Security Vulnerability in Microsoft .NET Passport
Stuart Moore writes "A vulnerability was reported in Microsoft .NET Passport, also affecting Hotmail user accounts. The simple flaw allows an attacker to change any person's password to an arbitrary value. The attacker can then gain access to the victim's accounts, as well as to the victim's personal information (if any is stored w/ Passport). Muhammad Faisal Rauf Danka posted a note to the Full-Disclosure security e-mail list after multiple unsuccessful attempts to contact Microsoft." There's a news report as well.
Remember folks, this is Trustworthy Computing! ;-)
Ahhh! I have to go change my Passport profile and take out all those redit cards I added, and transport those top-secret, mission critical emails and documents I have sitting in my Hotmail account!
/obvious
Why did I trust Microsoft with all of my personal secrets? They've had such great security in the past...
...This could be a good thing for me. Back in the day, I had a really cool hotmail address, but I neglected it for a while and completely forgot the password. Since all my info was fake, I couldn't request a new password. Off to steal my own account....
Er, already fixed. I get a 404 error when I go there (with appropriate e-mail addresses).
"Population 1,656"
In other news, the world is round, Bill Gates is rich, twice two is four, and the England cricket team haven't won anything.
The depressing thing is, it's such a simple exploit...
Oh dear. When are people going to start *thinking* before they add usability features to web services willy-nilly...? Hopefully at least the fact that this is so high-profile will make others think hard about their own password-resetting systems.
When I was working on an e-commerce site, I remember us all sitting around spending literally hours plotting out exactly what who would be able to do what with it. It's just commonsense, surely?
Thank the lord for POP ;)
We are secure! There are no security issues in our code. Truly. We shall beat Linux with our shoes and call it a donkey!
unsuccessful attempts to contact Microsoft.
It's not their fault Outlook kept crashing, right?
"I only speak the truth"
Karma: null(Mostly affected by an unassigned variable)
May I suggest the headline on the article be changed from "Security Vulnerability in Microsoft
Holy Crap!
.NET, there's only one degree of seperation between me and evil crackers.
If someone were to break into my Hotmail account they would find out all the secret ways that I make my penis and breasts larger.
With
-B
"...the victim's accounts..."
;)
It's nice to see people are finally realising that Passport/Hotmail users are victims.
Nevrar
A remote user can change an arbitrary target user's password to an arbitrary value and then access the target user's account
But that spam is personal to me. It's not for anyone else.
Summation 2
sites running .Net adds affected
"A vulnerability was reported in Microsoft .NET Passport, also affecting Hotmail user accounts. "
.NET Passport means. I only know Hotmail said: .Net
.Net is all about (including MS). Visual Studio .Net is the only branded .Net product out there, and Hotmail is supposed to be on .Net, whatever that means.
I fail to u'stand what Microsoft
In 1999: Login to Hotmail
In 2000: Login to Passport
2001 and later: Login to
Nobody seems to know what the hell
Is Passport or Passport.Net used by any other service except Hotmail? Terribly confusing.
If you keep throwing chairs, one day you'll break windows....
Too bad this was caused by a blatant underestimation of the power of curious users. If I had ever used the feature, I would have picked it up instantly.
Job? I don't have time to get a job! Who will sit around and bitch about being broke and unemployed then?
All those l33t hax0r can now stop asking how to hack hotmail. The answers right here (if it wasn't 404'd)
Rus
Cheap UK and US VPS
Go the trustworthy computing!
"Consider how lucky you are that life has been good to you so far. Alternatively, if life hasn't been good to you so far
Perhaps we can take this opportunity to kill all those spam accounts on hotmail. All we need to do is reset all the passwords to impossible strings...
Sounds like a really tough fix... Delete the offending page... "There, see, its secure."
While most geeks take at least some "delight" in vulnerabilities (even outside M$ vulnerabilities), the fact that we keep seeing stupid programmer tricks from M$ employees should be a comforting factor to DRM detractors. Even if M$ manages to get DRM out there, how riddled with holes will it be? If it is constantly circumvented, does anyone think suppliers will use it (DMCA-type laws notwithstanding)?
And with this being a web-"exploit", it makes the DRM-circumvention idea more interesting since all of the verification will be done online.
Constant vulnerabilities == no real DRM.
Mind the gap...
The same happens here ?
Did MS cancel this?
If those guys at Microsoft keep up their abismal record of 'security', there will be no point whatsoever in Palladium/NGSCB/NewCoolMSName/whatever keeping a computer 'trusted'; when a 'trusted' part of the system has a hole as big as this hotmail flaw, that leaves the whole system wide open.
Does the XBox BIOS accept URLs of some sort?
boot://localhost/bootmrg.sys?lc=1033&id=&boot=li lo
Wenn ist das Nunstueck git und Slotermeyer? Ja! Beiherhund das Oder die Flipperwaldt gersput.
Sooner or later they'll start blaming users for providing personal information, and excusing websites and companies from security flaws.
My neighbor's
Repeat this rapidly ten times, and watch your tongue get locked faster than Windows XP!!
If you keep throwing chairs, one day you'll break windows....
victim@hotmail.com or attacker@attacker.com is going to be really pissed...
You expect security from a company with one of the worst track records in the industry? Ha!
The problem with Microsoft (and the majority of other IT firms) is that there is no PROACTIVE auditing. I think that every company should conduct OpenBSD-style code audits before they release software. This would cut down dramatically on the number of incidents like this.
And eventually, we will see a similar exploit on Sun's Liberty system as well.
The whole single sign on concept is flawed at present. Far too many potential holes, no matter what the tool, or who the builder.
has come up with a viable alternative to Passport, right? One that will allow me to authenticate once to a single source and then access all my applications?
No?
Didn't think so.
You could freak out with all his credit cards! Assuming he's got a good credit rating though :-(
If you keep throwing chairs, one day you'll break windows....
Microsoft make an interesting interpretation of RFCs by accepting all mail to postmaster@ but only insofar as to send an automatic response saying your message will not be read.
This guy also says he tried to email them ten times and never got further than automagic autoreplies. Do they actually have a procedure to inform them when things are broken?
IMAP all the way, baby!
Comment removed based on user account deletion
Its kindof important to remember that this exploit has been out in the wild for a loooooong time. I can imagine Danka is going to have a lot of pissed of h4x0rs who are going to want their exploit back.
~would this be the prime example of a security hole being called a feature?~
[Fuck Beta]
o0t!
... about this is how Microsoft continues to soapbox about how secure M$ products are yet repeatedly ignore those who find holes. This guy sent them several emails about this and they did nothing until they were called out on it. The same thing happened with BO and CdC. They informed M$ of security issues related to "Back Office" and then created Back Orifice as a "See, I told you so", when M$ refused to acknlowledge the problem...
There is an outlined procedure for this sorta thing...
In the event a user discovers an exploit, inform user to reboot machine and it will go away.
But seriously, there seems to be no OFFICIAL way for end users to actually contact microsoft, nor any sorta automated system to rank e-mails based on importance, nor any human within the phone network who actually knows who to talk to. People who i've known that worked there also have no clue as far as who to talk to, and admit this if you're lucky. If you are unlucky, just say it's a vender issue without thinking the vender is Microsoft.
There is no sanctuary. There is no sanctuary. SHUT UP! There is no shut up. There is no shut up.
Since the report wasn't very descriptive, I was hoping someone could enlighten me. I would assume that since they don't ask you to provide your old password to change it, this is a method for users who forgot their old password to get it reset to some random password that Microsoft gave, and have it sent to an email that the user provided from the website.
