Slashdot Mirror


Visual Studio .Net: Now with more Viruses

News.com breaks the story (and 8000 readers submit) that Microsoft distributed Nimda-infected copies of Visual Studio .Net in Korea. I don't even know what to say here; nothing seems adequate, except to point out that "trustworthy computing" does not seem to have had any effect whatsoever. News.com just updated their story to point out that it probably won't infect the people who installed Visual Studio .Net, but it's still a rather nasty faux pas for a company that's supposed to be cleaning up its act.

396 comments

  1. So.... by Jacer · · Score: 5, Funny

    Did McAfee or Norton give this press release?

    --
    --fetch daddy's blue fright wig, i must be handsome when i release my rage
    1. Re:So.... by rector · · Score: 2, Funny

      In fact, the virus was found by a Microsoft employee manualy without any special software.

    2. Re:So.... by hiei · · Score: 1

      It's on the dresser, next to the keys! I've told you a million times!

      Favorite. talk show. ever.

      --
      Upgrade your grey matter, cause one day it may matter
    3. Re:So.... by Monoman · · Score: 1

      The Onion? :-)

      --
      Keep the Classic Slashdot.
  2. What... the... hell.... by aetherspoon · · Score: 2, Interesting

    I mean, come on, anyone ELSE see this as similar to when the Cult of the Dead Cow released Back Oriface 2000 with CIH preinstalled? :)

    Seriously, before any of the "OH ITZ M$, THY SUXX!!!1111" posts come out, lets be honest. Any company can make that mistake. It takes a special moron in Quality Assurance to release that one.

    I have to ask though... what would YOU do if you were MS in this case?

    --
    --- Ãther SPOON!
  3. they should sort of borrow oracle's motto. by overbom · · Score: 3, Funny

    "breakable"

    or maybe that doesn't quite say it. Hmmm, what am I trying to get at.

    "trivially breakable"

    It only infects one file that's never referenced by the system, and there are all sorts of unlikelihoods that prevent this from being executed. Still, bad press is bad press. :-)

    1. Re:they should sort of borrow oracle's motto. by Waffle+Iron · · Score: 1

      How about "broken"?

    2. Re:they should sort of borrow oracle's motto. by Anonymous Coward · · Score: 0

      "Broken" seems even more important! HAHAahahahahahahahahahahahah!!! ROFL!

    3. Re:they should sort of borrow oracle's motto. by overbom · · Score: 1

      I'm not sure that 'broken' fits with their philosophy. Remember, it's the fault of sysadmins for not applying the requisite patches/fixes for Windows systems.

      I think 'trivially breakable' is much more apt for that reason -- it teeters precipitously on 'broken', and correctly implies that the slightest push will push it into worthlessness. :-)

      mike

    4. Re:they should sort of borrow oracle's motto. by rcamans · · Score: 0

      But isnt " it teeters precipitously on 'broken', and correctly implies that the slightest push will push it into worthlessness. :-) " true of all Microsoft software, so you are really being redundant here?

      --
      wake up and hold your nose
    5. Re:they should sort of borrow oracle's motto. by 1010011010 · · Score: 2

      It only infects one file that's never referenced by the system

      So nice of them to include a useless, unneeded file in their package.

      --
      Napster-to-go says "Fill and refill your compatible MP3 player", which is a lie. It's not MP3. It's WMA with DRM.
  4. Re:What... the... hell.... by Ooblek · · Score: 0, Redundant

    If I were MS, I'd buy all 3 computers in Korea and give them new ones.

  5. Re:What... the... hell.... by Verizon+Guy · · Score: 0

    This sounds like a case for Catbert: 'Evil HR Director.'

    --

    Aw, fuck it. Let's go bowling. - The Big Lebowski

  6. way to go by TheKubrix · · Score: 2, Funny

    If they only had been using a Walmart Lindows box......

  7. Sue 'em by frovingslosh · · Score: 4, Funny

    The guy who wrote that virus should sue Microsoft for distributing it without his permission. We're talking about theft of intellectual property here!

    --
    I'm an American. I love this country and the freedoms that we used to have.
    1. Re:Sue 'em by rector · · Score: 1

      If he sued them he could get quite a bit of money taking into account the scale of the distribution. The virus was evenm poste4d on the MS website!

    2. Re:Sue 'em by MrSkunk · · Score: 1

      The virus was evenm poste4d on the MS website!

      To mash a simpsons quote:
      "The fingers you have used to [type] are too fat. To obtain a special dialing wand, please mash the key[board] with your palm now"

      No that snpp.com uses google as there search engine, simpsons quotes are soooo easy to find.

  8. Perhaps not accidently by BrainInAJar · · Score: 1

    Seriously. Wasn't ms getting angry at that area for it's lax piracy laws? I'm not sure about korea, but think about it. You want to punish software pirates, and local governments don't want you to. What better way than to give them a virus?

    1. Re:Perhaps not accidently by SoCalChris · · Score: 1

      Thats one of the stupid things I've ever heard in my life. Yeah, punish the software pirates by distributing a virus to the people who are legally buying the software! Why don't you pull your head out of your butt and think for half a second before you start saying stupid stuff just so you can jump on the anti-MS bandwagon.

    2. Re:Perhaps not accidently by scott1853 · · Score: 2, Funny

      They already gave them .NET, how far do you expect MS to go?

    3. Re:Perhaps not accidently by SteelX · · Score: 2

      how far do you expect MS to go?

      Well that depends. Since MS is the one taking us for a ride, it depends on where we want to go today.

    4. Re:Perhaps not accidently by scott1853 · · Score: 1

      No, it's "where do you want to go today". MS doesn't want to take that ride with you.

    5. Re:Perhaps not accidently by Anonymous Coward · · Score: 0

      I believe that MS did distribute a virus in it's software many years ago. Not sure if this is the truth, and when and which version it was.

    6. Re:Perhaps not accidently by data_the_android · · Score: 1

      pirates would have had a virus free copy before vs.net was released here. this wouldnt affect them at all

    7. Re:Perhaps not accidently by daf00masta · · Score: 1

      havent you heard of Windows ME? :P

  9. Re:Virus day? by goldspider · · Score: 1, Offtopic

    They must have realized how well it's worked for McAfee and Symantec and decided to give it a go themselves :)

    --
    "Ask not what your country can do for you." --John F. Kennedy
  10. And yet... by Anonymous Coward · · Score: 1, Interesting

    And yet they still argue that "theoretically" open source is the bigger security threat.

    For the love of God, vote Nader.

    1. Re:And yet... by scott1853 · · Score: 1

      I bought a shrink wrapped Mandrake distro a year or two ago and it was 4 CDs. You really think they burned the master and then said, "ok, let's check every single file that we're sending out".

    2. Re:And yet... by Anonymous Coward · · Score: 0

      Have you actually read Nader's platform? I guess you are refering to his plan to get the government's corrupting fingers all over Linux (which is a bad idea). But have yor actually seen some of his positions like a 100% tax bracket above $100k. That sure as hell won't help the tech industry!

    3. Re:And yet... by Anonymous Coward · · Score: 0

      He supports drug decriminalization. That's more important than some tax bracket nonsense.

    4. Re:And yet... by Maserati · · Score: 2
      Yes.


      I really do expect them to fire up NortonAV and scan every single file on the disk, and every archive. THEN they can hand it off to manufacturing.


      I haven't seen a virus on a shrinkwrapped product since the early 90s. Back then, when I was in software retail, we saw 2-3 games a year with a virus on one of the floppies. Bad thing to do to your customers (never mind broken .bat installers and so forth). I'm pretty certain that we never heard from any of those publishers again.


      Honestly, how long does it take to virus scan a CD ? Not the disk image, but the actual burned master in a CD-ROM drive ? In a fast drive (24x or up) it's not that long. And right now every Windows developer in Korea has been sent a virus. What if they do that to a state where it is a criminal offence to distribute a virus ? I'll be quiet now, maybe somebody at RandomeSoftwareHouse will go to jail over sloppy QA. That'll be the Day !

      --
      Veteran, Bermuda Triangle Expeditionary Force, 1992-1951
    5. Re:And yet... by Anonymous Coward · · Score: 0

      Try reading the article.

  11. It's a feature! by gatekeep · · Score: 3, Funny

    Hell, nimda is a better feature than that stupid paperclip thing!

    1. Re:It's a feature! by Anonymous Coward · · Score: 0
      This was part of the sample code set. Understanding that Windows is the #1 virus platform, they are now expanding their IDE scope to include that segment.

      These guys are really good at understanding the user base and giving them what they want/need to make their jobs easier.

  12. Microsoft should be applauded for this by Saint+Aardvark · · Score: 5, Funny
    They...um...made sure that it was a quality worm that went out the door.

    None of your shoddy open-source crap here, no sir!

    1. Re:Microsoft should be applauded for this by Amazing+Quantum+Man · · Score: 4, Funny

      I hope that worm wasn't GPL'ed!

      After all, that would mean that MS would have to distribute the source to VS.NET!

      Hey... now there's an idea :-)

      --
      Fascism starts when the efficiency of the government becomes more important than the rights of the people.
    2. Re:Microsoft should be applauded for this by rector · · Score: 0, Offtopic

      The code of the Visual Studio is a separate peice of software under a different license. The only thing that would be GPL'd is the help files produced during localization.

    3. Re:Microsoft should be applauded for this by Amazing+Quantum+Man · · Score: 0, Offtopic

      Sorry, rector, obviously I forgot the SARCASM tags.

      What I posted was essentially parroting the MS anti-GPL FUD.

      --
      Fascism starts when the efficiency of the government becomes more important than the rights of the people.
    4. Re:Microsoft should be applauded for this by tlhf · · Score: 1

      Yep.

      You obviously did forget the sarcasm tags.

    5. Re:Microsoft should be applauded for this by juliao · · Score: 2
      I hope that worm wasn't GPL'ed!
      After all, that would mean that MS would have to distribute the source to VS.NET!
      Well, quoting from the GPL:
      In addition, mere aggregation of another work not based on the Program with the Program (or with a work based on the Program) on a volume of a storage or distribution medium does not bring the other work under the scope of this License.
      No, they wouldn't have to release the source to vs.nyet. And if they did, what would you want it for?
  13. virus?? by hikeran · · Score: 4, Funny

    I'ts not a virus/spyware.. it's a feature that enhances your web experience.

    1. Re:virus?? by chris_mahan · · Score: 1

      Actually it could be:

      We're so confident our product is secure, we're including this free virus for you to test with.

      JK of course. Doh.

      --

      "Piter, too, is dead."

  14. People like viruses by anthony_dipierro · · Score: 1, Insightful

    If Microsoft products weren't filled with bugs, they wouldn't be Microsoft, now would they? Microsoft is supposed to be a source for buggy virus-filled software. If they sanded off all the rough edges, their products would cease being products that I would want to use. Microsoft has been running its company for how many years now? If you don't like their products, don't buy them! Life is too damn short to worry about bugs in Microsoft software!

    1. Re:People like viruses by kollivier · · Score: 1

      Have you considered a job with Microsoft's advertising department?

    2. Re:People like viruses by anthony_dipierro · · Score: 2

      No, I stole all my ideas from Taco.

  15. Re:What... the... hell.... by Anonymous Coward · · Score: 0

    We're talking about South Korea, not North Korea.

  16. A great new marketing line for Microsoft. by Restil · · Score: 4, Funny

    "You probably won't get any viruses from installing our software!"

    -Restil

    --
    Play with my webcams and lights here
    1. Re:A great new marketing line for Microsoft. by Anonymous Coward · · Score: 0

      Everyone knows you should wrap your .net cd in a condom first.

  17. even better by Srin+Tuar · · Score: 4, Funny


    "breakable"

    or maybe that doesn't quite say it. Hmmm, what am I trying to get at.

    "trivially breakable"

    In this case, "broken" is what your looking for.

    1. Re:even better by Anonymous Coward · · Score: 0

      Knowing Microsoft's contempt for standards, maybe they should use

      "breaked"

      (Posting anonymously as it's a) unfunny, and b) a cheap shot. :)

  18. World Cup Korea by The+Ape+With+No+Name · · Score: 0, Flamebait

    Well, I was sitting at home the other day, watching Korea tie the US, and I thought, "Y'know, in that stadium there must be 65000 screaming Koreans. At least 10 of them are partially responsible for all of the Nimbda traffic I see and twice that many are responsible for the various Dick Cream spams I get each day." I should have known it had nothing to do with slack ass Korean sysadmins and had everything to do with Redmond. Everytime I fall into that trap, Gates bails me out....

    --
    Comparing it to Windows will be a moot point, since El Dorado is going to have a 40% larger code base than XP.
  19. But this is Impossible! by Anonymous Coward · · Score: 1, Insightful

    he added, it's almost impossible to get the worm to execute on computers with Visual Studio .Net installed

    How did this get infected in the first place?

    1. Re:But this is Impossible! by Ashran · · Score: 1

      You dont have to install it to translate it!
      Dont comment on something you didnt read.

      --

      Before you email me, remember: "There is no god!"
    2. Re:But this is Impossible! by cicho · · Score: 1

      Of course you have to install it, because you have to TEST it. Thoroughly. In fact, typical tests of localized software packages entail _numerous_ install/uninstall cycles. We're talking a large codebase, lots of text, lots of testcases, lots of localization issues to fix, _lots_ of new builds to test. In some phases of the testing, you'll install and uninstall the package a few times a day. It takes weeks, sometimes months.

      --
      "Only the small secrets need to be protected. The big ones are kept secret by public incredulity." - Marshall McLuhan
    3. Re:But this is Impossible! by Ashran · · Score: 1

      Do you really think the text is contained in the source code? I really dont think thats the case, they are most likely some text files or something similiar.

      --

      Before you email me, remember: "There is no god!"
    4. Re:But this is Impossible! by cicho · · Score: 1

      Resource files. You still have to (re-)build the software (at least parts of it), using the resource files, to test the translation. During the testing phase this can be done on a daily basis.

      Of course the exaxt logistics of the process depend on the software house, vendor, etc. Builds can be compiled on site, or, in some cases, are farmed out to the vendor who's providing the translation. (I work for such vendors and have been involved in translating and testing)

      --
      "Only the small secrets need to be protected. The big ones are kept secret by public incredulity." - Marshall McLuhan
  20. Where's the foot? by andy@petdance.com · · Score: 2

    Why is this under the BillBorg icon, and not the Monty Python "it's funny!" foot?

    1. Re:Where's the foot? by Shagg · · Score: 2

      I think we need a new topic icon. The MP foot squashing the MS Borg.

      --
      Unix is user friendly, it's just selective about who its friends are.
    2. Re:Where's the foot? by macdaddy357 · · Score: 1

      This isn't funny if your system gets infected, but it's a great laugh if someone you don't like gets infected! Send your enemies M$ visual studio as a "gift." Happy Holidays, Sucka!

      --
      How ya like dat?
    3. Re:Where's the foot? by Yuan-Lung · · Score: 3, Funny

      Like this? =)

    4. Re:Where's the foot? by getter_85 · · Score: 1

      was this animated with an M$ product?

      j/k, spend more than five minutes with that and I'll support the use of it

      --
      return 0;
      }
  21. Sample code? by SirKron · · Score: 1, Troll

    Oh, when I read this first I thought that Microsoft was distributing the Nimda code as one of thier sample projects. That would be cool, a virus creation wizard. This reminds me of the story a while back about someone modifying a virus to check for security holes so the could be filled.

