidence of this happening?
Want to learn about race cars? Read my Book