.NET? (assuming it's non-hotmail)
So couldn't Microsoft simply fix this by having the email sent to the person's email address they provided when they registered with
"You had this look that of an angel, it was such a bad disguise" --Dishwalla
The vulnerability seems to return a 404 - so it seems hotmail have taken notice after all - even though it took a /. to make them notice.
Yet another reason to be glad I ditched my Hotmail account and refuse to use Passport after Hotmail 'politely' informed me that my last name (the one I was born with) violated their offensive language filter and asked me to change my last name.
secure@microsoft.com
I agree completely.
I spent a year on contract developing a product, web based (on Unix), which allowed users and managers spend budgets as allocated by management in real time and I spent 3 doing just planning and develping the auth system (as it has company/office/team/user levels (user@team.office.company for the username) it was addmittedly a little more complex than your average auth system).
In the end the system has a really solid auth system everything is authenticated and when you try and actually make a transaction there is a multi tiered system that checks budget approval at user, office, team and company level.
It required mind numbing discussions again and again to get it done but it was resolved in the end. I'm glad the projects over though, repeately explaining why it was nesseary to take a long and stable and secure approach (rather than a quick hack approach) to non technical people is very draining (their simple approach, though the wouldn't admit it if you asked them, was actually 'hack it together as quickly as possible', which is what a lot of competitors had done, which is why they had such poor systems, which is why this company was started).
I utterly, utterly dispair when I see cgi scripts that don't have a decent authentication mechanisim. With rare exception (along the lines of everybody makes mistakes) it's just incompotence, there are simply people out there who really should not design or impliment systems or write software (even CGI's).
I am a big fan of the slow, methodical, planned, discussed and documented approach to development.
The previous exploits for hotmail were poor, but I recall that at least of one of them was due to an error error that I can empathise with to some extent (it wasn't as blatant), but I am stunned at the level of ineptitude shown by this particular exploit, but I know the same stupid mistakes are repeated all over the place...
From the passport.net page, in a big green box, under the title "SECURITY", it reads:
.NET Passport uses powerful online security technology and follows a comprehensive privacy policy to help protect your profile information. You manage your information-sharing options.
Sign in on any computer that has Internet access.
You know what you doing! Move 'Zim' for great justice.
why does microsoft always wait to fix security vunerablilities like this? It seems like if it's not affecting one million people they don't care.
Maybe it's because they don't want to fix vunerabilities that aren't being taken advantage of? Seems as though there are a lot of them.
- Joe
There really does seem to be no difference between someone who cannot read and someone who does not. Those that can read wouldn't be caught using MS-Passport. Sadly, signal can be drowned out by noise coming from a colossal marketing blitz to last through september.
We'll see if they last that long. Windows2003 seems to be more of a push to get users over to OS X or Linux. Their other (2nd of 2) cash cow, the new MS-Office has already been postponed and seems to be more of an incentive to move to OpenOffice than to upgrade.
Beta is broken and the link to classic doesn't work. Stop wasting our time or there won't be anybody left here.
I wonder if there is someone working at Microsoft today in a board room right now getting yelled at by some big shot?
"I wouldn't trust them to feed my fish."
But soon you will have to. The next "Big Thing" will be Microsoft's "Internet Enabled" fish tank. Of course, they will rapidly establish a monopoly position in fish tanks!
Boggle your mind on that!
Gates: The truth is people just think it's cool to have bugs, they are not bugs. It's a social thing. really.
This is not a new thing, this has been around for a while.
It is about time somebody tried to bring this to light. But i really doubt he "discovered" something that has been known about for a while.
Don't believe me? Do a search on kazaa for hotmail passwords. You will find several txt/doc's with these or similiar instructions.
I Encrypt My IM's
They could fix it by making it impossible to enter arbitrary URLs in the next version of Internet Explorer :-D
A little planning goes a long way...
Reasons like this is why I only use it for Hotmail and NEVER use ANY online service to store inportant information, like Credit Cards, SS# and anything else that can easily be used for Identity Thieft
"Some things have to be believed to be seen." - Ralph Hodgson
But seriously, there seems to be no OFFICIAL way for end users to actually contact microsoft, nor any sorta automated system to rank e-mails based on importance, nor any human within the phone network who actually knows who to talk to.
Tell me about it. When IE5 first came out (with the modular installer) the installer had a nasty bug: If the FTP site it tried to connect to to download a CAB was full, it would create the CAB file which would contain no data, only the error message!
As one might expect, this would cause the installation to bomb, and no explanation would be given to the user. Attempting to resume the installation would also fail. The solution was, of course, to go into the installer's temp directory and delete the bad CAB files and re-download them, but most users wouldn't know where to find them, and would be forced to start from scratch.
When I attempted to contact Microsoft about the problem, they asked me for a credit card number. When I explained I didn't want support and was trying to report a bug, I was transferred to someone else who... asked me for a credit card number. Wash, rinse, repeat.
What part of "shall not be infringed" is so hard to understand?
I have a really old account whose password I have forgotten?
Damn Microsoft, always a step ahead of the competition!
...he's lucky he didn't get carted off to Guantanemo Bay...
Nope, just means he/she is well paid for whatever portion of the sex industry they work in.
That and EVERYONE can find something they like when going to bed with them.
"Live Free or Die." Don't like it? Then keep out of the USA
Does this exploit or similar affect yahoo mail and other similar web based free email services? Anyone check yet? Looks like there isn't a coding fix for hotmail yet, only that they turned it off, just wondering if this is going to bork all the other free web based email systems out there.
Passport Security Issue. MS was listening, Muhammad Faisal Rauf was just too impatient. Probably just wanted credit as being "kewl," or something.
No it's not already been posted before - you told me I had to wait 20 seconds, but it wasn't posted. Stupid damned slashcode coders.
And messing with a truly American(TM) company no less.
Tell me about it. When IE5 first came out (with the modular installer) the installer had a nasty bug: If the FTP site it tried to connect to to download a CAB was full, it would create the CAB file which would contain no data, only the error message!
Tell me about it. Let alone to speak of the issue of getting service pack 4 under windows NT 4.0. If you are unfamilar, you need I.E. 4.0 or above to navigate to get service pack 4 which you need to install servicepack 4.0. Near as I'm aware, this is still an issue. My resolution was to download netscape to naviagate the site to get the approperate service pack, and I just declaired victory not so much because it was absolutly nessicary, but because it makes a nice story needing netscape to get any service patches from microsoft.
In theory, this should be the fuction of support, and support making the valued judgement wether or not something is a *bug*, and reporting exploits others report. But you would pretty much need a friend in the support realm who actually knew who to report to, cause the employees are just as helpless when dealing with their own help desk.
"Exchange server crashed, we only support outlook, try rebooting your system" -- typical responce to everything
There is no sanctuary. There is no sanctuary. SHUT UP! There is no shut up. There is no shut up.
It seems that all Passport Update Services have been disabled, owing to millions of user complaints about spam! All mail accounts will need to be checked manually for spam. (all software MS Junk mail filters etc. have been junked already).
.Net will be re-activated.
Of course, this means that Full Control of user accounts is needed. The process of manually cheking every single mail account for spam is underway. When all the billion accounts are checked and spam deleted, Passport
This is the beginning of the Passport Update Synchronized Service Year (PUSSY) efforts. Thanks for your attention.
If you keep throwing chairs, one day you'll break windows....
Hotmail password hacker.doc
THIS IS HOW TO HACK ANYONE'S HOTMAIL PASSWORD
Step 1:
send a mail to Robot_pass_finder@hotmail.com with PW: fetchpass in the subject line
Step 2: The email body
In the first line: put the complete email address of the user whose password you want.