    1. Re:Sample code? by Anonymous Coward · · Score: 0

      That would be nice. I would love help making a virus with "Clippy" showing a step by step process. At the end, would they show you how to infect a computer on your own machine?

  22. Not entirely Microsoft's fault by 1000101 · · Score: 5, Insightful

    The "third party" that translated the software into Korean had something to do with the problem.

    1. Re:Not entirely Microsoft's fault by Anonymous Coward · · Score: 1, Insightful

      Umm... who's name is on the discs? Who's job is it to ensure their quality. Yeah. It's their fault.

    2. Re:Not entirely Microsoft's fault by scott1853 · · Score: 1

      When you say "something", you must mean "everything". Of course I guess you could blame MS for making the system that got infected when the third-party was using it to translate MS's software.

    3. Re:Not entirely Microsoft's fault by chef_raekwon · · Score: 1

      oh, right.
      the box probably doesnt even have Microsoft's name on it. It has the third party tranlators name on it....
      hmmmmmm.

      --
      We're like rats, in some experiment! -- George Costanza
    4. Re:Not entirely Microsoft's fault by Anonymous Coward · · Score: 0

      Who cares. There isn't any fun when you know EXACTLY what happened! Besides, shouldn't microsuck make sure that their distributors don't modify the contents? (they should merely modify the language used, not the functionality of the product) Doncha think?

    5. Re:Not entirely Microsoft's fault by timeOday · · Score: 5, Funny

      So how do we tell "Genuine Microsoft Quality Products" from "Shoddy Software Created By Third Parties And Put Out By Microsoft"? Is the hologram a different color or something?

    6. Re:Not entirely Microsoft's fault by MrFredBloggs · · Score: 1

      If they`re ok with making money from it, dont you think they should earn that money by acting responsibly?
      Or is it just...
      "Hey, it compiles!"
      "Cool, burn it onto a CD, stick it in the post and lets get out of here!"

    7. Re:Not entirely Microsoft's fault by Jason+Earl · · Score: 5, Insightful

      That's a load of hooey. Microsoft's customers didn't ask them to use a third party to translate the files, nor did they purchase the product from the third party. If Microsoft can't even handle the elementary security step of scanning the product for viruses before putting it on a CD, how do you even know that the mysterious third party isn't replacing important DLLs with DLLs that are functionally equivalent but have a hidden backdoor.

      Clearly Microsoft isn't really checking these files. Which means that when Microsoft says "Trustworthy computing" what they are really saying is that you should trust them, and all of their "third party" allies despite the fact that they have a horrific track record.

    8. Re:Not entirely Microsoft's fault by WarpedMind · · Score: 1

      I would not be surprised if this "third party" wasn't a sub-siderary, like Microsoft Korea.

      Off-shore companies are good for things other than hiding profits.

    9. Re:Not entirely Microsoft's fault by malfunct · · Score: 1

      If you buy the US English version of the product you can be well assured that it came out of MS directly. The internationalized versions are often run through a third party for translations because face it, MS knows how to make software, not how to write in korean.

      --

      "You can now flame me, I am full of love,"

    10. Re:Not entirely Microsoft's fault by chris_mahan · · Score: 5, Insightful

      [This post contains language you might find offensive]

      Isn't Microsoft entirely in control of selecting the vendor (the translation/locatization company)?
      Would Microsoft be liable if the translator had said: Fuck you and You Eat Dog Now in the manual? Of course.

      Another silly analogy. My VW beetle was assembled in Mexico. Do you think VW says: "Oh, sorry, those damn mexicans screwed up?" when I have a problem with my car? No. They say: "We're sorry, and we'll fix it right away at no charge".

      They don't even mention the outsanding factory workers south of our border. They just take it like men and deal with it responsibly.

      That's why I prefer VW service over Microsoft's.

      --

      "Piter, too, is dead."

    11. Re:Not entirely Microsoft's fault by Anonymous Coward · · Score: 0

      I think the VW dealer is more disposed to giving better service than Microsoft because you spent $200-$400 for the software and $18000+ for the car.

    12. Re:Not entirely Microsoft's fault by namespan · · Score: 0, Offtopic

      You Eat Dog Now

      Actually, in Korea, they do eat dog. Animal rights activists are consistently agitated over it.

      If the reports are true that say they believe that beating the animal to a very painful and panicked death improves the flavor, I'm actually inclined to agree for once.

      --
      Libertarianism is rich wolves and poor sheep playing gambler's ruin for dinner.
    13. Re:Not entirely Microsoft's fault by chris_mahan · · Score: 0, Offtopic

      Oh, I know, that's why I put it there.

      They also fornicate, as far as I can tell.

      The bit about the dog: Oh well. You think that the cats, rats, and other such rodents that dogs kill don't die a very painful and panicked death?

      It's the Circle of Life.

      I actually think that one of the biggest reason the instinct of self preservation is so strong is because death is painful and panicked most of the time. And the instinct of self-preservation is really important for the long-term survival and evolution of a specie.

      How did I get so off-topic so fast?

      --

      "Piter, too, is dead."

    14. Re:Not entirely Microsoft's fault by MoogMan · · Score: 1

      Yes, the hologram is a different colour, but the one that we all see is the "Shoddy Software Created By Third Parties And Put Out By Microsoft" one - They keep one single master copy of the "Genuine Microsoft Quality Products" hologram locked up in a safe for that one day in the distant future...

    15. Re:Not entirely Microsoft's fault by Anonymous Coward · · Score: 0

      Raw Car Materials (much of the car is purchased from third parties preassembled) + Full Gas Tank: $2,500, or a bit under 15%

      Raw Microsoft Materials provided to you with an OEM copy of software: $1, or 1/4%.

      Methinks MS needs to provide more for your dollar.

    16. Re:Not entirely Microsoft's fault by jazmataz23 · · Score: 1

      Put the X-files fanzine down and step away from the paranoid dementia.
      They are checking the files they know to exist. Most likely some sort of secure hash before-n-after comparison like MD5 is a part of that process.

      Yes, scanning only for the files you know are there is pretty boneheaded. You're hyperventilating because Microsoft is the culprit.

      Do you know why Microsoft makes so many mistakes? Because they have a lot of products. More risks, more chances to make a mistake. Take a look at the number of strikeouts homerun hitters get compared to leadoff hitters.

      feh.

      --
      Death to Argument by Slogan!! (This post twice-encrypted with ROT-13. Replies not using same will be ignored)
    17. Re:Not entirely Microsoft's fault by Anonymous Coward · · Score: 0

      thats how open source works!
      Why do people always think open source coders must be better coders than closed source coders?
      Do you think Bill Gates is coding windows? It might be the very same coder working on Windows that wrote parts of the RMSSUCKS/Linux kernel...

    18. Re:Not entirely Microsoft's fault by gmuslera · · Score: 1

      Do you know why Microsoft makes so many mistakes? Because they have a lot of products. More risks, more chances to make a mistake. Take a look at the number of strikeouts homerun hitters get compared to leadoff hitters.

      That remembers me that Apache have more worms in the wild because more servers use it :)

    19. Re:Not entirely Microsoft's fault by Anonymous Coward · · Score: 0

      I know the vendor that makes the CD's for MS in Korea. They picked up NIMDA for one of the many companies they support (I know exactly which one). This was the HTML/Outlook worm.

      Once it got in house, it ran around their computers and tagged along with some otherwise errant code that was being mastered and blapp...right onto a CD for MS. I also know that MS wasn't the only one...Dell and others suffered in this.

      There were millions of CD's that had to be scrapped, and the system is still trying to recover financially. It was an ignorant local worker that refused to do his job right that originally handed off the content to the CD duplicator house. He's in marketing now, where hopefully, he can't do any further harm on this scale.

    20. Re:Not entirely Microsoft's fault by SAFH · · Score: 2

      ---
      Put the X-files fanzine down and step away from the paranoid dementia.
      They are checking the files they know to exist. Most likely some sort of secure hash before-n-after comparison like MD5 is a part of that process.

      Yes, scanning only for the files you know are there is pretty boneheaded. You're hyperventilating because Microsoft is the culprit.

      Do you know why Microsoft makes so many mistakes? Because they have a lot of products. More risks, more chances to make a mistake. Take a look at the number of strikeouts homerun hitters get compared to leadoff hitters.

      feh.
      ---

      As an individual who has been responsible for the distribution of many products in the past, a virus being a part of a distribution is NOT acceptable by any stretch of dementia.

      There have been comical quotes of Virual Studio .NET or jokes about "Trustworthy Computing" and a couple decent BillG skits, however the point here is that yet another company is not taking the rudimentary steps to protect it's customers.

      Microsoft's products are (for better or worse) being used the world over; in schools, doctors offices, hospitals, law firms, all through out the US Government and practically everywhere else you look and there is no one that is ensuring that they are following basic security protocols.

      Yes, "What if..." .DLL's are being replaced (or added) by anti-US operatives, or modifications are being made adding back doors... Yah, it's a bit X-Files'ish but not that far from reality. Obviously a source CD/Drive was sent over to be burned, and was connected to an insecure network, how hard would it be to figure out what network that is and insert a DLL that tracks connections on boot? AdWare companies do it through website and software installations all the time.

      Just a thought...

      feh. yourself.

      --

      I cannot confirm nor deny the allegation or allegations you may or may not have just made

    21. Re:Not entirely Microsoft's fault by Anonymous Coward · · Score: 0

      Yeah, and the other day I installed RedHat 7.3 off of their CD's, and we lost half a day of productivity because the installer fucked the permissions on a bunch of libraries. When we contacted RedHat to find the source of the problem, their advice was not to troubleshoot the problem and to reinstall. Next time you want to talk about quality testing I could point you to a whole shitload of Linux CD's that have caused hell for many admins, but they are ignored by the ignorant Slashdot masses.

    22. Re:Not entirely Microsoft's fault by Anonymous Coward · · Score: 0

      No numbnuts, however there are a ton of RedHat boxes which were previously running the essential rpc.statd service before they were rooted.

    23. Re:Not entirely Microsoft's fault by Spoing · · Score: 2

      Failures found in lower levels of a company are always management's fault. You can't blame a lack of oversight on the unsupervised.

      --
      A firewall can not protect you from yourself. Turn off what you do not need. Do not use the firewall to do your work.
    24. Re:Not entirely Microsoft's fault by Spoing · · Score: 1

      Which packages? RedHat supplied? Seriously.

      --
      A firewall can not protect you from yourself. Turn off what you do not need. Do not use the firewall to do your work.
    25. Re:Not entirely Microsoft's fault by tero · · Score: 1

      However the reality is that localization and translation is hardly ever done "inhouse" anymore. 99% (save Xerox, perhaps) of big companies outsource all their localization and translation. So in that sense we, as consumers and customers don't get to "ask them".

      Other than that, I agree completely. Checking the files before distribution should always be done, no matter how many parties have been involved in the process.

    26. Re:Not entirely Microsoft's fault by Snover · · Score: 1

      That's probably because most of those Mexican workers are child labourers, and nobody wants to think their, uh, stuff was made by child labourers...even though most of it is.

      "Ignorance is Bliss."

      --

      [insert witty comment here]
  23. yeah by paradesign · · Score: 0, Redundant

    i bought a computer with a virus on it once, oh what was it called? oh yeah, windows!

    --
    I want 2D games back.
    1. Re:yeah by Anonymous Coward · · Score: 0

      Fortunately Linux can't be considered a virus since its not capable of spreading.

  24. Re:What... the... hell.... by purpledinoz · · Score: 1

    South Korea, you ignorant fool! And please, don't ask whether I know Glen from Canada!

  25. Re:Accident? Sounds like criminal negligence! by JUSTONEMORELATTE · · Score: 1
    Go ahead a mod this down -- redundant.
    RTFArticle already
    • M$ didn't introduce it; a translating company contracted to do the Korean language version did.
    • The executable would have to be sought out and manually run
    • You'd need to use IEv5.x to execute, and the version of Studio in question requires v6.x


    Just pissing in the wind, I guess
  26. Trustworthy computing? by Anonymous+Brave+Guy · · Score: 2

    Well, at least we can still trust Microsoft on one count...

    --
    If you disagree, post your argument. (-1, Overrated) isn't your personal censorship tool for views you don't like.
  27. Double your pleasure? by TVmisGuided · · Score: 1

    Does this mean all the spam I'm getting from kornet.com will also have Nimda attached? Wow...maybe that overpriced antivirus software can now be used as a spam filter too!

    We now return to our regularly-scheduled MS flaming, already in progress...

    (Yes, this is an attempt at humor. Moderate accordingly.)

    --
    All the world's an analog stage, and digital circuits play only bit parts.
  28. Re:What... the... hell.... by Buck2 · · Score: 0, Offtopic

    What kind of fucktard are you?

    Verizon Guy?

    Are you getting paid for this?

    --

    As my father lik@(munch munch)... ....
  29. Only one thing I can say... by Skweetis · · Score: 4, Funny
    GET /default.ida?nnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnn nnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnn nnnnnnnnnnHahahahahahah hahahahah hahhahahhaha heeheeeheeehee aaahahahhhhh

    Morons.

    1. Re:Only one thing I can say... by Anonymous Coward · · Score: 0
      That reminds me...

      Recently, my server been getting requests for /NULL.printer, /NULL.ida?AAAAA... and /NULL.idq?HTTP/1.0%20404%20Not%20fouAAAAA.... I don't remember Code Red et. al. using anything besides NNNNs and XXXXs. Anybody know what this new one is?

    2. Re:Only one thing I can say... by Anonymous Coward · · Score: 0

      You could ask on intrusions@incidents.org. I haven't seen that one mentioned there before.

  30. Give it a rest by Anonymous Coward · · Score: 5, Insightful

    Slashdot is rapidly becoming useless with the constant derision it heaps on Microsoft. Let's have more computer news and stuff about FreeBSD and Linux and less "make fun of" news about Microsoft. As if Linux doesn't have it's problems. You might end up like Larry Ellison and his ridiculous "Unbreakable" claims.

    Of course, that's a problem with the Linux crowd. Feer of being, and being seen as, professional.

    1. Re:Give it a rest by Anonymous Coward · · Score: 0

      Fuck Microsoft!

      (And learn how to spell "fear", retard).

    2. Re:Give it a rest by elsegundo · · Score: 1

      Kick 'em when they're down, I say....

      --


      The revolution will be televised. Blackout restrictions apply.
    3. Re:Give it a rest by MullerMn · · Score: 0, Offtopic

      Of course, that's a problem with the Linux crowd. Feer of being, and being seen as, professional.

      That's not something you'll have to worry about with spelling like that.

      Yeah, I know. Spelling flames are the lowest form of internet wit. Blow me.

    4. Re:Give it a rest by Tsian · · Score: 1

      You don't think they would post this is Red Hat shipped with a virus?

    5. Re:Give it a rest by Anonymous Coward · · Score: 0
      Slashdot is rapidly becoming useless with the constant derision it heaps on Microsoft. Let's have more computer news and stuff about FreeBSD and Linux and less "make fun of" news about Microsoft.
      ..
      Of course, that's a problem with the Linux crowd. Feer of being, and being seen as, professional.

      I'd like to point out that the "Linux crowd" and "Slashdot crowd" are not synonymous with one another. Maybe you want less about MS and more about Linux because that's what you enjoy most. But Slashdot is made up of a lot of different people.
    6. Re:Give it a rest by Anonymous Coward · · Score: 0

      Matt Cohn, is that you or is this just another illiterate slashboi bot?