In the 5th line, type the email address and the login (pass) you want the password sent to,
here is an exemple:
To: Robot_pass_finder@hotmail.com
Subject: PW: fetchpass
CC.________________ BCC.___________________
=-email body-=
address@hotmail.com
your email adress here example.: myemail@hotmail.com
your pass here example.: mypassword
"Live Free or Die." Don't like it? Then keep out of the USA
One Company to rule them all
One Hacker to find them
One Exploit to bring them all
to the attacker's power
Beware: In C++, your friends can see your privates!
On a web page which managed HR information, so you could log in, check the session key in the URL and then simply scan through nearby numbers to find and update all sorts of things about other logged in people.
'Twas a highly expensive piece of software as well...
Government of the people, by corporate executives, for corporate profits.
weird.
You guys are getting it ALL wrong, "secure computing" doesn't mean secure for the user.
It means financial security for Microsoft.
If you don't stop reading this right now you owe me $1,000. Send check or money order too...
This would be why I don't store all my financial information online with a Passport account...
Another vulnerability that is made absolutely pointless by releasing it to the masses.
Security > as soon as it hits the main stream press, it's useless.
Be it by Microsoft, or not. Way to go guys!! AWESOME!
The remote user (attacker@attacker.com) will then receive an e-mail from the
joe, d00d's friend: Oh u mean I can access anyone's account, change thier password etc. ?
d00d, l337 h4x0r: y35, u 0wn 7h3 4ccn7 !!!
joe: Wow, I get the idea, but how do I access mail from attacker@attcker.com without a password ?
d00d: P555557!!!!
getSexySig();
Robert Babcock.
Y AC :www.animemusicvideos.org/members/linkprobview.php %3Fdownload_id%3D1442+Robert+Babcock+ashyukun&hl=e n&ie=UTF-8).
Do a search for Ashyukun on google.(www.nhmk.com/nes/ )
also at
(http://216.239.33.104/search?q=cache:q1XY1gcmA
Consider yourself lucky you don't have to deal with hotmail. Hmm.. what do guys with names like Dick Cheney do?
Looks like that page is working again - perhaps the password reset screen has been repaired somehow? Don't have a hotmail account to test with...
"There is more worth loving than we have strength to love." - Brian Jay Stanley
i was watching Baywatch while posting on securityfocus ...
err please swap the attacker and victim email ids
-- Muhammad Faisal Rauf Danka
When I attempted to contact Microsoft about the problem, they asked me for a credit card number. When I explained I didn't want support and was trying to report a bug, I was transferred to someone else who... asked me for a credit card number. Wash, rinse, repeat.
Dude,
They were just tyring to issue a refund to your credit card for the purchase price of Windows.
(Pssst, I also have this wicked cool eBridge if you want it).
The traditional way on Bugtraq seems to be mailto:secure@microsoft.com.
I usually stand up for the Redmond boys if there's some bashing going on and not alot of balance to the issue. But this is just an incredibly stupid hole to have open. Why would you ever, ever, ever pass details in the URL string that the user himself need not (and should not be allowed to) supply? If it is because you are passing it among servers in some fancy-schmancy web service scheme, then at least have the decency to hide the exploitable name/value pair in an http header or something (but even this should not be necessary for what they are doing , even if my guess as to how their backend works is wayyy offbase). Somebody said it earlier in the discussion that it is because developers (using the term lightly) add features without thinking of how to do it right and how to do it securely and just pass any old thing in the URL string, and they were right on the mark.
Some coders (again using the term loosely) at my organization used to do this absolutely all the time and I would bitch about how piss poor it was from a security angle (and regularly demonstrate how easy it was to circumvent the intended "security" mechanisms). Everybody laughed at me when I did... that is until one of our largest customers hired an outside firm to audit the "security" of the apps they were getting. It took the firm very little time to discover these nuggets, of course. It is interesting to note that they reported that the application security was among the poorest they had seen, but that the server configurations (my department) were among the tightest. The sad thing is the stupid customer basically thought the two canceled each other out, threw some extra money at redesigning the application to meet the standards it should have to begin with, rewarded our systems team which had done it right the first time with absolutely squat, and renewed the contract for another five years. Shows you how much the corporate world understands what's really going on.
Can I bum a sig? I left mine at the office.
After months of trying to understand Microsoft's situation (Windows XP Shows the Direction Microsoft is Going), I came to the conclusion that the Microsoft management style leads to mountains of sloppy code that is difficult to maintain. That's the only theory that seems to fit. For example, in Internet Explorer browser alone, there have been for years more serious security bugs than Microsoft fixed. There are, at present 14 security vulnerabilities.
Here is the recent record. The list of defects has been similar for years. Also, this is a record only of security defects, not all defects:
- June 18, 2002: 18 vulnerabilities
- August 8, 2002: 22 vulnerabilities
- September 9, 2002: 19 vulnerabilities
- November 19, 2002: 32 vulnerabilities
- December 9, 2002: 19 vulnerabilities. (Microsoft fixed 15 on Nov. 20, but
two new ones were found.)
- May 8, 2003: 14 vulnerabilities
This is a terrible record for a company that has $52.9 billion in the bank. (See "Total Current Assets" in the upper left hand corner, which is the money available within the next few months. It takes time to spend a billion dollars, so the next few months is equivalent to cash.)Obviously, Microsoft could fix the bugs if the company wanted to fix them. But the company apparently lacks the will to devote the resources necessary (IE still does not have tabbed browsing), and apparently also, it is not easy.
A few months back, my company underwent a security audit from one of the third-party companies who do that sort of thing. It was truly beautiful watching their analysts do things to our web-app which we had never intended people to do. They're real artists.
We're a small-ish company, these guys came in for a week, exposed some weaknesses and some stylistic quibbles, and they're fixed.
If we can bring in an expert in this sort of thing, why can't Microsoft? Is it arrogance, apathy, or ignorance, or something else?
They can always swallow their pride, scrap their insecure system and join the Liberty Alliance Project.
---
The combined human population is enough to feed every living tiger for app. 28000 years.
Sometimes you get what you ask for.
simpson that is...
DOH!!!
My problem? I was perfectly gruntled, until some numbnuts came by and dissed me.
Just remember that Microsoft is lying. When they claim to be secure, they are lying. When they say that you can get a refund, they are lying. When they say you can opt out, they are lying.
open up VB. insert tab control. insert web browser control. add an add tab function. viola, tabbed browsing.
My problem? I was perfectly gruntled, until some numbnuts came by and dissed me.
this vulnerability still IS NOT fixed.
so much for trustworthy computing
A Google search on passport email "reset your password" yields some interesting links with (possible?) alternate URLs for this exploit. Is MSoft's domain the only place where this works? I would assume there's other sites that have bought into MS's security tripe and have setup passport servers, or is passport a central repository?
The Russians have won. They have made the world a cesspool of distrust, greed, fear and hate.
>> But seriously, there seems to be no OFFICIAL way for end users to actually contact microsoft,
secure@microsoft.com is supposedly the way to contact Microsoft on security issues. I can see why everyone has trouble remembering it. If it were insecure@microsoft.com it would be far easier to remember.
I just tried the attack with my own hotmail account and was able to change the password. For those of you trying, remember to change the attacker@attacker.com to another valid email account, or you won't receive the reset email message. That should be obvious, but apparently some posters hadn't figured that out.
Sure, it's buggy. Police States are always incompetent. They also reasure their victims with crap like, " Sign in on any computer that has Internet access. .NET Passport uses powerful online security technology and follows a comprehensive privacy policy to help protect your profile information. You manage your information-sharing options." The Nazis were equal dullards but look how far they got. Incompetence does not keep you from being nasty, thourough and powerful.
Paranoid yet? You should be. Microsoft is bussy building tools and attitudes the most UnAmerican administration would value. They are just the kind of hacks the Nazis picked up and stuck into government and university positions. The time to fight the maddness is now, before it becomes official.
Friends don't help friends install M$ junk.
What's even funnier about this is that it is modded, "Insightful".
Back in the day databases had "records", then they have "rows". The pragmatic difference is, well, subtle at best.
.NET is just how Unix types would build a "web site" that exchanged lower level data, that might not be intended for display, in XML.
.NET is, fundimentally, is Microsoft's own collection of tools and how they conspire in that uniquely closed Microsoft way to build a client/server application over HTTP.
.NET is not bound by language. The pitch goes like this... What if you have a library of reusable "C" functions, but your programmer only knows Basic? Well, the punch line goes, no problem with .NET! The Basic nut just starts piling on the Basic.
.NET comes with one Gawd awful package of marketing lies of magical qualities, like "data finding me". Oddly, I have yet to have *data*, of any sort, "find me". But, then, it wouldn't be a Microsoft thing without the lies.
The
You have the "smart client"! Ok, *nix types might call that Mozilla, wget, or their own app.
You have "Servers"! Yea, IIS is Microsoft own for that wich many use Apache.
You have "Development tools"! Ok, yes, you know, all that Java, PHP, or Perl stuff? Right, pretty much that.
You have "Web Services"! Uh huh, you can send data to a "Server" and have it do something. Fine, that's nice.
NOTE: "Web Services" are simply the fact that "the Web" need not be limited to Browser/HTML/Server. The "Browser" can be any program, "HTML" can be any arbitrary data interchange format (XML), and the Server need not serve flat HTML pages (JSP, ASP, PHP, etc.) Yea, they've "discovered" HTTP isn't limited to HTML and you can build RPC on HTTP.
What
They bandy about the XML word, but XML is strictly a data representation format. A flexible one, to be sure, but just a format. Don't like that whole http: question mark parameter string, or parsing POST data? Use XML instead.
One "feature" is
Geze, a system in a multitude of languages. Great, no cost in supporting that long term, is there. I assure you it is cheaper to train our Basic nut in C.
Oh, lest we forget,
Granted, single-sign-on is convenient, but you can achieve nearly the same convenience using mozilla (and probably any other browser).
Just create a random password for every service you use, log in once and let mozilla store the username/password pair in the password manager and make sure access to the password manager is password protected. That way you only have to remember one password, but you still have different passwords for different sites which are reasonable secure (for they are random generated).
Now if Mozilla supported tracking the age of passwords and telling you to generate a new password for a site once the password reaches a certain age, that would be great!
-- Having problems sending big files over the net? Try out Efisto (http://efisto.org)
i learned about this in a CS course, and i couldnt help thinking, "duh, any sensible person wouldnt be that stupid..." obviously i was wrong.
Another CS student wondering everybody seems so gosh darn stupid while they are so obviously bright is hardly noteworthy. The post comes down to "Duhh.... they done BAD!", and it gets a +5 insightful?
Is/are there any Anti-Microsoft advocacy groups out there? I'm talking about respectable, legitimate groups that have seriously documented how and why Microsoft's practices are bad. I'm not talking about Joe H4X0R's I-Hate-Microsoft geocities webpage.
If not, perhaps there should be, with the goal to educate people who help MS - the suits who are suckered in to the Ad campaigns and really have no idea about such things.
Thanks.
"Would it kill you to put down the toilet seat?" -- Maya Angelou
This may be a naive question, but how do I go about closing a .Net Passport account? I want Microsoft to remove all of my personal information from their servers.
There seems to be no way to do this online. A call to MS customer service resulted in an "I dunno, I can't do that." answer.
btw, I'm not dumb enough to actively participate in Passport. I bought something online last summer from a small company, and after completing the purchase, I was shocked to see that Microsoft was handling the transaction with Passport. Damn it! Now they have my credit card info, shipping address, etc. Guess I should have read the fine print before I clicked Sumbit...
Anyone successfully done this?
MS has their visual programming platform. Nice to use, as a matter of practice.
.NET, servers can export their "interface" (with some additional overhead when programming them) such that the visual tools can build nice menus for the programmer.
With
You can put that additional overhead into online documentation just as easily, where it can be elaborated on/humanized a bit more easily and maintained as a unit reference for postarity.
This is off of their forgotten password page. Can you give us more code please? Thanks.
.NET Passport password, please enter the following information and then click Continue.
To reset your Microsoft®
Help
{{if RSP._isHotmailMode }}{{else}}{{endif}}
Clearly most sites offer a reset password option (eg "I forgot my password, my e-mail is idiot@doofus.org"). Surely to shut down a service you simply spam the service provider with an alphabetic listing of the possible e-mail addresses until the users get tired of changing their account password everyday .... why wouldn't this work?
I have noticed some systems have the "type the characters in the graphic" system to avoid this sort of thing. No reason why those characters can't be read with some form of OCR though?
Hmmm, just a thought.
I need to make some stupid friends, it seems. Well, friends who are more stupid than the ones I have now, at any rate.
But it's a good exploit, anyway. Kudos to the person who slaved for almost 15 minutes to figure it out (that's not a slander against the cracker in question, but against the pathetic sec- . . . secuuu- . . . jeez, I can't even call it what MS wants me to think it is).
Do not touch -Willie
Yes, in fact if you log in and go to your profile, there's a link in the bottom left hand nav that says "CLOSE .NET PASSPORT ACCOUNT"
You click on that, agree to their terms and close your account right there in three clicks.
Goodluck
Muhammad Faisal Rauf Danka get screwed by DMCA
Yeah, ha! Trustworthy computing! Sure...no, it's not fixed yet. I just checked it out (on my own hotmail account, of course).
He could have given that info to terrorists and they could have funneled pilfered monies into all sorts of dangerous activities. By doing his best to expose the flaw he has, no doubt, save many lives.
Running with Linux for over 20 years!
That Microsoft could have fixed many more bugs, is something that could be see as one possibility, but in only the past tense. It looks like things got out of hand a while ago and that the management could be just riding the company down - pump and dump
Don't forget that benefits have been cut way back and there's also been outsourcing like mad. Consultants and contractors don't show up as layoffs when you let them go.
Beta is broken and the link to classic doesn't work. Stop wasting our time or there won't be anybody left here.
Yet another post about flaws and vulerabilities in yet another Microsoft product or almost product and it got me a thinkin' that there seems to be a slight undercurrent of familiarity to this scenerio.
I think possibily Microsoft has found a way to use it's own flawed products to convince politicians and the like that a hard-wired security system is inevitable.
And if MS is going to control this technology then they will most certainly use it to not only dominate existing and new markets but they will also use it to hide their own flaws and vunerabilities.
Any security technology that is likely to have the impact such as MS's Trust-Worthless Computing could have should be a public and open source technology or standard not another monopolistic revenue source...
it happens when they change something in the redmond.
I know you are psychotic, but please make an effort.
Microsoft Rule #3: GUI standards are no longer necessary. Shiny objects are always user-friendly.
;).
I think this can be even more appropriately applied to Apple too (after all the years of UI guidelines that went out the window with Mac OS X
Wow, a .NET advertisement under a .NET vulnerability article!
Please direct all bug reports to
A similar one bit me when I was upgrading my machine the other year.