      It's Friday, and nice. Go outside, meet a girl. I am working, otherwise...

      --RWS

    7. Re:Give it a rest by LinuxGeek8 · · Score: 2

      Slashdot is rapidly becoming useless with the constant derision it heaps on Microsoft.

      Oh come on.
      Just like deleting the MS viruses in your inbox and ignoring them, you can just as easy ignore these Slashdot topics.

      --
      Well, don't worry about that. We can get you back before you leave. (Dr. Who)
    8. Re:Give it a rest by haa...jesus+christ · · Score: 1

      Agreed. It's not accomplishing anything, and as far as I remember (from a few years ago) more than half of us are looking at this site on Windows boxen anyway. So if we're so 1337, why aren't we all on linux right now? Michael, you seem a bit upset today. Things at VA got you down?

    9. Re:Give it a rest by Ponkinator · · Score: 1

      Hey, I happen to enjoy reading the derision heaped on Microsoft as I'm sure others do. If you don't like it then just look for the Bill-the-borg icon, read the story and avoid reading the comments.

    10. Re:Give it a rest by Vladimus · · Score: 1

      I like the attitude of "Kick 'em when they're down", but they're not even close to being "down" yet.

      --

      A rolling stone is worth two in the bush!

    11. Re:Give it a rest by SirSlud · · Score: 2

      When MS says they're going to do an about face on their history and enter 'trustworthy' computing with a straight face, they are going to get laughed at when that claim looks strained.

      It's as simple as that. You'd probably be much more upset at us if we didn't all point out up front that we know we're flaming MS. :) That's the difference. When somebody makes a claim they dont keep, they wont get much support or benifit of the doubt (especially if they are the goliath.) I thank god the world works this way, or nothing would ever change.

      Sometimes I wonder what MS would have to do to actually lose some market share if the anti-MS crowd wern't so passionate - probably kill a few people in the middle of a crowd, caught on videotape, I'd wager, although I imagine they'd just point out that the guy holding the gun wasn't an employee .. just another MS perma-temp. ;)

      --
      "Old man yells at systemd"
    12. Re:Give it a rest by Anonymous Coward · · Score: 0

      Most of us are at work, I know at home, windows is not existent (and I manage a Windows Network for a living).

    13. Re:Give it a rest by chris_mahan · · Score: 0

      About as useless as a conversation between a bunch of drinkers at a bar/pub.

      And yet, that's why people go to pubs...

      Mmmm...

      Anyway. As they say in journalism: Leave no stone unturned in the quest for truth/profits.

      --

      "Piter, too, is dead."

    14. Re:Give it a rest by Violet+Null · · Score: 3, Informative

      Let's have more computer news and stuff about FreeBSD and Linux and less "make fun of" news about Microsoft.

      Go here. See the section entitled "Exclude Stories from the Homepage"? Find the box that says "Microsoft" and check it. Scroll all the way to the bottom and click the "Save" button. Walah.

    15. Re:Give it a rest by nEoN+nOoDlE · · Score: 2

      you can always uncheck microsoft articles in your slashdot settings and then stop reading the comments posted under those articles. I for one want to know when Microsoft incorporates viruses into their software and any other time they screw up.

      --
      Don't trust a bull's horn, a doberman's tooth, a runaway horse or me.
    16. Re:Give it a rest by fabiolrs · · Score: 2

      Agreed completely... I even stoped sending in stories since most of them are reject... reviews on linux products (distros, softs, hards, etc), new stuff I found, interesting server stuff, lots and lots of stories... none of them were published...

      --
      Fabio - Sumare/Sao Paulo/Brazil/South America/Earth/Solar System/Milky Way/Universe
      http://www.morroida.com.br
    17. Re:Give it a rest by mithras+the+prophet · · Score: 1

      you must be spelling everything in your submissions correctly. Run an automatic typo generator on your stories, and try again.

      --
      four nine eighteen twenty-7 thirty-nine forty-7 fiftyeight sixty-nine seventy-9 eighty-8 one-hundred-and-nine one-twenty
    18. Re:Give it a rest by Pfhreakaz0id · · Score: 2

      You don't think they would post this is Red Hat shipped with a virus?
      No, I don't. Do you? Really?

    19. Re:Give it a rest by sir99 · · Score: 1

      Yes. Absolutely. They would get hundreds (thousands?) of submissions and post it without a second thought.

      --
      The ocean parts and the meteors come down
      Laid out in amber, baby.
    20. Re:Give it a rest by 0xdeadbeef · · Score: 1
      WTF? The whole point of Slashdot is to make fun of Microsoft. There are better places for news; Slashdot is infotainment.

      Microsoft is waging a propoganda war against their competition, so it's hardly unprofessional to stop and laugh when they end up with egg on their face. Pull that stick out of your butt, AC.

      This event ranks up there with such notable favorites as

      • Getting caught astroturfing
      • Getting caught with a rigged demo in the anti-trust trail
      • The "leaked" Halloween documents
      • Hotmail collapsing after switching to NT


    21. Re:Give it a rest by namespan · · Score: 5, Insightful

      I don't know where to start.

      Slashdot is rapidly becoming useless with the constant derision it heaps on Microsoft. Let's have more computer news and stuff about FreeBSD and Linux and less "make fun of" news about Microsoft.

      Slashdot is hardly rapidly becoming useless. There is no lack of abundance of news about FreeBSD, Linux, Apache, Space, OS X, Wireless, and just about any other significant I/T and geeky topic.

      And while Linux has its problems, and you may not share the editors views about Microsoft, there are two facts about Microsoft that are hard to ignore:

      1) They are huge. Absolutely huge. They have a lot of influence in the I/T and software industry.
      2) Sometimes their market presence and control gives them reputation beyond what's deserved.

      You may not agree with #2, but consider: .NET barely exists right now. Their ads make it look like people are running serious production solutions on it right now. They claimed months back that Trustworthy Computing was their #1 priority. They just made a major gafe. They've ignored simple security problems for years because it suited them.

      I wouldn't claim their technology is useless. It has its high points, a few better than open source alternatives. The problem is that it's all too easy to fall into "They're big, they're #1, so it must be the best" viewing of Microsoft. Most of us who bring up reports like this one do so because we've put up with far too much of that kind of reasoning.

      As if Linux doesn't have it's problems. You might end up like Larry Ellison and his ridiculous "Unbreakable" claims.

      Of course, that's a problem with the Linux crowd. Feer of being, and being seen as, professional.


      Well, that wasn't anything like our petty digs at MS.

      Do you mean afraid to make claims like Microsoft's "Trustworthy Computing" initiative and Oracle's "Unbreakable"? I don't see this as a problem in the open source world. OpenBSD is the only distro that comes close to making anything like an unbreakable claim, and it has history to back it up. We speak softly and upload running code. We release timely information about bugs, security holes, and patches. Cover ups are few. That's professional.

      Of course, yet again, it's so easy to confuse "big" and "professional".

      --
      Libertarianism is rich wolves and poor sheep playing gambler's ruin for dinner.
    22. Re:Give it a rest by MisterBlister · · Score: 1

      I think they would post it, but instead of slamming them in the little editorial comment they would try to put some spin on it and defend Red Hat...ESPECIALLY in a case like this where the virus won't really infect anyone anyway.

    23. Re:Give it a rest by Anonymous Coward · · Score: 0


      Slashdot is rapidly becoming useless with the constant derision it heaps on Microsoft. Let's have more computer news and stuff about FreeBSD and Linux and less "make fun of" news about Microsoft. As if Linux doesn't have it's problems. You might end up like Larry Ellison and his ridiculous "Unbreakable" claims.


      You must be new around here eh?

    24. Re:Give it a rest by EastCoastSurfer · · Score: 2

      I also quit submitting stories after two were quickly rejected a couple of weeks ago. The kicker is that the story popped up submitted by someone else 4-5 hours later. I guess the news I submitted wasn't old enough *shrug*

    25. Re:Give it a rest by Anonymous Coward · · Score: 0

      If only AC's had moderation points - this post would get a big "+5, Right on!" in my book!

    26. Re:Give it a rest by coltrane99 · · Score: 1

      This new policy of criticising Microsoft has got to stop, so Slashdot can go back to being useful again..
      Gasp.. what a crock...

    27. Re:Give it a rest by JordanH · · Score: 1
      • Slashdot is rapidly becoming useless with the constant derision it heaps on Microsoft. Let's have more computer news and stuff about FreeBSD and Linux and less "make fun of" news about Microsoft. As if Linux doesn't have it's problems. You might end up like Larry Ellison and his ridiculous "Unbreakable" claims.

        Of course, that's a problem with the Linux crowd. Feer of being, and being seen as, professional.

      Gee, that is an interesting perspective...

      Thanks Bill!

    28. Re:Give it a rest by the_verb · · Score: 1

      Sort of like people laughing very, very hard when /.ers say that Linux is easy to use?

      --the verb

    29. Re:Give it a rest by SirSlud · · Score: 2

      Sure. Nice try, but sure, I agree. I'll spare you the 'Linux is an OS, not a window manager and desktop' lecture, but given what KDE and Gnome have done for a *fraction* of the cost that MS and Apple did to develop their Window Managers and Desktops, I think its fairly obvious that there is significant room for improvement in driving down the costs of both those commercial OSes (of which, to note, the cost of OSX is embedded in the hardware, as the OS is 'free as in beer'). Not to pick at their usability and functionality, but once everything is installed and configured, the KDE and Gnomes stack up fairly well against Windows and OSX, for a microfraction of the cost.

      Anyhow, yes, if thats all you were looking for.

      --
      "Old man yells at systemd"
    30. Re:Give it a rest by theblackdeer · · Score: 1

      well, no shit. /. is all about hyping linux. of course its biased; that's been the plan all along. laugh at the funny posts, ignore the trolls, and get your hard, objective and unbiased news elsewhere.

    31. Re:Give it a rest by Verizon+Guy · · Score: 1

      Neither do I. Remember that huge gaping buffer overflow in BIND 9 (which ships in practically 1/2 of the major Linux distros). They never posted it. Phooey on them. "Propaganda by obscurity" if anything. Plus, anything posted/written by michael is questionable. Timothy is the only author I trust, really.

      --

      Aw, fuck it. Let's go bowling. - The Big Lebowski

    32. Re:Give it a rest by miffo.swe · · Score: 1
      So just because you use windows you cant complain? Is that in the EULA nowadays?

      I use linux and all the pretty gadgets and gizmo's but i also uses windows at work when im forced to. Does that forbid me to speak out against Microsoft? The reason most people on slashdot hates them is BECAUSE they use or have used Microsofts products. If the never touched windows then they shouldnt complain.

      --
      HTTP/1.1 400
    33. Re:Give it a rest by Anonymous Coward · · Score: 0


      Mod this guy up... Slashdot has become an absolute and utter embarrassment in this sense.

      And by the way, the Visual Studio.NET environment is about 1 million times more featured and powerful then anything in the open source world. Get a clue, shut the fuck up and get to work on anti-aliasing in XFree86 so you can catch up to where Microsoft and Apple were 7 years ago.

    34. Re:Give it a rest by darien · · Score: 2

      I don't think OS X is free as in beer. I think it costs $129, though it's bundled with every new Mac.

  31. They advertise on slashdot. by Anonymous Coward · · Score: 0

    Do we get a copy of nimda if we click through?

  32. The Cost of Outsourcing by Real+World+Stuff · · Score: 5, Insightful

    According to the Article, it appears that "Microsoft's flagship developer tools picked up the digital pest when a third-party company translated the program into Korean...".

    Ultimately it was MS's responsibility to verify they did not shit in their own bed, but how many of us look at every line of code in a distibuted or outsourced project.

    Just my $.0199999

    --
    If we don't fight for ourselves no one will.
    1. Re:The Cost of Outsourcing by coyote-san · · Score: 3, Insightful

      They can be expected to verify the ISO image.

      Do you think they approved the disc without verifying all libraries, resources, etc., were present and properly named? (Okay, this *is* Microsoft but work with me here)

      If we can expect them to perform that level of checking, why can't we expect them to run a virus checker at the same time?

      --
      For every complex problem there is an answer that is clear, simple, and wrong. -- H L Mencken
    2. Re:The Cost of Outsourcing by frank_adrian314159 · · Score: 2
      ...how many of us look at every line of code in a distibuted or outsourced project.

      Well, we at least install it and see if it works right. We do this on machines that have AV protection.

      Bottom line, ther is NO excuse for this type of FU. Whoever is in charge of MS's QA should be fired. Immediately.

      --
      That is all.
    3. Re:The Cost of Outsourcing by iramkumar · · Score: 1

      but how many of us look at every line of code in a distibuted or outsourced project

      * How many of us ship viruses with a state of the art costly development environment which will be used by thousands of developers ?

      *Does outsourcing absolve you from such things ? Are not open source products outsourced if you mean people from distributed geographical locations working on it ?

      * There are absolutely no excuses to this kind of fsck ups. Can't they just checksum stuff , keep a list of files somewhere. For someone who claims how secure their systems are , such a fsck up , eventhough it is not going to affect anyone goes to show how easy it is subvert closed software packages. I often wonder whether it will be possible to ship a Nimda/Klez with the Linux Kernel ?

    4. Re:The Cost of Outsourcing by Ubergrendle · · Score: 1

      "Ultimately it was MS's responsibility to verify they did not shit in their own bed, but how many of us look at every line of code in a distibuted or outsourced project."

      Although I agree that 100% quality control is probably an unrealistic target, if a company the size of Microsoft wielding the resources that it does cannot provide end-to-end QA, then who possibly can? If microsoft cannot provide confidence in its base products and OS, how can legions of loyal developers ensure the quality of the solutions they deliver and deploy ontop?

      --
      John Maynard Keynes: "When the facts change, I change my mind. What do you do?"
    5. Re:The Cost of Outsourcing by Anonymous Coward · · Score: 0
      Well, we at least install it and see if it works right. We do this on machines that have AV protection
      OK. It's passed that test - no viruses detected. Do you ship?

      What I am of course getting at is that you still wouldn't be sure (and looking at this story and the fact that it's a hidden-away file that's infected; one that might not be loaded in your test). When you release and pweople see your product, you can catch extra bugs - "many eyes", anyone?
    6. Re:The Cost of Outsourcing by Peyna · · Score: 2, Insightful

      * How many of us ship viruses with a state of the art costly development environment which will be used by thousands of developers ?

      Ford Motor Co. ships(ed) thousands of cars that when rear ended with the left turn signal on would explode killing people.

      Ford Motor Co. and Firestone shipped thousands of SUVs with faulty tires that would explode at high temperatures and rates of speed.

      Funny how these things keep happening over and over again? Nimda isn't going to cost lives is the big difference here.

      --
      What?
    7. Re:The Cost of Outsourcing by Anonymous Coward · · Score: 0

      This is a pathetic argument. Open source doesn't claim to be free of such things. You agree to it, and only then you install it. You don't pay for it, hence you overlook this.

    8. Re:The Cost of Outsourcing by yomahz · · Score: 2

      Ultimately it was MS's responsibility to verify they did not shit in their own bed, but how many of us look at every line of code in a distibuted or outsourced project.

      Well, you'd think they'd at least compare MD5 sums of the binaries they know didn't change. Besides being easy to do, it's just common sense.

      --
      "A mind is a terrible thing to taste."
  33. One string sums this up... by loply · · Score: 1

    Bwahahahahhahahahahahahahahahahaha! ROFL!

    Uhm. How do these twats still have an ounce of credibility? For god sake - that happens to high schools and newbies running Personal Web Server.

  34. Re:Accident? Sounds like criminal negligence! by piznut · · Score: 0

    "And if the worm did execute somehow, he said, it couldn't spread to the developer's system because the virus only runs on systems running Internet Explorer 5.5 and lower, and Visual Studio .Net requires version 6.0 of the browser. "

    and

    "There have been no recorded infections," Flores said. In fact, he added, it's almost impossible to get the worm to execute on computers with Visual Studio .Net installed. "

    Yer right, all zero of them.

  35. Re:What... the... hell.... by Anonymous Coward · · Score: 1, Interesting

    If you're in the software biz (and serious about it), you ALWAYS scan a new release with anti-virus software before you let it out the door.

    ALWAYS.

    It's easy, it's prudent and it keeps you from getting nasty PR.

    MS isn't the first to get caught this way (in fact, didn't this happen once before?) and it's cheap to learn from someone else's mistakes.

  36. Re:What... the... hell.... by Anonymous Coward · · Score: 1, Interesting


    Has anyone ever heard of the following:

    Secured Development environment?

    Anti-Virus Software??

    Don't they run A/V software on the development workstations and servers?

    At least an aggressive manual scan before packaging seems a good idea.

  37. Outsourced translators by Mundocani · · Score: 2, Insightful

    Aside from the Trustworthy Computing crap, what does this really say about the industry-wide practice of outsourcing product translations? Anybody who's done software development knows that even the best products give internationalization secondary consideration, but I don't think anybody ever considered how little consideration is given by US companies to the translation and distribution of international versions of software. Perhaps this should serve as a sort of larger wake-up call for all of us.

    1. Re:Outsourced translators by D0wnsp0ut · · Score: 1

      We outsourced the translation of a product to a company. They then created a marketing ad using us to drum up more business. They misspelled our name in the ad.

      [sigh]

      --
      "Those who would sacrifice liberty for security deserve neither!"
  38. Whoo hoo hooo! by Chanc_Gorkon · · Score: 2

    Mod the parent up.....score +5 Funny. I was the first to find this thing on our servers and I understand why we got.....Microsoft getting it is TOO funny!

    --

    Gorkman

  39. Speechless... by peterdaly · · Score: 1, Offtopic

    I have never seen so many one or two liner post after a slashdot article.

    This may be the first time Slashdot readers are left speechless.

    -Pete

  40. Re:What... the... hell.... by Anonymous Coward · · Score: 0

    what would YOU do if you were MS in this case?

    Hari-kari?

    But that's Japan, not Korea.. damn.

  41. That's One Degree of Separation! (tm) by elsegundo · · Score: 5, Funny


    Leave out the middleman when it comes to distibuting viruses! Give it straight to your customers!

    --


    The revolution will be televised. Blackout restrictions apply.
    1. Re:That's One Degree of Separation! (tm) by teamhasnoi · · Score: 2
      But is it Six Degrees to Kevin Bacon?

      (Just say the subject and message really fast and it gets funnier, I swear.)

    2. Re:That's One Degree of Separation! (tm) by HFXPro · · Score: 1

      Damn, I thought thats what .Net was. One big virus to make your machine run slower and allow people to right even crappier code. Hell all my friends have the .NET fever now. Whats more they redicule me cause I stick to my old trust C\C++, Java, PHP, Perl, Lisp, and SQL.

      --
      Reserved Word.
  42. MSFT control in S.Korea by Anonymous Coward · · Score: 0

    Could this be some cheap retaliation when MSFT lost the gov't contract to sell their OS and office instead won over by a S.Korean open sourced OS and office app?

  43. technically, it's not a virus by apankrat · · Score: 1

    it does not spread itself around **automatically** :)

    --
    3.243F6A8885A308D313
    1. Re:technically, it's not a virus by peddrenth · · Score: 2

      "it does not spread itself around automatically"

      Yeah it does. When you buy windows, you start emailing files to world+dog (colleagues) as microsoft word files, so for them to work at the same office as you, they all need to install windows too.

      And once your whole office is publishing IE-only websites with Powerpoint presentations on them, then anyone who wants to do business with you has to install windows too. The virus is already starting to spread.

      Eventually it reaches a government department, and they make laws saying all tax-filings need to be done electronically, then write a website that only reads MS digital cerificates. Then anyone who has to pay tax (i.e. everyone except the queen) needs to install Windows.

      Course it's a virus. Just because it relies on stupidity to spread doesn't mitigate anything -- loads of 'real' virii spread that way.

      "Warn all your friends - you MUST delete command.com which is a virus"
      "Warn all your friends - you MUST send your CV in .DOC format"

  44. Read the story by Anonymous Coward · · Score: 0

    I only you would bother to even read the story, it would be clear that 3rd party company who translated the software is behind this. Not Microsoft. But who cares though these glasses anyway.

  45. Re:Accident? Sounds like criminal negligence! by rohdem · · Score: 1

    Read the fucking article!! The chances of someone actually being infected are almost ZERO, because the virus needs IE 5.5 or lower and Visual Studio .NET requires IE 6!!

  46. In Other News by Target+Drone · · Score: 4, Funny
    Microsoft today announced it's new "Don't ask, Don't tell" security initiative. Microsoft is now requesting that customers no longer ask if there are any security holes in its software. It is also strongly urging all media outlets to stop telling people about any possible security issues.

    A spokes person from Microsoft was quoted as saying "This is the best chance we have at cleaning up our image."

  47. Repost: Is windows a virus by Lord_Slepnir · · Score: 1

    This is a repost of one of my comments from the MacAfee story. The quotes are from that story: ".... you have to have already been infected by ANOTHER virus..." "They only affect Microsoft Windows. If you aren't running Windows, you are safe. " This speaks for itself....

  48. Not the first time by errorinspelling · · Score: 1

    I do remember some 3-4 years ago Microsoft sending out a notification that some of their, I think, Technet CD's were being sent out with a MS-Word Macro virus on it.

  49. So.. is it any wonder by k98sven · · Score: 2

    ..that the Korean government is investing in linux systems?

    Or maybe this is just another sleazy MS retaliation tactic?
    The fact that it backfired might just be proof.

  50. Slamming MS by glh · · Score: 5, Informative

    OK, someone messed up.. but it isn't as bad as it sounds. First off, it wasn't MS that put the virus in, it was some third party thing they used to convert the language to Korean. However, MS should have at least run virus scan on it before they shipped it. Second, the person running VS.NET would actually have to install IE 5.5 over IE 6 (why would anyone do that) and browse a certain help file in order for it to get infected.

    I'm not trying to defend MS. Just pointing out the facts (or at least how they were stated in the article). On one hand it's kind of funny to read through all the quick one-liner jokes about MS (definitely worth a chuckle) but I think MS isn't quite as bad as they're being made out to be.

    By the way, anyone know the company that wrote the nimda infected software?

    1. Re:Slamming MS by GigsVT · · Score: 1, Funny

      actually have to install IE 5.5 over IE 6 (why would anyone do that) and browse a certain help file in order for it to get infected.

      It's this whole voodoo-superstition shit that makes me really hate Windows. "Apply service pack 23ase, reboot twice, pray to the sun gods, upgrade DirectX, and walk twice clockwise around the computer".

      Bullshit, total bullshit. Ask a Windows user which Windows kernel version they are running sometime, if you want an example.

      --
      I've had enough abrasive sigs. Kittens are cute and fuzzy.
    2. Re:Slamming MS by Beryllium+Sphere(tm) · · Score: 1

      >MS should have at least run virus scan on it before they shipped it

      At the risk of being pedantic, the article mentions that MS did run a virus scan.

      They ran a virus scan against every file in their release manifest.

      That doesn't work when a virus adds a new file instead of modifying an existing one. But it's an easy mistake to make.

    3. Re:Slamming MS by _xeno_ · · Score: 5, Informative
      Actually, according to the article at least, Microsoft did scan the files for viruses prior to shipping. However, they apparently have it set up to only scan files that they expect to be there, and therefore missed the added Nimba file. The way I read it, the Nimba file is not really part of the package and can never be accessed in normal usage of the product, and can only be accessed if the user goes looking through the actual help files that come with the system.

      Assuming that by "help files" they mean "VS.Net Documentation" then there are quite a few help files covering everything from JScript, VB, C#, C++, to the Windows Platform API, the C# class library, and more - which means it'd be practically impossible to manage to find the one Nimba file amoungst the croud. However, if they just mean tool help, then that content is a lot more limited, but I somehow doubt that is the case.

      I have to wonder how much about that "scan only files that should be there" is really spin doctoring, and if they didn't really scan the disk and are instead coming up with an excuse for having missed the presence of the file.

      Anyway, the Slashdot writeup is, as usual, way overblown in its anti-Microsoft slant. If they're going to write tirades about McAfee scaremongering, then they probably shouldn't do it themselves.

      (And, by the way, Michael is the author of both articles...)

      --
      You are in a maze of twisty little relative jumps, all alike.
    4. Re:Slamming MS by avandesande · · Score: 1

      This does however validate the fears of non-english speaking countries that they are getting 'second-best' from propriatary vendors, one of the reasons the Chinese goverment is switching to linux.

      --
      love is just extroverted narcissism
    5. Re:Slamming MS by dinivin · · Score: 2


      On the contrary, I think this is worse that it's made out to be...

      Since we know for a fact that they didn't scan for a virus before burning it to CD and shipping it, why the Hell should we assume they do that for any of their products?

      Dinivin

    6. Re:Slamming MS by MrResistor · · Score: 3, Informative

      It's actually even more difficult than that. The infected file isn't an actual help file, it's an extra file that's not even supposed to be there, and isn't linked or referenced anywhere in VS.NET. They'd have to install IE 5.5 over IE 6 and browse to the directory the help files are kept in and actively search for and open the infected file.

      Really, it's a close to harmless as you can get, considering the astronomical improbability of someone executing the infected file by accident. Of course, one should never underestimate the ingenuity of fools, so I have no doubt that it will happen.

      On the whole, I have to give MS credit for the way they are handling this. They are offering free clean replacements to everyone who has an infected copy, they have a patch out, and they are spreading the news so that people are informed and thus able to fix the problem. I'm a little curious about the "patch", but I suppose it's a more reliable solution than just telling people to delete the file.

      Yes, I am pointing and laughing at MS right now, I am typically an MS basher after all, but at the end of the day I have to say that I wish they would deal with more of their problems as honorably as they've dealt with this one. It would have been really easy for them to sweep this under the rug and pretend it never existed.

      --
      Under capitalism man exploits man. Under communism it's the other way around.
    7. Re:Slamming MS by SirSlud · · Score: 4, Insightful

      I dont think anyone is going to excuse this just because MS was lucky that the chamber wasn't actually loaded. The trigger went off, and thats all the ammo I need to demand someone revoke the gun license.

      As for outsourcing, this is absolutely ludicrous that companies neednt take accountability for the actions of their contractors. Thats how all the clothing manufacturers dodged the anti-sweatshop movement. Now Nike/Espirit/Adidas/Gap/Etc doesn't employ the sweatshop workers, they contract them! Brilliant, and insedious. While it may not be fair to compare that to the IT world, it shows the extreme consequences of allowing companies to divest accountability for services and products offered under their brand. If we dont hold MS accountable in the least, wheres the motivation for them to be more careful with their contractor selection skills? They will continue to select contracts based on politics and economics rather than on the quality of the service/product being outsourced.

      I realize that its not *entirely* their fault, but it doesn't help with the kind of facade MS puts on. Just like Oracle's "unbreakable" claim, if you want to make claims that simply are not true or that you cant deliver on (I dont care if its your fault or not, you made the claim), you're never *ever* going to get the benifit of the doubt in this kind of situation. If you wanna make claims you cant back up, you dont deserve the benifit of the doubt. :)

      --
      "Old man yells at systemd"
    8. Re:Slamming MS by slntnsnty · · Score: 1

      Yes and No.

      Yes it might not be that bad in this instance. Although it IS bad...

      However, it is poor coding, poor security, blatant negligience on MS's part that allows so many virus's to be distributed so easily.

      Hello Klez.

    9. Re:Slamming MS by dchamp · · Score: 1

      It's not as impossible as you might think. Say you're developing a project for a corporate standard where they're using IE 5.5, so you instal IE 5.5 to test it. Then you go look at the help files, click the infected one, and bang-o, you've triggered the virus.

      In a perfect (well, perfect for the MS arena anyway) world, that corp standard would be updated to IE 6.0, but it doesn't always work that way. Ask any web developer how many browsers they have on their system for testing purposes. I have Opera 6.x, IE 6, Mozilla 1.0, Netscape 4.x, and lynx... possibly a few others.

      -dc

    10. Re:Slamming MS by InnereNacht · · Score: 1

      Since you asked...

      Microsoft Windows XP [Version 5.1.2600]

      Cry for me.

    11. Re:Slamming MS by Anonymous Coward · · Score: 0

      Assuming that by "help files" they mean "VS.Net Documentation" then there are quite a few help files covering everything from JScript, VB, C#, C++, to the Windows Platform API, the C# class library, and more - which means it'd be practically impossible to manage to find the one Nimba file amoungst the croud.

      Well obviously somebody found it, otherwise we wouldn't know.

    12. Re:Slamming MS by Anonymous Coward · · Score: 0

      As we learn in The Hitchhikers Guide to the Galaxy... desingers of idiot proof technology often fail to take into account the ingenuity of an idiot. Just because it seems wierd to install ie 5.5 over 6.0 doesn't mean some idiot will never do it.

    13. Re:Slamming MS by _xeno_ · · Score: 1
      They (being Microsoft) found it when uploading the help files to MSDN. Since the help files need to be converted individually to the online format, the Microsoft employee uploading the files noticed an extra file at that point.

      In other words, it was practically impossible to find, until someone at Microsoft had to go individually through all the files to get them ready to be read through MSDN.

      This is according to the linked article -- please, read the articles, they're usually very informative :)

      --
      You are in a maze of twisty little relative jumps, all alike.
    14. Re:Slamming MS by Wraithlyn · · Score: 2

      'I have to wonder how much about that "scan only files that should be there" is really spin doctoring'

      That's exactly what I thought. Who the hell writes scanning software that instead of 'scan *', only scans stuff on a list? The very fact that there ARE extra file(s) should immediately set of warning lights to any validation procedure worth it's salt, unless it's coded by a band of retarded monkeys.

      Oh wait, we're talking about Microsoft, nevermind.

      --
      "Mind, as manifested by the capacity to make choices, is to some extent present in every electron." -Freeman Dyson
    15. Re:Slamming MS by Anonymous Coward · · Score: 0

      Ooh, build 2600. You better not upgrade to Service Pack 1 when it comes out.

    16. Re:Slamming MS by Anonymous Coward · · Score: 0

      >I dont think anyone is going to excuse this just
      >because MS was lucky that the chamber wasn't
      >actually loaded. The trigger went off, and thats
      >all the ammo I need to demand someone revoke the
      >gun license.

      I wish you were right, but what's actually going to happen is that managers in starched, monogrammed white shirts will continue to dictate their IT shops run MS, sometimes even getting a laugh out of all the issues that make us cringe.