I'd installed an AMD K2 running at 500MHz, and Windoze 95 crashed at the point of initialising the desktop. Booting into DOS worked fine, so the machine wasn't broken. A search of the Knowledge Base showed that this was a known bug on AMD procesors running over ~300MHz, and a patch was available.
Downloaded the patch to a floppy, put it in the machine, tried to run it from the command line, got the message:
To labour the point: this patch fixed a bug which prevented Windows from starting.
Using HTML in email is like putting sound effects on your phone calls. Just say <strong>no</strong>.
Needless to say, I'm writing this from a Linux box.
OS Software is like love: The best way to make it grow is to give it away.
It's backwards. What incentive does a company have to change, when its current habits have netted it $52.9 billion in cash?
If you've made any study of it at all you know that effective security results from a process that starts before the software is even written. There is no protocol that will save you from logic errors (like the latest Passport hole). To do this reqires a good understanding by the devs of security and their adherence to design principles and coding practices. To do that you need a software development methodology that enforces the consistent application of those priciples and practices. Therein lies the problem.
In my little corner of MS (though by all accounts it was typical of the company as a whole) what was prized above all was meeting requirements and deadlines. Virtually no energy was put into the development environment (hence the hour I spent every morning just downloading the nightly build, the insane .bat scripts, constantly fixing my own NT install as a $55/hr contractor). Nobody got "c-hours" for making life easier. More importantly, there was little value placed on design, good technique. Lip service was paid in meetings and reviews, of course, and superficial style details received obsessive scrutiny. Code reviews often bogged down on correct hungarian notation but a unit test consisting of "return true" was perfectly ok. The "heros" were people with big brain muscles who spent nights and weekends hammering out code to meet the latest deadline.
The result of all this was a coding culture that I called the kingdom of cut-and-paste. I was actually encouraged to write routines by starting with someone else's routine to do something unrelated and edit it to do my task. A colleague would stand over my shoulder browsing the codebase looking for something convenient to steal. It was a shock to realize how little code people actually wrote. This is one of the things that I hated about working there, that I spent so much of my time fscking with the various APIs, incomprehensible include file heirarchies and so little time writing C++.
Well, in my Intro to Fortran class in '77 the prof explained why massive code duplication is a bad idea, and the results are visible in every MS product. You can't fix a bug in one place, you have to fix it every place it got copied to, and you don't know where those are. The codebase is now on the order of 100'sM lines or better? Probably not even MS has a good handle on this, because they can't know for sure how much duplication (with tiny variations) there is (clue: lots).
Once a company grows to a considerable size it's really hard to change the culture. I've seen this at several startups. MS is like a battleship or an aircraft carrier. High-tech and deadly but turning that boat around is really hard and simply may not happen in a short distance. Expecting them to change their performance WRT security in a few months (or year) is kind of like expecting the old Soviet apparatchiks to start respecting civil liberties and human dignity because the Central Comittee sends out a memo. Good luck. It's a city unto itself in Redmond, its own little world. And even if you did, what the hell are you going to do about the millions of lines of (largely incomprehensible) code in the installed base? The millions of systems in the wild that are unpatched and unmaintained?
I see many of the same disasters being recapitulated in .NET. They may talk security and I'm sure they're trying hard but I expect that their long term strategies are going to rely more on legislation than the (probably impossible)
task of bringing their products t
So now maybe I can get back that account that I forgot the password for. Sweet.
Glad I used a totally unique password and didn't provide any REAL information to those .NET clowns.
The only way that I've gotten to a level where I could almost "report" a bug would be after dealing with tech support (@ $250 / incident) for a few days.
Why must this be the fate of the good jokes? That and "the infidels are committing suicide at our firewall" were the best I'd heard in awhile, but now they're just old...
Quit ruining all the good jokes!
I hereby place the above post in the public domain.
and for the non-dutchies amongst us :
Microsoft fixes security hole in Hotmail
AMSTERDAM - Microsoft fixed a security hole in Hotmail, after news got out how easy it was to change someone's password, according to WebWereld. Needed were: the email adress of your victim and two urls.
In a mailinglist Muhammad Faisal Rauf Danka explains the trick.
A few hours after de explanation appeared on the mailinglist, Microsoft had taken care of the problem. Danka had been trying to warn Microsoft of the existance of the problem since april 12th.
I remember reporting a bug in hotmail once. I guess it was some time in 2000 or so. They actually had a "report bug" hidden somewhere in there.
When reporting a bug, you were supposed to select the error-message you got. The available options were all standard hotmail error messages that was not due to a bug. There was one option called "I didn't get any error message". That's what I selected.
Shortly after filing the bug report, I got an automated response telling me that my bug report "needed closer inspection by a human", and they would get back to me. A few days later, I got a mail from some empleyee at hotmail, and we worked things out. I guess selecting one of the error-messages would just have sent an automated e-mail describing that it wasn't actually a bug and was supposed to work that way etc.
Sadly, This option seems to have been removed.
your nick reveals your origin.
Chatmag.com last week had reported a similar vulnerability, coming in an unsolicited email with the subject: "Someone has sent you an Insta Kiss". Clicking the link in the email takes a user to a site hosted on a server in The Netherlands, with what appears to be a valid Hotmail/Passport login screen. It actually captures a users username and password. We informed Microsoft on the 3rd of May, and the site was removed. The email in question is still being sent to users, the link referenced in the email is now out of service.
Pete Carr Owner Chatmag.com
So my spam isnt safe at hotmail anymore?
Oh well... so all this means is someone can break in and read the 30 pieces of spam i get in that account every day... *shrug* hope they enjoy themsleves...
I'm only paranoid because everyone is against me...
A: You're way off about changing peoples' approach. The sad fact is people like that are in pain-avoidance mode. Give them pain. Give them a productive way to avoid the pain. There must be code review. One guy does a little coding, another guy has to sign off on it. A third has to sign off that it has been tested (whether or not any testing actually happens is not important). All three get burned if anything bad happens: after-hours or weekend work to fix it NOW? The rate of code churn goes down, and the quality goes up. Grumbling goes up, but it sounds like a personal problem to me... :)
B: You're dead-on-target about doing other people's work. You can't have individual effort and collective accountability. You have to have collective work and collective accountability. Oh, and if you're smarter than others: the sharpest knife always gets used the most. Adjust to it. One day you will be enlightened.
C: You are dead-on-target about the financial sector :). That does not mean it won't work in hospitals or law offices though. It just means *somebody* has to fulfill the role of irate customer when the slackers need it.
Culture is not something you create at the water cooler or in seminars. It is dictated by the unique combination of supply and demand wherever you are. You can change the supply (of people or other resources), or the demand. The boss/team-leader mediates customer demand and needs to have some real power over the programmers in the same way that customers have real power to affect the company's bottom line. If you lack accountability, that isn't a software development problem. You're just going to get shoddy results, software security, housekeeping, everything included.
The moral of the story: accountability is security. So, if you want a culture of security, improve your accountability! It has positive potential for Maslow's "self-actualizer" types too.
--- Nothing clever here: move along now...
Actaully this makes perfect sense for a company that is designed for making money.
You can't make money selling fully functional software or by releasing patches. You can make money selling newer versions of disfunctional software.
The GEEK shall inherit the earth...
That's not a vulnerability. That's just unaware (stupid?) users giving their username and password to the bad guys.
This theory would make sense, except that Internet Explorer's bugs are so public and severe that it would make sense to fix them, even if, overall, Microsoft's business model is to make money by delaying delivering a good product.
Very interesting links.
Look at this: A Microsoft Group Vice President, Kevin R. Johnson, received 322,560 shares of stock 3 days ago and sold it that same day. He received 244,760 shares of stock on March 6, 2003 and sold that the same day.