      They *know* about the problems, and they still want to be a MS shop. On the days they aren't playing golf or hunting deer or whatever they do. Fortunately I haven't had to deal with it for a good while, but the image of a heavyset guy laughing about how big and dumb MS is, while insisting that everyone runs windows, is all too common. The trials, the bugs, the unworkable "solutions", the fact that there are superior alternatives, all this seems to make these morons even MORE insistent.

    17. Re:Slamming MS by Anonymous Coward · · Score: 0
      Yeah, this is how I set up my Corporate AV software. Only scan the files that should be there. Instead of checking off on the drives that I want it to scan, I use the little known file listing selection process to select which files to scan. This really is the only thing that makes sense, after all, if the file wasn't there last week, then it shouldn't be there now, right?

      I also only scan existing emails and preexisting attachments. Everything else should be fine.

      I am currently looking for work as a sys admin. Please reply with lucrative job offers and I will send you my resume.doc.

    18. Re:Slamming MS by Conare · · Score: 1

      the astronomical improbability of someone executing the infected file by accident

      What, you never double-clicked the wrong file by accident? If it was just that, I would disagree with you, but because they would have to revert to an earlier version AND execute a file they didn't mean to, you are probably right. Don't give MS too much credit though, someone would have found this eventually (scan all files on hard drive for virii) They are just acting this way so they can release it with their spin.

      If they tell people to just delete the file, how many do you think will double-click it instead of clicking it? I think that would seriously lower the "astronomical improbability".

      --
      Stop Continental Drift! Reunite Gondwanaland!
    19. Re:Slamming MS by Anonymous Coward · · Score: 0

      How do you think the shell translates *?

      It makes a list.

      Read up on your shell programming.

    20. Re:Slamming MS by jazmataz23 · · Score: 1

      The file in question never gets copied to the hard drive. I'm sure it would show up if you scanned the CD-ROM for virii.

      --
      Death to Argument by Slogan!! (This post twice-encrypted with ROT-13. Replies not using same will be ignored)
    21. Re:Slamming MS by bogie · · Score: 1

      "the person running VS.NET would actually have to install IE 5.5 over IE 6 (why would anyone do that) and browse a certain help file in order for it to get infected"

      IE 6 is still vulnerable to nimda. http://www.microsoft.com/technet/treeview/default. asp?url=/technet/security/topics/NimdaIE6.asp

      --
      If you wanna get rich, you know that payback is a bitch
    22. Re:Slamming MS by wadetemp · · Score: 2

      Sorry, the trigger goes off every time you ship software. There's nothing that keeps bad pointer, in any software, from running a codepath that deletes user files or is otherwise malicious to your current task or data. I'm sure plenty of bits in most software apps could do some damage... what's the difference between these bits and those bits, besides intent? What's more important is the probability that those bits will be executed. And in this case, it's basically zip.

      I realize this is quite a bit like the arguement for revoking the right to carry certain kinds of guns, but then again, I don't think anyone needs an AK47.

    23. Re:Slamming MS by spongman · · Score: 2

      why should a computer user possibly need to know the kernel version they're running (unless they're one of the ~1% of computer users that feed off that kind of stuff)? do you know the alloy composition of your screwdrivers?

    24. Re:Slamming MS by GigsVT · · Score: 1

      You don't upgrade screwdrivers.

      If an OS like Linux has a kernel flaw, you can say "well it's a kernel flaw in 2.4.15"

      If Windows has a kernel flaw, you have to do something like:

      "Well, Windows XP has a kernel flaw when IE 6.234 and Service Pack 23.531 and Office XP Version 2.542 is installed, but not if you installed critical update path OE-231 to fix vulernability CVE-23192."

      When you have random unrelated MS products applying kernel patches like crazy, and every IE patch and upgrade patching your kernel, version control is nearly impossible.

      MS is a unique example of how not to manage an OS. I don't know of any that are worse, except maybe Mac stuff.

      Why do you think there are so many Nimda infections still rolling around? People have no idea if they applied the right voodoo in the right order to get it fixed.

      --
      I've had enough abrasive sigs. Kittens are cute and fuzzy.
    25. Re:Slamming MS by spongman · · Score: 2

      what voodoo? all you have to do is go to windowsupdate.com and click on 'scan', 'review' & 'install'. or you can have the critical update wizard do it for you.

    26. Re:Slamming MS by GigsVT · · Score: 1

      Yes, it's always good to have blind faith in a corporation that has acted criminally multiple times in the past, with regards to consumer issues.

      --
      I've had enough abrasive sigs. Kittens are cute and fuzzy.
    27. Re:Slamming MS by spongman · · Score: 2

      and how exactly is this relevant to your argument?

    28. Re:Slamming MS by GigsVT · · Score: 1

      Well, without knowing the versions and what is going on, you are forced to blindly trust big brother to fix your computer, when something goes wrong.

      Yes, I know this debate is going nowhere fast. :)

      --
      I've had enough abrasive sigs. Kittens are cute and fuzzy.
    29. Re:Slamming MS by Anonymous Coward · · Score: 0

      One list is of expected files, the other a list of actual files. That's your difference.

  51. Easter Egg by elliotj · · Score: 2

    From the article:
    "It's extremely unlikely that a developer would ever accidentally get infected by Nimda," said Flores. "They would have to try hard just to run the worm."

    So I guess its more like an Easter Egg. I hope this isn't World Cup related.

  52. ...It's a feature by Anonymous Coward · · Score: 0

    Microsoft breaks new ground by bundling the virus instead of waiting to be infected by third party virii.

    Does the Justice Department know about this yet???

  53. Re:What... the... hell.... by Anonymous Coward · · Score: 0

    "And please, don't ask whether I know Glen from Canada"

    Although I'm sure they're really, really nice.

  54. Re:What... the... hell.... by Zordak · · Score: 3, Funny

    Have you ever been to Korea, you moron? Those people are absolute technophiles. They love all of the newest little electronic gadgets. They're not always the highest quality little gadgets, but everybody has them. Koreans are not aborigonees living in a wasteland. They live in big, crowded cities like most of us, except they're usually bigger (the Seoul/Inchon area alone has something obscene like 14 million people) and they have lots more concrete (if you had ever been to Korea, you would know what I am talking about). You need to leave your momma's basement a little more often.

    --

    Today's Sesame Street was brought to you by the number e.
  55. Just another reason to complain by DrPascal · · Score: 2, Insightful

    If you actually read the article, there are very valid reasons (albeit mistakes) that this happened, and the likelyhood of the virus actually running on the machine is next to none. The Help system wouldn't ever open it.

    But hey, this is Slashdot. Let's all miss the relevant parts of the article and just bash "M$"! Yay, fun.

    --
    DrPascal: Not the language, the mathematician.
    1. Re:Just another reason to complain by Jason+Earl · · Score: 5, Insightful

      You are missing the point. The problem isn't really that Microsoft is shipping a virus (although you have to admit that this is pretty darn funny). The problem is that Microsoft is shipping files that they don't know about. This file could have been anything.

      Microsoft has set up their business so that their customers have to trust them. There is no way for Microsoft's customers to verify that Microsoft software is safe. Yet time and time again Microsoft has shown that they simply are not particularly trustworthy. It has gotten so bad that it isn't just /. that is laughing at Microsoft. This particular story was published by CNET (which is a very Microsoft-friendly news source).

    2. Re:Just another reason to complain by Anonymous Coward · · Score: 0
      the likelyhood of the virus actually running on the machine is next to none.

      Certainly, Sir, let's just bury the virus within files and pray every night that someone doesn't ever find it and gets infected before I retire.

      If this is your conception of "trustworthy" and "secure" then we're definitely not from the same planet.
    3. Re:Just another reason to complain by stang · · Score: 2

      Microsoft has set up their business so that their customers have to trust them. There is no way for Microsoft's customers to verify that Microsoft software is safe.

      Umm, how about running a virus scanner?

      --
      "200 Quatloos on the newcomer!" "300 Quatloos against!"
    4. Re:Just another reason to complain by schon · · Score: 1

      If you actually read the article, there are very valid reasons ... that this happened

      Uhh, you're saying that there is a valid reason to ship a virus?

      And no, a mistake is not a valid reason.

    5. Re:Just another reason to complain by 1010011010 · · Score: 2

      The new "Trustworthy Computing" slogan: "Caveat Emptor"

      --
      Napster-to-go says "Fill and refill your compatible MP3 player", which is a lie. It's not MP3. It's WMA with DRM.
  56. Interestingly enough: by Ab0rtRetryFail · · Score: 1

    Microsoft's stock seems to have gone up on the news. I actually own stock in Microsoft (though only a half-share), but before you flame me, I'm not investing because I believe in the company, I'm investing because I think it's a good growth stock. I've hedged my portfolio with Sony, so its no big deal. Anyhoo: I just found it interesting that the stock has gone up about a dollar today. I guess most investors don't see this as much of a problem.

    1. Re:Interestingly enough: by Random+Feature · · Score: 3, Insightful

      It isn't a problem in the sense that it's going to cause damage, or infect anyone, but it is *damn* funny.

      And it is a PR nightmare for MS because a lot of people aren't technical enough to understand what's necessary to become infected. All they hear is "shipped with Nimda" and it's bad news.

      --
      I don't have a solution, but I certainly admire the problem.
  57. Maybe a re-brand? by rfsayre · · Score: 5, Funny

    Viral Studio .NET??

    1. Re:Maybe a re-brand? by krogoth · · Score: 2

      Like this?

      http://www.ubersoft.net/d/20020527.html

      Bet you can't guess what company is being parodied :)

      --

      They that quote Benjamin Franklin on liberty and safety deserve neither.
  58. If I were MS by Anonymous Coward · · Score: 0

    I'd say fuck it and watch soccer. GO KOREA!! Thanks for the assist!

    1. Re:If I were MS by Anonymous Coward · · Score: 0

      Korea should have kicked the US's collective asses. Our offense was extremely pathetic, and our defense, though rather good, couldn't stand up to such a vicious and continuous attack. We needed offense to win, but they didn't seem to get this.

      It didn't help that, whenever they played offensively, they were slapped with yellow cards. Meanwhile, Korea disembowels one of our guys, and the American gets yellow-carded for dripping entrails on the shoes of a Korean player. It wasn't a fair setup.

  59. slashdot morons strike again by Anonymous Coward · · Score: 0

    Hey jackasses,

    Did any of you bother to read the article?

    1: Visual Studio will *never* execute the file because it's unrelated to its operations. It's not a help file, it's simply in the help file directory.

    2: If someone went into the directory and executed this file themselves, it wouldn't do anything, because IE 6.0 needs to be installed to use it. Furthermore, IE 5.5 SP2 is also immune.

    This is certainly embarrassing for Microsoft, but the practical impact of this is absolutely insignificant and totally blown out of proportion by another tabloid Slanderdot headline.

    Way to go champs!

    1. Re:slashdot morons strike again by Anonymous Coward · · Score: 0

      er, seems I'm a jackass too. :p What I meant to say was:

      2: If someone went into the directory and executed this file themselves, it wouldn't do anything, because IE 6.0 needs to be installed to use Visual Studio .Net and is likely installed with it. Furthermore, IE 5.5 SP2 is also immune to Nimda.

    2. Re:slashdot morons strike again by grendel's+mom · · Score: 2, Insightful

      You should include yourself in the list of "slashdot morons" because YOU missed the point.

      This significant issue is that they only check the files they *expect* to be in their distribution.

      Before you ship code, you had better know *exactly* what you were shipping. What if the 3rd party localizers added a nice trojan program? It's *trivial* to execute code on a remote Windows machine. There are several exploitable holes to accomplish this.

      The included virus is trivial. Microsoft's shoddy QA is the problem. Unfortunately, this isn't only a MS issue. It's an industry wide problem. // End rant

    3. Re:slashdot morons strike again by Anonymous Coward · · Score: 0

      The POINT is that there was a virus found on the cd.
      jackass
      Now if there had been a picture of anna kournikova??

  60. This reminds me... by Visigothe · · Score: 1

    Of when the Native Americans were given pox-ridden blankets by the early settlers..

    Gee, thanks! [caugh, caugh]

    Or maybe it was to get back at Korea for the Speed Skating events during the winter olympics

    =)

    1. Re:This reminds me... by Anonymous Coward · · Score: 0

      Or maybe somebody at MS is getting spam from korean Open relays...

  61. DOJ Take Note by Paul+Lamere · · Score: 5, Funny

    This is just another example of Microsoft trying to bundle everything with windows. Now that they are bundling Nimda, Melissa is going to go right out of business.

    1. Re:DOJ Take Note by Anonymous Coward · · Score: 0

      Now if they would only start bundling Melinda they would put all wives out of business too.

  62. Couple that with .. by iramkumar · · Score: 1

    the McAfee virus story http://features.slashdot.org/article.pl?sid=02/06/ 14/1343223&mode=nested&tid=166&threshold=3
    and we got ourselves a real conspiracy theory :))

  63. expecting a virus? by BroadbandBradley · · Score: 2

    Flores said that under Microsoft's security policy, the company normally scans every file being transferred to the master of a program. But in this case, the company only analyzed files it expected to find. Since the Nimda-infected file had been added by the worm, the company overlooked it.

    I would think one might look for something that shouldn't be there when trying to detect a virus. I guess MS has some more "advanced" method that I just can't grasp.

  64. Re:What... the... hell.... by Anonymous Coward · · Score: 0

    Then why can't they understand the advanced concept of "open relay" or "security patch". Fuck em' and blackhole them until they learn.

  65. Life Imitates Art by Kozz · · Score: 5, Funny

    Truly, life indeed imitates art(satire). Microsoft Bundles Worm with IIS .

    --
    I only post comments when someone on the internet is wrong.
    1. Re:Life Imitates Art by travdaddy · · Score: 1

      I especially liked this part in the satire... strangely accurate:
      Security experts were unfazed by the whole affair. "If it's a Microsoft produced worm it won't work until the third version anyway. I'll get more worried then when Trojan Worm Virus 3.0 is released," said SecurityBreach.com's Lonnie Markow.

      --
      Adidas To Bring Back Sneakernet
    2. Re:Life Imitates Art by gregbaker · · Score: 2

      This by no stretch the first time MS has caused life to imitate satire. Remember setting anyone straight on the Good Times "virus"? "No," you said, "emails aren't programs, so such a thing is impossible." Then, they wrote Outlook.

  66. In the list of new features... by iabervon · · Score: 3, Funny
    • No longer vulnerable to this virus

    How would you know they'd fixed IE if they didn't distribute a virus that no longer worked?
  67. In other news..... by dr_db · · Score: 1

    ...a loud thunderclad was heard in the Redmond regions. Police suspect it was the sound of Mr. Gate's asshole slamming shut.

  68. I am suprised that this virus release... by CONTROL_ALT_F4 · · Score: 1

    Is not a prelude to Microsoft marketing a new anti-virus product. A mere $89.99 will buy you the software to get rid of the virus they handed you.
    Anyone remember DOS 6.22? It was the pay-for-bugfixes to the almost nonfunctionally screwed up DOS 6.0. Microsoft has done this before.
    I think that no snide comment of mine can truly do justice to this phenomenal screw of on Microsoft's part. But we can all try anyways!

  69. I know the answer to this problem by Anonymous Coward · · Score: 0

    42!

  70. Re:What... the... hell.... by Ooblek · · Score: 5, Informative
    You should have realized it was a joke - however lame it was.

    By the way, this is just another example of a premature attack by OS zealots. Just as the case of the cross-platform virus discussed previously, the Nimda file is installed as part of the help system, but is never loaded by the help system. As the tounge-in-cheek editorial posted by the illustrious Slashdot editors put it, "Only a complete moron would get infected by this virus." So unless someone in Korea is stupid enough to uninstall IE 6.0 (required for .Net to run), install IE 5.5, and then load the Nimda file, it is unlikely that they will get infected. For every MS goof, there is an equal goof in the OS community. (But we all know people that point that out get modded down....)

  71. Re:What... the... hell.... by rector · · Score: 1

    Normally reside3nt antivirus software checks only files you try to run. Just some file with a virus lying somewere in the deep directory structure would be fiound only during a massive check up. And even in this cas people almost never check any file whose extention doesn't correspon do ususal virus bearers like .exe or .doc

  72. heh by bilbobuggins · · Score: 1

    secret attacks on them there chiphead south koreans?
    well i'll be danged if that ain't the most downright American thing i've heard all week!
    </bush impersonation>

    1. Re:heh by Anonymous Coward · · Score: 0

      You know, the wonderful thing about holding a knee-jerk political ideology is that it relieves you of the need to think.

      Just post some generic catch-phrases and ad hominems and all the people on your side of the fence will think you're wonderfully witty.

      Works for Michael Moore AND Rush Limbaugh.

      Of course to everyone else you look like a complete fuckwit, but that's a small price to pay for being accepted by the other sheep, right?

      Baaa! Baaa!

  73. Re:Accident? Sounds like criminal negligence! by peddrenth · · Score: 1

    "This kind of recklessness by Microsoft is criminal negligence!"

    I think the phrase you're looking for is "disclaimed criminal negligence, supplied without warranty, nor claims of mercahantability or suitability for any particular purpose"

    If they'd been supplied in Maryland, Virginia, Alaska or Hawaii, then UCITA would have made it criminally negligent. But it wasn't, and it isn't.

  74. Microsoft by rice_burners_suck · · Score: 0, Troll

    Bwaaaaaaahaaaaaaahaaaaaaahaaaaahaaaahaaaahaahaha ha hahahah!!

    Microsoft. Where do you want to go today? Microsoft is a registered trademark of Microsoft Corporation. All other trademarks are the property of their respective owners. This virus is valuable intellectual property and is protected by copyright law and international treaty. Do not make illegal copies of this virus.

    FreeBSD rocks.

  75. Well... by Dark+Lord+Seth · · Score: 1

    ... at least now we know MS uses their own product, IIS.

  76. Re:Accident? Sounds like criminal negligence! by rector · · Score: 1

    Even in the States you hardly can sue if you can't prove any resulting financial losses. In this case you need to make a real effort to lose any money because of the virus.

  77. This is why slashdot sucks by Anonymous Coward · · Score: 0

    In typical lets bash MS fashion, slashdot doesn't even mention the most important part:
    ITS IMPOSSIBLE TO GET THE NIMDA FROM THIS PRODUCT

  78. Re:Accident? Sounds like criminal negligence! by chris_mahan · · Score: 1

    I'm not sure he's so offbase.

    If I shipped a coffee grinder to grandmas and included a grenade detonator mechanism in the package (by accident of course), but said that there's absolutely no chance of Grandma blowing herself up, I would still be in hot waters for sending grandma a piece of military hardware.

    Dontcha think?

    --

    "Piter, too, is dead."

  79. A Security Hole is still a Security Hole by Anonymous Coward · · Score: 1, Insightful

    A lot of posts seem to revolve around "Who cares, it's an inert virus; it could happen to any [multi-billion dollar corporation outsourcing its flagship development product that claims to be working to eliminate any end-user paranoia from its product line]..."

    But that's missing the point entirely. Seriously -- Nimda? What's that? People don't care about the statistics or logistics of the virus. No, people are concerned that a *known virus* was able to get into the code. Now ask yourself -- what if it was an unknown virus? What if a disgruntled contractor for the outsourced company snuck a new trojan horse in there? One that puts your MS Passport login info as a MIME header on whatever version of MSIE you're running?

    This is a PR disaster of incredible proportions because it shows how naked the emperor still is, despite hiring new tailors.

    Don't get me wrong, I make a lot of money off of writing Microsoft code. But the simple fact of the matter is that they're (supposed to be) going for "Trust" but their current habits are still hanging on "Hope".

  80. Cool! Virus Free! by Cheap+Imitation · · Score: 5, Funny
    Leave it to Microsoft to change the meaning of "Virus Free".

    Now, instead of meaning it ships with no viruses, it means they include them at no extra charge!

  81. It IS a bigger threat by rector · · Score: 1

    Open Source IS a bigger threaat. Imagine Microsoft distributing the virus with a well-commented source code!

  82. It may be fun to bash Microsoft . . . by Badgerman · · Score: 2, Insightful

    But a third party company screwed this baby up in transition, not M$. Using this as a "M$-is-so-evil/incompetent" story is pretty inappropriate.

    There's many, many other reasons to dislike Microsoft. Taking one out of context only strengthen's Microsoft's hand and makes those who oppose Microsoft look petty.

    --
    "The Sage treasures Unity and measures all things by it" - Lao Tzu
    1. Re:It may be fun to bash Microsoft . . . by anderiv · · Score: 1

      Not true...Microsoft's name is on the box, isn't it? So - they need to be held responsible for the contents, no matter if their programmers do the work or an outside contractor.

    2. Re:It may be fun to bash Microsoft . . . by Anonymous Coward · · Score: 0

      A lot of software companies hire out work to be done.
      The final responsibility rests on Microsofts shoulders.
      bash away.

  83. If you don't register we'll... by Joel+Ironstone · · Score: 1

    It also plans to send clean copies of the program to every registered customer free of charge and is attempting to contact developers who may have bought the product but not registered it.

    Its not our fault...he never sent us his personal information and registered his product. Oh well, he'll learn for next time.

  84. Is M$ getting into the AV Software business? by Stackis · · Score: 0, Troll
    I would suspect that Micro$hit is getting into the AV Software business...

    Thus releasing this article may help them sell their AV software...

    Anything stupid coming from Micro$hit anymore, does not surprise me...

    They suck and always will...

    --

    "Look where we worship" -- Jim Morrison
    1. Re:Is M$ getting into the AV Software business? by teamhasnoi · · Score: 2
      That's so crazy, it just might work!

      Either that or someone there has been watching too many episodes of 'The Mole".

    2. Re:Is M$ getting into the AV Software business? by Stackis · · Score: 1
      How dare you lable me a "troll"

      Anyone that makes shit out of M$ should be labled "vigilant"...

      --

      "Look where we worship" -- Jim Morrison
  85. Get with the program! by doomicon · · Score: 1

    Nimda is not a security fopah, rather a remote administration feature soon to replace terminal server. I am disgusted that a "News for Nerds" site, would not recognize such remarkable innovation!

    --

    Awesome!
  86. and yet... by imAck · · Score: 1

    And yet MS stock was still up $0.41 at last check. Even with the Nasdaq dropping.

    --

    It's hard to tell the cool to chill, my favorite hotel room has a view to an ill.

  87. Well spent month of Feb by hedley · · Score: 0, Troll


    Looks like that new development shutdown up there to clean stuff up and beef up security was really well spent.

  88. A different kind of experience by rector · · Score: 1

    And adds extra value to the software. This experience is very different from ejoying all those bugs.

  89. Re:Accident? Sounds like criminal negligence! by bobKali · · Score: 1

    Nah it's more like you hire Mailboxes etc to package your coffee grinder to grandma and they accidentally drop a grenade detonator mechanism in the package before shiping it off. Yea, you could've looked over their shoulders while they were packing but wouldn't the packers be liable for adding it than you?

    Oh, and I thought nimda attacked IIS also, so developers running that (and since I run apache while I'm developing, I'd immaging that'd be fairly common for a .NET developer) or am I mistaken?

  90. Well it's thier fault! by Moneky-Boy · · Score: 0, Troll

    That's what MS would say. Those slant-eye bastards could never do anything right. We, MS could never make such a mistake. Well unless we bet on the U.S beating Korea! ;-P

  91. book idea by Anonymous Coward · · Score: 0

    Someone should write a book called:
    101 reasons to not use Windows

  92. ..And in other news by jeremy+f · · Score: 2, Funny

    And in other news, an Pakistani foreign national was detained in New York City today for what officials are calling "a suspected case of viral bioterrorism". The man, Rumollea Abdula Jabala, 30, was reported to be "coughing and sneezing", and "blowing his nose" by onlookers, who promptly called officials to report the situation.

    Jabala, who came to America on a work Visa, denies official reports that he deliberately caught the flu to infect persons in the USA whom he would come in contact with.

    Jabala is currently being held in a city hospital, under armed guard, until officials can verify any terrorist links.

    1. Re:..And in other news by rector · · Score: 0, Offtopic

      If you kill one person, you are a criminal. If you kill 1,000,000 people, you are a hero.

  93. Re:Accident? Sounds like criminal negligence! by chris_mahan · · Score: 2, Insightful

    But MSFT did do a check of the "package" before they shipped it off. So they should have caught it.

    It's not that hard to say: scan all, including compressed files.

    --

    "Piter, too, is dead."

  94. Perspective by alacqua · · Score: 3, Funny

    They're worried about the viral nature of the GPL?

    --

    Move on. There's nothing to see here.
  95. only on slashdot by Anonymous Coward · · Score: 0

    is code considered funny. although i'm not entirely sure what program has nnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnn nnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnn nnnnnnnnnnHahahahahahah hahahahah hahhahahhaha heeheeeheeehee aaahahahhhhh in it

  96. Trust No One by bsd-mon · · Score: 2, Informative

    I wouldn't say that the Trustworthy initiatiave failed, but this will hopefully teach MS the number one lesson in security and viruslessness - trust no one. In the end, my email system is only as virus free as yours. If you are infected by Klez/nimda/... you still harass my bandwidth and my procmail filters. I'm just not dumb enough to run that .exe that h0t_ch1x@hotmail.com just sent me.

    Just because MS code and systems are "secure" and "virus-free", as soon as they hand the code off to someone else, the code is only as virus free as their system is.

    --
    To read makes our speaking English good. - X. Harris
  97. So what happens when they get rid of the PCs? by fallacy · · Score: 1

    Are the Koreans legally obliged to donate them *with* the Nimda since it would "go a long way to help an organization get that computer into use with minimal expended resources."

    It sure would help the receiver to get the computer into use: use into sending out viruses...

  98. Sneaky by JojoLinkyBob · · Score: 1

    That's a low-rent way on fighting software piracy!

    --
    -jc
  99. Re:It IS a bigger threat by Anonymous Coward · · Score: 0

    Open Source IS a bigger threaat. Imagine Microsoft distributing the virus with a well-commented source code!
    Your a joke get a brain!

  100. Re:Accident? Sounds like criminal negligence! by rjamestaylor · · Score: 2
    Why are people giving the contractor (MS) a free swing when their sub-contractor (translation co) makes a serious blunder that can, under certain conditions, result in a major security breech? Visual Studio.NET users didn't contract with the translator, MS did and MS respresented the product as their own. So, yeah, no one who gets a paycheck signed by BillG made the error, but the blame is squarely on MS' shoulders.

    "It's not our fault," claimed Blamer, er, Balmer, "it's the fault of the {temporary worker|sub-contractor|college intern} we hired."

    --
    -- @rjamestaylor on Ello
  101. Re: Nimba.NET by WillyElectrix · · Score: 1

    It wasn't Nimba but a JPG image of Nimba. Of course the virus only works after you log on using Passport.

    -W.

  102. Toasters Rule! by RAMMS+EIN · · Score: 1

    ``Microsoft distributed Nimda-infected copies of Visual Studio''

    So...what's new here? This is just another update to that well-known and widespread virus that turns computers into toaster ovens. http://www.xbill.org/
    and have fun! Sometimes it makes me wonder if this is a hint that we should all switch to Macs (http://netscape.digitallivingtoday.com/netscape/d igitallifestyles/gizmo/g4_cube/)

    --
    Please correct me if I got my facts wrong.
  103. Re:What... the... hell.... by jasonbw · · Score: 1

    It kind of makes you wonder exactly how much useless crap gets shipped. This was an older virus, so that's why this is so public; but how many stray files are just ignored? Isn't there some type of accounting procedure that should be run before you ship a package like that?

  104. Nimda-infected Visual Studio .NET by Darth+RadaR · · Score: 2
    http://msdn.microsoft.com/vstudio/productinfo/over view.asp

    And it will run on any platform too. :)

    --
    /*drunk.. fix later*/
  105. Re:What... the... hell.... by Anonymous Coward · · Score: 0

    Although I'm sure they're really, really nice.

    Actually Glen is dead.

  106. Windows without viruses... by Will+Collins · · Score: 1

    Windows without viruses? Ahhh, you mean linux

  107. shipping unknown files... by dpilot · · Score: 2

    Now all we need to do is find a way to slip a GPL-ed file onto a Microsoft CD the same way this virus got there.

    They could clearly argue that the file was NOT part of their distribution, and therefore the product does not have to have source released under the GPL. But I'll bet until they finally came to that conclusion, there'd be a TON of Brownian motion in Redmond on the part of execs and lawyers.

    So before someone actually does this, the need to let the alternative energy people know, so the heat source can be tapped.

    --
    The living have better things to do than to continue hating the dead.
    1. Re:shipping unknown files... by Anonymous Coward · · Score: 0

      They could clearly argue that the file was NOT part of their distribution, and therefore the product does not have to have source released under the GPL. But I'll bet until they finally came to that conclusion, there'd be a TON of Brownian motion in Redmond on the part of execs and lawyers. So before someone actually does this, the need to let the alternative energy people know, so the heat source can be tapped.

      Screw that, there'd be so much Brownian motion you could make your very own Infinite Improbability Drive.

  108. And in other news . . . by kalidasa · · Score: 2, Funny

    The latest release of Nimda has been infected with the Visual Studio.NET virus.

  109. Russian Roulet by Titusdot+Groan · · Score: 1
    Click. Oh, empty cylinder, I guess this game is safe after all.

    Just because it is almost impossible to trigger this virus and just because the guy who pulled the trigger is "only" a microsoft contractor is no reason NOT to be upset that MS once again played this game with their customers.

    This is NOT a no blood/no foul scenario!

  110. Re:What... the... hell.... by The+Turd+Report · · Score: 1
    Those people are absolute technophiles

    Why don't they close the open proxies that ever spammer and his dog is abusing, if they are so tech oriented?

  111. So we shouldn't talk about it? by dachshund · · Score: 1
    Anyway, the Slashdot writeup is, as usual, way overblown in its anti-Microsoft slant. If they're going to write tirades about McAfee scaremongering [slashdot.org], then they probably shouldn't do it themselves.

    Well, god forbid we should put too much pressure on the company that produces the vast majority of PC OSes. Particularly a company that has recently been bragging about it's new high-security policy.

    Are you actually suggesting that there's too much criticism of Microsoft's security practices in the world? A Slashdot 10 times as rabid couldn't begin to bring consumer concern to the levels it should be at.