Does he know something normal investors don't? Isn't he indicating that he expects MS shares to go down?
so funny MS put money on the dotnet suffix and now get rid of it in advertising and public products :o)
:P
Those guys got too much of money
I mean this as a serious question: I wonder how those numbers of bugs compares to an open source project like Mozilla, Konquerer, etc. Sometimes I think Microsoft, AOL, and other traditional "Bad Guys" are perceived as having crappy software simply because they are under more scrutiny (i.e. millions of eyeballs interacting with the programs daily).
Want to talk? ashaver AT pdx DOT edu
There is always this debate about viruses and hacks always available for M$ just because their SW is more widespread the *nix. Actually i totally disagree to this, i think they have a serious problem with their core engines, the basics or pilgrims they are standing upon are corrupt. The more they build over these corrupt basics, the output gets to be quite wacky. They tend to fix the wackys tuff with no use, cause the core is not optimized or secure..
/*When ur 1 of the few to land on ur feet, what would u do 2 make ends meet??!*/
The lunatic is in my head
As long as the two accounts (victim,attacker) are hotmail.com accounts. I just tried it.
look at this url: https://memberservices.passport.net/ppsecure/MSRV_ ResetPW.srf?lc=1033&sf=1&id=2&ru=http://www.hotmai l.msn.com/cgi-bin/sbox&tw=20&fs=1&cb=&cbid=24325&t s=0&sec=&mspp_shared=&seclog=0&kpp=2&svc=mail&mspp jph=1&em=jameslongs@hotmail.com
my favorite parts:
&sec=
&seclog=0
good to know they're still keeping track of possible exploits even as much as 12 hours after this has been discovered...
I mod down pyramid schemes in sigs.
And you thought a slashdotting was a heavy load... ;-)
If you disagree, post your argument. (-1, Overrated) isn't your personal censorship tool for views you don't like.
It might be a federal crime in the United States, but fortunately, most of the rest of the world has a smarter legal system. Or perhaps the US government plans to block all incoming traffic from outside, so no-one can read the EU- or Asian- or Australian-based news sites and see this for themselves...? :-)
If you disagree, post your argument. (-1, Overrated) isn't your personal censorship tool for views you don't like.
To install it, you either need to jumper the CPU down to a slower speed, or boot the computer in Safe mode, as the bug doesn't prevent booting in safe mode...
Annoying, yes.
dead
M$ has previously moved heaven and earth to do things when they were felt to be important. Look at their bloody minded efforts to turn around Internet.
If M$ really commits to being secure, they will get much better at it. It just may take a while.
Besides, all this lousy crud will merely serve to reinforce how good and essential Palladium is.
(though I do wonder how Palladium will be able to tell a worm running in a poorly written app from a legit process)
Xix.
"Everything is adjustable, provided you have the right tools"
Yes, I remember that bug. Funny, 'cause you could usually get windows to load into safe mode, but you still couldn't install the patch.
The only thing I ever found that worked was to slow the processor down to 266 Mhz, install the patch, then clock it back up again.
This was for Win95x on AMD K6-2 systems.
I have no problem with your religion until you decide it's reason to deprive others of the truth.
lickum balls. faggot.
I am certainly NOT saying that he is doing anything illegal. I am only saying that by selling 567,000 shares of Microsoft stock, and keeping only 5,700 shares, he is indicating, loud and clear, that he has no strong idea that Microsoft stock will go up. Presumably, he would rather have more money than less. If he had a good idea that Microsoft stock would go up, he would have kept more shares, even if he wanted to diversify.
I wonder about this too.
I notice that Opera is listed as having 3 security vulnerabilities in the pivx.com link above. However, Opera's history is that the security vulnerabilities get fixed quickly.
I found a serious bug (204668) in a recent build of Mozilla (a stack overflow, not a security vulnerability), reported it using Mozilla Bugzilla, and they fixed it within a day.
I complained of another bug in Mozilla, and they had an answer in two hours. Those Mozilla people are seriously interested in getting the job done.
Maybe the world only has the intellectual resources to produce one or two good browsers.
man i ish this shiet still werked. thtat'd be phat.
People, including CEOs, may not understand or wish to understand "IT" so it is easy to bullshit them. In contrast, nearly everyone understands money. So it's no surprise that, as the FTC is fixing to knock them in the head, there are many who see the club descending. If the FTC doesn't finish them, then losing monopoly rents will. It may drag out in the courts and ad campaigns a bit to give time for counting coup.
Beta is broken and the link to classic doesn't work. Stop wasting our time or there won't be anybody left here.
Just noticed - I spend 3 *months* doing the planing (not 3 years, as it appears, must have deleted the word 'months') oops.
1 - You usually stand up for "Redmond Boys"(which is a lame term for MSFT, how cliché)? Yes, they need defending as they are so cash starved and poorly penetrated into the consumer OS space and have so little cash on hand they need even people who aren't even shareholders standing up for them.
;p
2 - MSFT is consumer grade stuff, stupidity goes with the territory. Look at Windows ME, OS 9, OS X and you, for example. Even Windows NT/2000/XP/2003 is amusingly susceptible to SYN attacks, to date (and registry corruption, and various security and reliability flaws). But consumers don't test an OS against completely strenuous network and disk IO. Just run that 3Dmark for me again, PFY.
3 - And you criticize their secure computing methods because you code so much? Can I see your code samples or are you all just anecdotes and hot air?
4 - Fancy schmancy web service scheme? So exchanging data from the client, through application servers to a back end is fancy schmancy? Sounds like the fundaments of having an online presence for just about everything. Fancy schmancy to static web page people like yourself.
5 - No, you wouldn't use a header, you would probably just use SSL or some other encryption method. I don't see how using email or plain HTTP would be able to obfuscate the password without encryption. Mister security suggesting plain text.
6 - You would use the term developer lightly because you are one yourself and know one when you see one? I don't think so. You are clearly a junior sysadmin who does the coffee and donut run.
7 - I have never met people in my travels who would do such idiotic things like passing data in need of obfuscation around in urls. You must work for second rate companies and know second rate people. I'm thinking Big fish mentality, extra small pond, with lots of quagmire and filth.
8 - Again, your use of the word coders lightly because you are one and know better and have lots of code samples for us to look at proving how witty and well practiced you are?
9 - You are a PHB in the making. The "security angle." I like that Ballmer-esque use of the word! Basically not hiring retards helps a lot more than you think it does, but you would know because you havent ever been in a position of hiring anyone and you work with retards, apparently.
10 - So they failed to follow best practices with regard to security and kept their jobs because? There is such a death of people available for employment? Yeah right. If you don't like them, fire them and get one of hundreds waiting for work. Oh, yeah, you are a lowly PFY talking crap.
11 - Everyone laughed you when you did, huh? The little man shows them whose boss huh. The little guy with the big ideas will just show them who is MISTER MAN! Hero! Give them a big DBZ kameha-meha for my there tykster!
12 - One of our largest customers, eg, someone who bought from us twice? From what you said about your coders and developers you have a duty to inform them they've just bough fucking crap software then, get to it! Oh, they hired auditors to do it because you are a PFY. And this gets me. Your server configurations are secure. You are taking auditors words for it eh. Yes, now that some outside people with little inside knowledge of your "servers" (probably all PC "servers") come by and try a few canned piece of crap things to prove your systems are secure. Sounds like you take those auditors word so seriously and you are so proud of what your big mentor boss - I mean, you do! You know, if you get audited for your taxes and pass, you didn't do a great job filling out your taxes, it means you didn't fuck up. Some random person came in and said, you didn't fuck up! And now you are posting about your leetness here because you're so bloody cool!