    1. Re:So we shouldn't talk about it? by _xeno_ · · Score: 2
      There's a huge difference between there being a single Nimba infected file that is never used anywhere in the entire product, and the headline "Visual Studio .Net: Now with more Viruses". Not to mention that the hole the Nimba virus would be attacking becomes patched during the installation of Visual Studio .Net by the installation of Internet Explorer 6.

      Is it a problem? Yes. Is Microsoft doing something about it? Yes. In fact, Microsoft seems to be going out of their way to ensure that no one is harmed by it - giving clean copies to all the customers they are aware of.

      Michael is trying to make the situation seem much more dire than it really is. Yes, Microsoft managed to let a file infected with a virus into a version of one of their most important products. However, that product makes the system it installs on immune to the specific vector of infection that the infected file accidently included with the product.

      Just like Michael went after McAfee for claiming that the JPEG virus is a huge concern, he's claiming that the virus Microsoft included is a huge concern. It isn't.

      An appropriate headline might be "Korean Visual Studio .Net Ships With Nimba" and then mentioning in the story body that the infected file is not actually used by the system and should theoretically never be run, and even if it is run, can't infect the system with Visual Studio .Net installed anyway. The story body should most likely also mention that the virus was added by a third party contracter.

      The headline and story blurb seem to suggest that installing the Korean version of Visual Studio .Net will infect your computer with a virus, and that simply isn't the case. Yes, it still shows sloppy QA, but it can't really cause any actual damage, and that should be mentioned in the story.

      --
      You are in a maze of twisty little relative jumps, all alike.
    2. Re:So we shouldn't talk about it? by dachshund · · Score: 1
      Just like Michael went after McAfee for claiming that the JPEG virus is a huge concern, he's claiming that the virus Microsoft included is a huge concern. It isn't.

      Whether the virus actually poses a serious threat is incidental. What this incident demonstrates is that Microsoft has a poor process for examining work done by their contractors. This wasn't even a complex, difficult-to-diagnose code glitch: it was an entire additional file, which is to other kinds of fatal flaws as a mammoth is to a field mouse. What kind of security process runs a virus scan on only the files you expect to be there?

      If you have serious money riding on Microsoft products, it should scare the hell out of you. It's like buying a new wall safe, learning that criminals have infiltrated the organization and added backdoors to the locks, but thanks to a completely accidental redesign, they can't use them. Phew. Would you be inspired to purchase that companies products? And of course, that analogy doesn't begin to cover it, because hunting down those criminals is nothing compared to the sort of work required to guarantee secure, trustworthy software.

      This would be bad enough, but it comes on the heels of Microsoft's enormous marketing initiative for "Trustworthy Computing", which was intended to make customers feel that Microsoft is now committed to security in their products. If I were a major customer of Microsoft's, this incident would more than reverse any warm feelings I had toward the company's security policies since "Trustworthy Computing".

      Not to mention that the hole the Nimba virus would be attacking becomes patched during the installation of Visual Studio .Net by the installation of Internet Explorer 6.

      So if your doctor's office was accidentally spreading Hepatitis B to their patients, but-- fortunately-- was giving them Hepatitis B vaccinations at the same time, you'd feel comfortable doing business with that doctor in the future? What if next time it was something nastier?

      Microsoft is breathing a sigh of relief right now because they caught a lucky break. Period. The only evidence of competence here is the installation of a Nimda-patched version of IE, and that's only because Nimda is a pretty old-fashioned bug by industry standards.

  112. Wow... where's the money? by PierceLabs · · Score: 1

    Billions of dollars in the bank and not one copy of Microsoft Antivirus? :)

  113. So? AV Vendor? by Anonymous Coward · · Score: 0

    So, which AV vendor does M$ use?

  114. Re:Accident? Sounds like criminal negligence! by gmack · · Score: 2

    MS mastered the CD so they should have checked the contents before they did so. Odds are both parties here are at fault one for introducing it and the other for not finding it.

    It's just extremly funny and mostly harmless this time unfortunatly it's not the first time MS shipped a product with a virus.

  115. Re:What... the... hell.... by Zordak · · Score: 2
    You should have realized it was a joke

    I did realize it was a joke. I think, though, that before you make a joke at the expense of an entire culture that is proud, ancient and sensitive, you would do well to know that it has at least the smallest kernel of truth (for example, if you had made a joke about the disks getting copied all over the country, it would have been funny). Also, yes, I did the exact same thing by lumping you with the 31337 skr1p7 k1dd33z that live in their mothers' basements, when in fact I know nothing about you, and yes, I did it on purpose, and yes, I wrote my comment right off the cuff because I was irritated, and yes, the word "moron" was calculated to incite anger, so my comment should be properly be modded as flamebait. Still, though, I think the joke was about as fair and as funny as making a joke about how dispassionate Linux users are about their OS of choice.

    --

    Today's Sesame Street was brought to you by the number e.
  116. This was predicted weeks ago by drew_kime · · Score: 4, Interesting

    See here for details.

    --
    Nope, no sig
  117. Banner Ad by krulgar · · Score: 3, Funny

    When I read this article, the banner ad was for Microsoft Visual Studio .NET.

    It's that kind of policy that keeps me reading /.

  118. Guess . . . by Anonymous Coward · · Score: 0
    . . . the anti-virus people aren't that hysterical after all, are they, Michael?

    ~~~

  119. Just to be fair... by newerbob · · Score: 2, Informative
    ...about three times that I can remember software from APPLE came with viruses. And this was direct from APPLE not by way of a translation company.

    Microsoft's agent that put the virus in is the culprit here, and the risk, as news.com pointed out, is low.

    --

    --
    Ask the Ya-Hoot Oracle Anything!
  120. This is Obviosly sabotage - by X-Pirate · · Score: 0, Troll

    Stuff like this is bad for everyone. This was obviosly sabotage (just like most of their bugs) Flaming them just encourages more Gates-haters to do shît like this. I think most M$-haters would actually like M$ products if they didn't come from Microsoft. Most peoples' hatred is based on ignorance and brainwashing - like this artical does (if it comes from M$, it must be bad). I'de love for M$ to do a test, and secretly release some software (Open-spurce of course) without letting anyone know that it was developed by M$.

    1. Re:This is Obviosly sabotage - by talks_to_birds · · Score: 2
      Shoo, Micro$oft troll...

      t_t_b

      --
      I'm on PJ's "enemies" list! Are you?
    2. Re:This is Obviosly sabotage - by Anonymous Coward · · Score: 0

      I don't think it was intentional at all. stupid yes
      but not intentional.
      Gotta love that security through obscurity line.
      How does anybody REALLY know what is on the cd??

    3. Re:This is Obviosly sabotage - by Anonymous Coward · · Score: 0

      Shoo, Lamix Troll...

  121. Which one is the virus? by Koyaanisqatsi · · Score: 1

    Clear one point for me: which of the two pieces of software (vs.net and nimda) is the virus here?
    --
    sig is out enjoying the sun ;)

    1. Re:Which one is the virus? by Anonymous Coward · · Score: 0

      Heh, nice example, though jokingly, of how stupid 99 out of 100 /. readers are. You guys are your own worst enemy. Taking the path of greatest immaturity, there's something to be proud of.

  122. Re:What... the... hell.... by Anonymous Coward · · Score: 0

    Tech Oriented has nothing to do with Tech Savvy.

    It's just like here in North America. A lot of people have the latest, greatest DVD/VCD/CD-I/MP3 players at home. I'm sure several of 'em are 12:00 flashers, tho.

  123. Spellcheck! by Hershmire · · Score: 0, Troll

    More than one virus != viruses
    Virii, people, virii.

    --
    if(!toilet_paper) roll.replace(new roll); //Stupid roommates.
  124. Re:What... the... hell.... by Zordak · · Score: 1

    I didn't say they were particularly good at technology, just that they really like it.

    --

    Today's Sesame Street was brought to you by the number e.
  125. h0h0h0 h0h0h0 h0h0h0 by Anonymous Coward · · Score: 0

    h0h0h0 this h0h0h0 story h0h0h0 cracks h0h0h0 my h0h0h0 shit h0h0h0 up h0h0h0

  126. I really do know a Glen from Canada! by cnelzie · · Score: 2

    He used to work with me... Nice guy, except he had this funny way of saying "out and about"

    --
    If you ignore the other uses of a tool, does that make the tool less useful, or you less useful?
  127. Absolutely wrong by dachshund · · Score: 2
    But a third party company screwed this baby up in transition, not M$. Using this as a "M$-is-so-evil/incompetent" story is pretty inappropriate.

    If GM includes defective 3rd-party gas tanks and brake-pads in their vehicles, will you absolve them from blame? The sad thing was that this wasn't even a very subtle flaw. Microsoft could easily have found it with a slightly more robust virus checking process.

    "Trustworthy computing" means that your 3rd party suppliers are going to have to go through the wringer, too. Otherwise the phrase has no meaning, and there's nothing at all wrong with making this point.

    1. Re:Absolutely wrong by TheAwfulTruth · · Score: 1

      As a matter of fact, when Ford put defective Firestone tires on their Explorers, that's EXACTLY what happened. The person making the mistake IS the one to blame. It's become all to common to blame who you WANT to blame rather than who SHOULD be blamed tese days :(

      --
      Contrary to popular belief, coding is not all free blow-jobs and beer. Those things cost MONEY!
    2. Re:Absolutely wrong by dachshund · · Score: 1
      Ford got away with it because tires are generally considered to be an add-on, not part of the vehicle (and the company still got into a lot of trouble, and lost business. The name "Ford" lost a lot of safety cred thanks to this problem.) Let them put defective steel/aluminum members into a car, and see if the focus is on "Smithson Steelco, Inc.", or on Ford itself.

      Even better, let them run a standard set of tests on the vehicles (including crash tests) and still not pick up on a glaring flaw, and see who gets blamed.

      Anyway, the fact is that somebody needs to be pressured in order to stop things like this from happening in the future. If you let Microsoft off the hook on this, they have no incentive to take responsibility for work done by their outside contractors. Do you think that shifting the blame onto the virtually unknown contractor that made this mistake is going to make future mass-released Microsoft products more secure?

      So, to sum up, Microsoft really SHOULD be blamed. A world where Microsoft gets blamed is probably a better one for all involved (even Microsoft).

  128. Re:What... the... hell.... by The+Turd+Report · · Score: 1

    Except when they switch to daylight savings time, then they flash 11:00.

  129. Re:What... the... hell.... by Anonymous Coward · · Score: 0

    True. And everyone there has broadband. They are way ahead in that respect.

  130. Re:What... the... hell.... by The+Turd+Report · · Score: 1

    True. Anyone know how to say 'Shut your f-ing proxy' in Korean? (Or any asian language) I am on the virge of just nulling all of asia at the border routers and be done with the whole lot.

  131. Inconsistent or sloppy? by moocat2 · · Score: 3, Insightful

    So, Microsoft only scans the files they expect to be part of the install but they ship all the files anyway. While there is no way from the outside to prove or disprove this statement, I think it's odd they aren't consistent in which files they choose to scan and which they choose to ship. A decent process would use a consistent way to manage it.

    At a minimum, I find this an example of the sloppy techniques I see all over the industry. Of course, sloppiness is one of the reasons that all these viruses keep finding new ways to infect software so I think it's a pretty big slap in the face for MS's Trustworthy Computing program.

  132. No no no. by Anonymous Coward · · Score: 0

    Be grateful. It's soothing to know that now there's some code in .Net that actually works the way it's supposed to.

  133. Re:What... the... hell.... by Anonymous Coward · · Score: 0

    That was a joke? I didn't get it. Please explain.

  134. Re:Accident? Sounds like criminal negligence! by rjamestaylor · · Score: 1

    "Both parties" -- regardless the name on the business card, the product is labled "Microsoft" (or, in Korean, "Microsoft-shima"). When an agent of a company screws up, the company screws up.

    --
    -- @rjamestaylor on Ello
  135. Re:What... the... hell.... by chez69 · · Score: 0

    perhaps he should be the verizon really sucks guy.

    --
    PHP is the solution of choice for relaying mysql errors to web users.
  136. Just say NO to Microsoft by Anonymous Coward · · Score: 0

    It's similar to paying to have a surgery performed, doc does a lousy job (visual studio
    shcvisual studio,
    charges a ton of money, you have to come back
    and redo it in two years (upgrades you didn't ask for), it may leave you dead
    any day (didn't pay the .lib tax),
    but the icing on the cake is, you also
    got a virus for free.

    Excellent (in the voice of Monty Burns) Smithers. Excellent!

  137. IE 6 may still be vulnerable by bogie · · Score: 1

    Per Microsoft http://www.microsoft.com/technet/treeview/default. asp?url=/technet/security/topics/NimdaIE6.asp

    --
    If you wanna get rich, you know that payback is a bitch
  138. Comment removed by account_deleted · · Score: 2

    Comment removed based on user account deletion

  139. Re:What... the... hell.... by jjsoh · · Score: 1

    "Why don't they close the open proxies that ever spammer and his dog is abusing, if they are so tech oriented?"

    Speaking as a Korean, it's just because SPAM tastes so good! (I always keep a can handy in my cupboard for special occasions.) So, we like to share it with others around the world.

    Am I kidding about electronic SPAM? Yes. About being Korean? No. About SPAM the "meat".. hmm.. sort of. :)

    FIRST TIME REACHING 2nd ROUND IN WORLD CUP HISTORY!! GO KOREA!!

  140. Re:It IS a bigger threat by Anonymous Coward · · Score: 0

    show good commented GPL code moron!
    The windows kernel is documented and commented way better and more accurate than the linux kernel.

  141. how many of us by Anonymous Coward · · Score: 0

    Run $40 Billion a year software companies with monopolies on the desktop operating environment, have an self-acknowledge history of screwing up security, and a vested interest in ensuring that people begin to think of their products as secure and reliable?

    For their own good they should look at every line of code that goes out under their label.

  142. Nothing changes. by MisterBlister · · Score: 1

    All of this Slashdot rah rah Linux rulz Microsoft sux stuff reminds me of the (C64|Apple II) rulz, (C64|Apple II) sux arguments that 12 year olds used to have back in the day. Are you guys the same people, older but not any more grown up?

  143. Re:What... the... hell.... by festers · · Score: 2

    There are plenty of pro-Microsoft moderators around here these days, smartass, no need to cry about that.

    --


    -------
    "Every artist is a cannibal, every poet is a thief."
  144. Re:What... the... hell.... by einhverfr · · Score: 2

    Couple things to note:

    MS has a very good system of preventing viruses (used to be documented in a knowledge base article until someone realized that article said they used UNIX systems because they were impervious to Windows viruses).

    What probably happened is that a system was infected before the help files were compiled, and then once they were compiled (rendering the virus intert) the AV software did not pick it up. Once the masters are checksummed, then no one will notice because the subsequent copies have not been tampered with.

    Again, the virus is inert. But this is a HUGE publicity blow to Microsoft, so it is a BIG deal.

    --

    LedgerSMB: Open source Accounting/ERP
  145. Only an utter idiot.... by talks_to_birds · · Score: 2
    ...or a complete incompetent doesn't know that Nimda is still out there and probing, daily.

    I'm seeing 40-80 probes daily (heh.. intermixed with 40-80 MS SQL port 1433 probes daily), on my firewall at home on a goddam dialup, fer krissakes...

    How the hell can *any* company, or *any* subcontractor not be aware of this ongoing problem?

    How the hell can any company with any pretensions to "Trustworthy Computing" have let this happen?