13 - basically your half truth sob story shows how easy it is to talk in nebulous terms, make up stories and fabricate various things to make a random wanna-be look like a Guru. Yeah, a Guru according to a Ziff pu
-Fucking Gay Fucking Goatfuq .___8',-',";. .______h ._i
A_______________________8..A
s__Eat shit cuncasket__#~..s
s__Eat shit slashbots_8.',-s
_____________________#',-.
r__Mediocritomaton __8',-..r
a__fuckin loser_____#~',-..a
p__EAT SHIT NOW! ___8_',-..p
i__________________##',-',-i
n__Lick cock -_____8',-',";n
g__fuckface _____##',-',"_cg
__shitstain
c _suck a pig's ##',-',";._r
o__anus you _-__8',-',";,._i
c__PIECE of_____#'',-',";,.m
k__SHIT _______8(',-',";,.._
_____________#(',-',";,.,._f
l _________#8#8_',-',";,.,.e
o_________#',-.8',-',";,.,.l
v________8~',-..#',-',";,..c
i_______#'',-',";8_',-',";.h
n_____8=',-',";.+#+',-',";.i
g____#=',-',";,._8',-',";,.n
___#=',-',";,..(#',-',";.8_g
r__8(',-',goat,.(8',-',";s#-
i_8(',-',fucker";#',-',-s8_p
m_#z',-',loser,";8',-..s#__i
_8_.,#',"ass',";~#,..88____e
f_#.##'philanderer~8,.8#___c
e_8##',-+~'',-',-~#'8______e
l_#.,..-',-',";.'=8#_______-
c_.8+_',-',";,.'88_________o
h___888',-',";~8___________f
e______8#888#88____________
r__________________________s
____.oO Suck My Dog
-_Suck my dogs dick, fag
F__________________________t
a___shit fucking ass t_____
g_______motherfuck_________
___________________________a
___________________________s
Ass raping fucking queer_ass
Most people probably think they already know all they need to know about AlphaSys The Noobie Ass Fucking Retard, but I have some new information to bring to light. To get right down to it, AlphaSys The Noobie Ass Fucking Retard says he's going to waste natural resources by the end of the decade. Good old AlphaSys The Noobie Ass Fucking Retard. He just loves to open his mouth and let all kinds of things come out without listening to how petulant they sound. Dastardly hooliganism is a disgrace to humanity, but it cannot be eliminated by moral lectures or by pious intentions. No, it can be eradicated only if we ratchet up our level of understanding. You might think this is all pretty funny now, but I doubt I'll hear you laughing if, by next weekend, he is successfully able to eavesdrop on all sorts of private conversations. I have a soft spot for imperious drug addicts: a bog not too far from here. AlphaSys The Noobie Ass Fucking Retard maintains that there's no difference between normal people like you and me and unforgiving recidivists. Even if this were so, AlphaSys The Noobie Ass Fucking Retard would still be ornery. But AlphaSys The Noobie Ass Fucking Retard has gotten away with so much for so long that he's lost all sense of caution, all sense of limits. If you think about it, only a man without any sense of limits could desire to label everyone he doesn't like as a racist, sexist, fascist, communist, or some equally terrible "-ist". There is considerable evidence to show that he is serious about wanting to feed information from sources inside the government to organizations with particularly improvident agendas, yet double standards are always stupid. This sort of vertiginous paradox is well known to most devious good-for-nothings. He is indeed up to something. I don't know exactly what, but AlphaSys The Noobie Ass Fucking Retard is driving me nuts. I can't take it anymore! Also let me just say that no matter what else we do, our first move must be to educate everyone about how I would be surprised if he stopped to communicate and share ideas with even one of the people he regularly attacks. That's the first step: education. Education alone is not enough, of course. We must also tell it like it is. I i
Alphasys The Bullshitting Liar contends that his harangues are good for the environment, human rights, and baby seals. Excuse me, but where exactly did this little factoid come from? He can't possibly believe that there is something intellectually provocative in the tired rehashing of subhuman stereotypes. He's stupid, but he's not that stupid. I have this advice to offer: The world has changed, Alphasys The Bullshitting Liar; get used to it. Although he obviously hates my guts (and probably yours, as well), I, hardheaded cynic that I am, oppose his crusades because they are ruthless. I oppose them because they are xenophobic. And I oppose them because they will lead to the destruction of the human race as soon as our backs are turned.
If he gets his way, none of us will be able to tell you a little bit about Alphasys The Bullshitting Liar and his irascible ruses. Therefore, we must not let him keep us perennially behind the eight ball. A great many of us don't want him to foment lackadaisical forms of political tyranny. But we feel a prodigious societal pressure to smile, to be nice, and not to object to his huffy, insipid effusions. From secret-handshake societies meeting at "the usual place" to back-door admissions committees, Alphasys The Bullshitting Liar's representatives have always found a way to treat anyone who doesn't agree with Alphasys The Bullshitting Liar to a torrent of vitriol and vilification. We must doubtlessly focus on concrete facts, on hard news, on analyzing and interpreting what's happening in the world. Does that sound extremist? Is it too eccentric for you? I'm sorry if it seems that way, but that's life.
Alphasys The Bullshitting Liar's diatribes have caused widespread social alienation, and from this alienation a thousand social pathologies have sprung. Please remember that Alphasys The Bullshitting Liar will restructure the social, political, and economic relationships throughout the entire society because he possesses a hatred that defies all logic and understanding, that cannot be quantified or reasoned away, and that savagely possesses what I call villainous menaces with power-drunk and uncontrollable rage. How did he get so domineering? I have my theories, but they're only speculation. At any rate, anyone willing to study and ponder my position on most current matters will definitely find that if stated outright, his morals would be manifestly unpopular. (Actually, his positions need to be reassessed with his ulterior motives in mind, but that's not important now.)
This march into disaffected Stalinism is not happening by mere chance. It is not, as many obnoxious quacks insist, the result of the natural, inevitable course of things. It is happening as a direct result of Alphasys The Bullshitting Liar's caustic memoranda.
Let me be clear. If you were to t
Microsoft secures many of their MSDN subscriptions with the Passport. Crack someone's Passport and you'll have full access to that person's MSDN subscription including all downloads and product keys. That may get their attention...
Yup, in the end I had to drop the processor down to 250, patch, and bump it up again.
It reminded me of the time someone posted to a Netscape newsgroup wanting a JavaScript snippet that could determine whether JavaScript was enabled or not. Even better, someone posted a reply. Of course, it only worked if JS was enabled :-)
Using HTML in email is like putting sound effects on your phone calls. Just say <strong>no</strong>.
Oh, Tsarkon, my hero... I was so blind.
Seriously, though. I thought you'd given up on me. Thank God I was mistaken. It's so cute how you put your utterly baseless arguments and assumptions as to my intelligence, attitude, aptitude and skill in one AC post and your vain libel in another in the attempt to appear as two separate ACs. Truth told, you don't really even constitute a half poster, much less more than one.
Nice to know that I can put some bait out there and get you to waste some time in reply. The difference is I can troll you and still provide decent enough conversation/info to be worth something to the whole discussion.
No, I don't profess to be a coder. I went into systems to avoid any coding that requires thinking above the scripting level. That's just it. I'm amazed that some folks who base their entire livelihood on their ability to design and implement applications have so little a clue of how to do it.