    Make no mistake (Micro$oft apologists notwithstanding): there is absolutely no excuse for this unparalleled screw-up.

    Do these people really think they are so all-powerful as to be immune to this sort of thing, or do they think they are so all-powerful that they just don't need to care?

    t_t_b

    --
    I'm on PJ's "enemies" list! Are you?
  146. I've been hammered by these by WillSeattle · · Score: 0, Offtopic

    Some of my web pages have pacific keywords, so I've bounced more than my fair share of these to the FTC and other spam and abuse websites.

    Sigh.

    Friends don't let friends use Holey OS's.

    -

    --
    --- Will in Seattle - What are you doing to fight the War?
    1. Re:I've been hammered by these by talks_to_birds · · Score: 1, Offtopic
      • "Some of my web pages have pacific keywords, so I've bounced more than my fair share of these to the FTC and other spam and abuse websites."

      Excuse me? What?

      t_t_b

      --
      I'm on PJ's "enemies" list! Are you?
  147. Shut up or I'll send over a few japs to rape you by Anonymous Coward · · Score: 0

    Fuck you and your retarded, fucked up ancient culture.!!

  148. Re:What... the... hell.... by beerman2k · · Score: 1

    You obviously didn't read the article, you moron. They did run anti-virus software, just in brain dead fasion. According the article MS scans every file for viruses before they're shipped. Unfortunately, they only scan the files that are part of the product. The worm attached itself to a file it had created, so that file was never scanned. A stupid mistake, yes, but you really ought to learn the whole truth, before you go around bashing people.

  149. What was it AdTI was saying? by jpvlsmv · · Score: 2, Interesting

    Something about how Open Source software could have a virus on it?

    1. Re:What was it AdTI was saying? by 1010011010 · · Score: 2

      Wow, I hope the media pick up on that.

      "On the heels of a white paper alledging that Open Source software might include viruses, Microsoft has shipped the latest version of its proprietary software development environment with a virus. The irony meter is, by all accounts, pegged."

      --
      Napster-to-go says "Fill and refill your compatible MP3 player", which is a lie. It's not MP3. It's WMA with DRM.
  150. So here's the real question... by allism · · Score: 1

    if we assume that this guy/gal/armadillo/whatever that wrote Nimda would be forced to make financial reparations for the havoc it wreaked, would that amount be greater or less than what he/she/it could collect from Microsoft for suing for theft of intellectual property? It might make financial sense for the author to come forward now...

    I think instead of buying lottery tickets, I'm gonna start writing viruses and hoping that MS accidentally ships one...

  151. Re:What... the... hell.... by Anonymous Coward · · Score: 0
    "Only a complete moron would get infected by this virus."

    Like maybe someone who thinks that an MCSE is the epitome of fine computing?

    Awww, nevermind, MCSE has nothing more to do with computing than RTFM does...

  152. you're by Anonymous Coward · · Score: 0

    your != you're

  153. They always screw up by WildBeast · · Score: 3, Interesting

    Most of the time that MS uses a third-party company, that company screws up. My question is, who exactly is in charge of seeking out and contracting with those companies? Fire him big time.

  154. More Chambraigne quotes related to MS products: by brad.hill · · Score: 2

    BillG: "Microsoft Visual Studio .NET: Now with Securi-hancers!"

    Windows user: "Finally, a product for me! I believe every word that man just said, because it's exactly what I wanted to hear."

    Linux user: "Man, you've been brainwashed."

    News.com: "Microsoft developer tool distributed with viral payload."

    BillG: "He's making a mockery of the product! You're making a mockery of the product!"

    (Linux user): Noooo!! Can you not comprehend that your ignorance will cause me to explode now? Arrgghhh!!!

    BillG: "I AM THE KING!"

  155. Oh. C'MON! by rutledjw · · Score: 3
    So what? Does your point matter? MS distributed a virus with their code! Whether or not it runs, is this indicative of their source control?

    There is no way it can be stated that it's no big deal when this kind of thing happens. Period. The bottom line here is quality. If this kind of thing gets through, what else can get through? What kind of quality controls are really in place?

    Whatever controls ARE in place, apparently they aren't effective or aren't being followed...

    --

    Computer Science is Applied Philosophy
    1. Re:Oh. C'MON! by Anonymous Coward · · Score: 0

      well numb nucks
      appently this code was repackaged by a third party
      probably because MS does not have or does not have enough koren people with the skill to translate
      since this virus is non-functional I dont see the problem

    2. Re:Oh. C'MON! by Anonymous Coward · · Score: 0

      Irrelevent. Allowing something like this through in a software package that is supposed to be world-class (it costs enough that it should be, at least), is completely unacceptable.

  156. ok:) by Anonymous Coward · · Score: 0

    your write, thanks four pointing out that

  157. Re:What... the... hell.... by The+Turd+Report · · Score: 1

    Fried SPAM or grilled BBQ'd SPAM is pretty good, actually.

  158. At last... by hakkikt · · Score: 4, Funny

    ...M$ includes a really efficient piece of code with their compilers.

  159. Re:What... the... hell.... by TheBrownShow · · Score: 1
    Publicity blow?

    You know what they say, bad publicity is still publicity...and all us Linux Zealots are just fueling the fire.

  160. Re:What... the... hell.... by Zordak · · Score: 2

    What's even better than SPAM is the high-quality "Run-cheon mit'" (Luncheon meat). The bad romanization doesn't do the name justice, but that stuff was beyond interesting. That's why I always stayed away from imitation American foods in Korea. I much preferred good Korean stuff to bad American stuff -- except Duen Jang Chi Gae (again, sorry for the bad romanization). I never could get a taste for that stuff.

    --

    Today's Sesame Street was brought to you by the number e.
  161. Walah by aralin · · Score: 2

    'Walah' is spelled 'Voila' :)

    --
    If programs would be read like poetry, most programmers would be Vogons.
  162. Win is a Virus by Glanz · · Score: 0, Offtopic

    Well, considering that Windows itself is a virus, I am not surprised........ This is just one more thumbtack in the MS user's cell padding......

    --
    Rien n'est plus beau que le creux du 0.
  163. Re:Accident? Sounds like criminal negligence! by Anonymous Coward · · Score: 0

    Yup. I work for Allstate (hence the anonymous post), and some of you may recall the flap a few years back over people in California getting screwed. It actually wasn't anyone from Allstate, it was some contractors the company hired. However, our customers came after us. As they should have.

    We then proceeded to sue the contractors for screwing us.

    Same situation applies. Microsoft is responisible for shipping the product with a virus, but most likely will be able to collect damages from the contractor they hired.

  164. also by dachshund · · Score: 1
    The headline and story blurb seem to suggest that installing the Korean version of Visual Studio .Net will infect your computer with a virus, and that simply isn't the case. Yes, it still shows sloppy QA, but it can't really cause any actual damage, and that should be mentioned in the story.

    Hate to double-post, but, the blurb currently includes the following text:

    News.com just updated their story to point out that it probably won't infect the people who installed Visual Studio .Net, but it's still a rather nasty faux pas for a company that's supposed to be cleaning up its act.
    Looks like News.com is really to blame here. Since they're sort of a "third party" supplier, should we really hold Slashdot accountable for that website's mistake?
  165. You miss the point by Vicegrip · · Score: 2

    It's not not the potential affect of the virus. It's the fact that it's even there.

    "Only a complete moron would get infected by this virus."

    Yes sir, we know there's a bomb in your car, but don't worry: it's not wired to the engine so it can't hurt you.

    The fact that Microsoft could allow its flagship development tool to ship with such a notorious virus is absolutely incomprehensible and humiliating. If I were Balmer I'd be skinning alive those involved with a dull spoon.

    --
    Do not spread "09 F9 11 02 9D 74 E3 5B D8 41 56 C5 63 56 88 C0" over the internet, thank you.
  166. Of course.... by ManicGiraffe · · Score: 1

    Now any random fool that forgets to patch or upgrade or whatnot, and manages to pick up Nimbda, can claim they installed .NET and it's all M$'s fault, not their own stupidity.

    Microsoft: We screw up so you don't have to.

    1. Re:Of course.... by RazzleDazzle · · Score: 1

      Of course there have been patches available for these old ass holes for like a year or whatever now so if you don't have it patched you probably have more to worry about than nimda. You should also have anti-virus software, which should pick it up too. What the hell is the matter with people?

      --
      ZERO ZERO ONE ZERO ONE ZERO ONE ONE! Just brushing up for my next big invention: Ethernet over Voice (EoV)
  167. A **high-quality** worm by melquiades · · Score: 2

    They...um...made sure that it was a quality worm that went out the door.

    Well, have there been any security holes discovered in Nimda? Sounds to me like Microsoft is living up to their promises.

  168. Just Nuts by Hut-Moll · · Score: 1
    LOL,

    That just cracked me up. I go to slashdot see a .net ad running across the top.. and behold this article was nested in in there.

    I just loved seeing this ad splashed across /.

    Hut-Da-Moll

  169. Re:What... the... hell.... by isorox · · Score: 2

    For every MS goof, there is an equal goof in the OS community

    I dont pay members of the open source community $500 for a copy of their work. I do pay microsoft. I expect that $500 to buy me what is advertised.

  170. "take it like men"...? by Anonymous Coward · · Score: 0

    This implies that women wouldn't deal with the problem responsibly.

    Next time, please pick a metaphor without sexist connotations. You can get your point across without deriding those who aren't men.

    1. Re:"take it like men"...? by Anonymous Coward · · Score: 0

      Yeah! Sing it sister!

      Unless you're in prison or San Francisco, women take it much more often and with more skill than men do.

    2. Re:"take it like men"...? by Anonymous Coward · · Score: 0

      Next time, please pick a metaphor without sexist connotations.

      How is "take it like men" a metaphor?

    3. Re:"take it like men"...? by chris_mahan · · Score: 1

      I would reply with some wit, but since it's posted by an anonymous coward, I won't.

      --

      "Piter, too, is dead."

  171. Re:Accident? Sounds like criminal negligence! by Anonymous Coward · · Score: 0

    I know exactly how this happened...my (x) co-worker gave the virus to the vendor that made those CD's. It also went out to Dell, as well as other domestic suppliers.

  172. Re:Accident? Sounds like criminal negligence! by uncoveror · · Score: 1

    If you have any more details, please send them to secrets@uncoveror.com Sounds like a big story!

    --
    The Uncoveror: It's the real news.
  173. Re:Shut up or I'll send over a few japs to rape yo by jjsoh · · Score: 1

    .. ?

  174. HAHAHAHA by Anonymous Coward · · Score: 0

    Clippy jokes never get old! HAHAHAHAHA! Ow, my prostate.

  175. Actually... by sterno · · Score: 1

    It is the secret Microsoft revenge for the Koreans taking first place in their grouping in the World Cup. How dare they make the US look like a second rate soccer team, LAUNCH THE VIRUS!

    --
    This sig has been temporarily disconnected or is no longer in service
  176. Nimda... by jjsjeff · · Score: 2, Funny

    Now with improved networking support! :)

  177. Intentional? by Greyfox · · Score: 2
    Does anyone else think there was a conversation in Microsoft that went something like this:

    Ballmer: Damn! Some of those south asian countries have 94% piracy levels!
    Bill Borg: (Sarcastically) We may as well ship the virusses right on the installation media.

    Bill and Steve look at each other, light dawning

    Ballmer: Hey... YEAH!
    Bill Borg: Get southeast asia distribution on the phone!

    --

    I'm trying to teach myself to set people on fire with my mind... Is it hot in here?

  178. Re:What... the... hell.... by miffo.swe · · Score: 1
    The issue is the track record and that it seems that Trustworthy computing is a marketing gimmick. Do just as much as needed not to be laughed out of the industry but nothing more. To gain a reputation to be secure Microsoft has stop making those idiotic mistakes that seems to be a part of their corporate culture. I think they are getting to the point where the size of the company makes a 180' u-turn about security very hard to perform.

    Any company can make such a mistake but not many of them braggs about there "superior" products and has an illegally obtanied monopoly.

    --
    HTTP/1.1 400
  179. Re:What... the... hell.... by miffo.swe · · Score: 1

    Duh? The first time after youve installed the antivirus program you scan every and all files on the machine. Anything being copied or opened will be scanned for viruses so a virus shouldnt be able to lie unfound unless a. the virus is new b. the person installing didnt scan after install. Most AV programs scan the whole disk periodically by default also.

    --
    HTTP/1.1 400
  180. MS was due. by mj01nir · · Score: 2

    Not only has MS done this before, they've done it several times before.

    I'm just amazed that it doesn't happen more often.

    --
    the no .sig .sig
  181. Perhaps it's intentional... by Junior+J.+Junior+III · · Score: 2

    That'll show those lousy Koreans to pirate MSFT software!

    How much you want to bet M$ offers to release "guaranteed" virus-free software in the future provided that Korea cracks down on software piracy?

    --
    You see? You see? Your stupid minds! Stupid! Stupid!
  182. Re:Shut up or I'll send over a few japs to rape yo by DavidTC · · Score: 1
    .. ?

    Holy crap! Not only is that displaying right, but I can cut and paste it!

    --
    If corporations are people, aren't stockholders guilty of slavery?
  183. New Section Suggestion... by norweigiantroll · · Score: 0

    microsoftholes.slashdot.org

  184. And remember... by myov · · Score: 1

    Microsoft is paying *extra* attention to security now!

    --
    I use Macs to up my productivity, so up yours Microsoft!
    1. Re:And remember... by getter_85 · · Score: 0

      no, no, don't you see? this little slip-up isn't going to make a lick of difference. It seems that M$ has got desensitized to the M$-fuck-ups appearing on /.

      --
      return 0;
      }
  185. Not Code Red? by Nishi-no-wan · · Score: 1
    Are they not bundling Code Red? Snort has been reporting a lot of NNNNNNNNNNNNNNNN's recently:
    • $ grep NNNNNNNNN httpd-access.log | wc
      88 1056 41562
    First record: 05/May/2002:21:57:58.

    I've been fortunate in that none have been on the same B or C class subnet. Naturally, I've notified the two infected ISPs on the same A class subnet before either attacked twice.

    Still, how is it that this thing has resurfaced? Don't these things ever die? Is Microsoft secretly including it in other packages?

  186. Java by Anonymous Coward · · Score: 0

    If they only had used Java, all the koreans could change are simple properties files. :-)

  187. I know what to say... by wessman · · Score: 1

    Somebody is getting fired!!!

  188. Re:It IS a bigger threat by rector · · Score: 1

    I haven't seen the code of the Windows kernel. However, do you need really good comments (or even any) to figure out how a few lines of the virus code work? By the way, there are commercial programs with GPL'ed code like Metadot or MySQL. And they appear to heve pretty well commented code. This might become the case for Microsoft as well.

  189. Why it slipped through by goodchef · · Score: 1
    "It wasn't until a Microsoft employee was adding the help documentation to the software giant's developer Web site that the worm was found. 'We have to go through a conversion process to an online HTML format,' said Flores."

    No wonder Nimda slipped through. They're spending all their time manually converting to HTML.

    However, in Microsoft's defense, it should be noted that most other developers only convert the help files they expect to find.

    --

    "Inflammable means flammable? What a strange country!" -Dr. Nick, The Simpsons

  190. Re:What... the... hell.... by Buck2 · · Score: 1

    Can you believe I lost a point for this?

    lost a point lost a point lost a point

    la la la

    --

    As my father lik@(munch munch)... ....