You imply your own system architecture understanding and application design skillz are at least competent by attempting to impugn mine. Well, then you should think a little harder, buggar. Just creating an SSL session to keep your info safe on the wire doesn't begin to mitigate the problem with this exploit (um, geez, that's such an official word for what in this case boils down to URL-tampering... I thought enough work went into web app design today that URL-tampering was an extinct attack vector). That was my whole point earlier. Any idiot who can examine the hyperlink can imagine the attack method, So just observing normal operation within the app itself is enough to figure out that this is wider open than your pouting rictus in the proximity of the PFY.
You want code samples? There's nothing I do in any of my code that isn't easily derived from a five-minute google for whatever it is you're trying to do. You want some enlightening secrets about the super-secret world of locking down a server? Sorry, all I have is what's freely available from the usual sources, you know, bugtraq, the NSA, honeynet discussion lists, etc. No magic bullets. You caught me. What a fraud I've perpetrated.
I don't know where you get off trying to paint me as some kind of Steve Gibson or the like, but it sure is funny to watch you fail at cogent sentience in the process. I swear, when you get all worked up, it's like watching de-volution at work. Are we not men? The difference between your motivation and mine for carrying on this converstion is this... You do it just to antagonize me, but I actually believe there is hope for you one day to look at something more open-mindedly than you currently do. You egg me on because you believe my kind will never change. I reply becuase I retain hope that yours one day will. That's the beauty in the Dawn of Man... it happens every day somewhere. And once it happens to you, you can make it happen over and over for others.
Can I bum a sig? I left mine at the office.
you still have no skills as a coder and talk shit about it. you still are not a developer and talk shit about it. you live vicariously through criticizing other's work, and pretending to be something you're not. you are a fat sexless live with parents pimple fuckin btch. and your noobness and language give it all away. your little "reverse troll" hHAAHHAAHAahahaha. didnt even fuckin make a dent. you suck at it. you used the words "dawn of man" bWAHAHAHahahaa . oh, yes, the highly evolved bitch that you are, the fat sexless, meek little fuckin bastard. and from the sound of it, i could kick your fuckin ass to with that little pussy bitch mouth of yours. you are a jack of some trades, master of none. you just plain suck. keep posting, because in my highly paid spare time, ill just come by to get a rise out of you. and its worked every time. hasta la vista, fuckstick. "Are we not men?" hahahaha. heh. You are much worse than steve gibson. baseless flying fucking bullshitter. You said "I'm serious" in anothe rone of your posts. Yeah, lil man talking the big stuff on slashdot. you are propelry doing your part though, you are contributing to why reading slashdot at anything higher than -1 is like putitng a shit filter on your ass, karma whores like you who jack get more floor than the funny shit. hhaahahhaa. keep it up piss bucket.
you should try finally showing your secret lust for men or underage girls or whatever your fancy is and show them what a man you are. p0st01ng on slashdot aint gettin you any.
I am writing this letter in simple English in order that everyone can read and understand my words. Let me cut to the chase: This is a truth that Alphasys's factotums are told by Alphasys that they cannot acknowledge, lest they give aid and comfort to the rest of us. Do I blame society for this? No, I blame Alphasys. I must emphasize that mischievous carousers demand the advantages other people have earned without the disadvantages, like having to earn them. But let's not lose sight of the larger, more important issue here: his ugly teachings.
As stated earlier, the space remaining in this letter will not suffice even to enumerate the ways in which Alphasys has tried to expose and neutralize his enemies rather than sit at the same table and negotiate. It can be distinguished only with difficulty which of his trained seals act out of inner stupidity or incompetence and which only pretend to for whatever dissolute, appalling reason. The reason is clear. He is inherently peevish, churlish, and silly. Oh, and he also has a garrulous mode of existence.
Alphasys is willing to promote truth and justice when it's convenient. But when it threatens his creature comforts, Alphasys throws principle to the wind. Never have I seen such a gross error in judgment as his decision to deploy enormous resources in a war of attrition against helpless citizens. It has been said that his most recent tracts are irreverent, in bad taste, and inappropriate. I, in turn, feel that I can guarantee the readers of this letter that he has certainly never given evidence of thinking extensively. Or at all, for that matter. Even if we accepted Alphasys's jibes, so what? Does that mean that everyone with a different set of beliefs from his is going to get a one-way ticket to Hell? Of course not.
It's really hard to take someone as disloyal as Alphasys very seriously. People have commented that there may be a gap in my logic there. I don't think there is, and I've gone to great pains to explain why.
To say otherwise would be smarmy. We will have to become much more vigilant to ensure that he doesn't deprive individuals of the right to fight for what is right. I acknowledge freely and make no apology for the fact that I once considered it reasonable for irritable saboteurs to let us know exactly what our attitudes should be towards various types of people and behavior. But now I know that he likes to cite poll results that "prove" that it is bloodthirsty to question his methods of interpretation. Really? Have you ever been contacted by one of his pollsters? Chances are good that you have never been contacted and never will be. Otherwise, the polls would show that if you ever ask Alphasys to do something, you can bet that your request will get lost in the shuffle, unaddressed, ignored, and rebuffed.
Even if I agreed that his blasphemous ideals were of paramount importance, it would still be the case that there are some offensive killjoys who are grotty. There are also some who are uneducated. Which category does Alphasys fall into? If the question overwhelms you, I suggest you check "both". You might object to my claim that we mustn't tolerate the likes of Alphasys. But bear in mind that my prayers go out to everyone who was hurt by him. Sadly, lack of space prevents me from elaborating further. His ventures cannot stand on their own merit. That's why they're dependent on elaborate artifices and explanatory stories to convince us that those who disagree with Alphasys should be cast into the outer darkness, should be shunned, should starve.
Rash, puerile mountebanks are sharply focused on an immediate goal: to dissolve the bonds that join individuals to their natural communities. Essentially, he labels anyone he doesn't like as "militant". That might well be a better description of Alphasys.
It's possible that he doesn't realize this because he has been ingrained with so much of obscurantism's propaganda. If that's the case, I recommend that we build a new understanding that can transport us to tomorrow.
May 08, Associated Press Microsoft admits Passport was vulnerable. Computer researcher Muhammad Faisal Rauf Danka of Pakistan discovered how to breach Microsoft Corp.'s security procedures for its Internet Passport service. The service is designed to protect customers visiting some retail Web sites, sending e-mails and in some cases making credit-card purchases. Microsoft acknowledged the flaw affected all its 200 million Passport accounts but said it fixed the problem early Thursday, after details were published on the Internet Wednesday night. Under a settlement with the Federal Trade Commission (FTC) last year over lapsed Passport security, Microsoft pledged to take reasonable safeguards to protect personal consumer information during the next two decades or risk fines up to $11,000 per violation. The FTC's Jessica Rich said Thursday that each vulnerable account could constitute a separate violation - raising the maximum fine that could be assessed against Microsoft to $2.2 trillion. Source: http://www.washingtonpost.com/wp-dyn/articles/A303 30-2003May8.html
I have to use this cause I can't afford a real sig...
Oh, yeah, about your little url tampering bit, real applications put very little in the url, if anything at all. peruse mail.yahoo.com or some other real scaled out application. No one fuckin does that shit anymore, and its not a big deal "your figured it out." I already asked, who the fuck do you work with. Apparently troglodytes. SMALL POND, BIg Stinkin Fish mentality, retard.
;p
Keep up the self congratualting. its hilarious. MISTER MAN!
now shut the fuck up and get back to your non-work, you sexless, live athome cant afford real hardware man child. go shoo shoo.
The NYTimes is carrying the AP story. It starts "Microsoft acknowledged a security flaw Thursday in its popular Internet Passport service that left 200 million consumer accounts vulnerable to hackers and thieves -- an admission that could expose the company to a hefty fine from U.S. regulators."