Slashdot Mirror


Microsoft Sits on Security Flaw for Six Months

pmf writes "Yet another critical vulnerability affecting Windows 2000/XP/2003 has been just announced by eEye. It is worthy to note, that it took Microsoft over 6 months to fix it. The bug affects ASN.1 library and is remotely exploitable through authentication subsystems (Kerberos, NTLMv2) and applications that make use of SSL certificates." The AP has an overview.

52 of 741 comments (clear)

  1. Love the poem... by jwthompson2 · · Score: 5, Funny

    U Can't Trust This
    By: MCSE Hammer

    Blaster did ya some harm
    We just say, hey, another worm
    But thank you, for trusting me
    To mind your site's security
    It's all good, when your server's downed
    Our dope PR will pass blame around
    Cuz it's known as such
    That this is some software, you can't trust

    I told ya Homeland
    U can't trust this
    Yeah that's why we're giving ya the code
    U can't trust this
    Check out eEye, man
    U can't trust this
    Yo let 'em bust more funky system
    U can't trust this

    Give 'em a string or recvfrom
    Like no sweat they got the keys to your kingdom
    Now ya know
    You talk about eEye, you're talking about holes
    Remote and tight
    Coders still sweating so someone better write
    A book to learn
    What it's gonna take in '04
    To earn some trust
    Legit, either secure or ya might as well quit

    That's the word because you know
    U can't trust this
    U can't trust this

    --
    Even if I knew that tomorrow the world would go to pieces, I would still plant my apple tree. -Martin Luther
    1. Re:Love the poem... by poot_rootbeer · · Score: 4, Funny

      U Can't Trust This

      Man, this cultural reference is even older than the security flaw they just fixed...

    2. Re:Love the poem... by tarquin_fim_bim · · Score: 4, Funny

      That would have been really funny 12 years ago.

      Wow. That would have been around about the last time Microsoft gave a shit about its customers. Surely only a coincidence?

    3. Re:Love the poem... by Anonymous Coward · · Score: 5, Funny

      That is an outrageous lie! Microsoft has NEVER given a shit about their customers!

    4. Re:Love the poem... by buckeyeguy · · Score: 4, Funny

      Geez, what's next? Baby Got Hacked?

      --
      I'd have a personalized plate on my car, but "toxic bachelor" won't fit into 7 letters.
    5. Re:Love the poem... by UFNinja · · Score: 5, Funny

      I like buggy code and I cannot lie. You other hackers can't deny When a geek walks in with a laptop briefcase And Knoppix-STD in yo face You get sprung Wanna boot it up quick cuz you know BSoD's suck Look at the theme Gnome's wearin' I'm hooked and I can't stop starin' oh Tuxy I wanna get with ya And take yo picture My MCSE tried to warn me But them hackin' tools make me so horny. . .

  2. Comment removed by account_deleted · · Score: 3, Funny

    Comment removed based on user account deletion

  3. Yawn... by Anonymous Coward · · Score: 5, Funny

    6 months? 2000's been out for 3 years! If it took them 2.5 year to find the bug, another half is year is no biggie.

  4. 6 months later, millions switch to Linux. by Adolph_Hitler · · Score: 4, Funny

    Thats the result of Microsofts terrible history on security. Please Mr.Gates, continue to help the Linux community thrive.

    --
    People don't exist to serve systems, systems exist to serve people.
  5. it took much more... by kyshtock · · Score: 5, Funny
    ... to kill the other security flaw... Windows 9x, that is.

    If you are Microsoft fundamentalist karma blaster, I meant that in a good way...

    --
    Bite my shiny metal... oops... Nevermind!
    1. Re:it took much more... by kyshtock · · Score: 1, Funny
      5 minutes to remove a network cable? what's wrong with you???

      --
      Bite my shiny metal... oops... Nevermind!
  6. That's no bug! by ackthpt · · Score: 4, Funny
    The bug affects ASN.1 library and is remotely exploitable through authentication subsystems (Kerberos, NTLMv2) and applications that make use of SSL certificates."

    That's no bug!

    That's Intellectual Property!

    "In other news: PanIP has filed suit claiming Microsoft's latest bug violates one or more of their patents."

    --

    A feeling of having made the same mistake before: Deja Foobar
  7. Re:ASN.1: same issues as in OpenSSL by sik0fewl · · Score: 4, Funny

    I dunno, hard to say. But you'd think if Microsoft would go so far as to copy the code they'd be smart enough to copy the patch, too, instead of sitting on it for six months :-)

    --
    I remember when legal used to mean lawful, now it means some kind of loophole. - Leo Kessler
  8. Better late than never... by ForestGrump · · Score: 1, Funny

    subject says all.

    -Grump

    --
    Is it true that more people vote for the winner of American Idol, than vote for the president? -Ali G.
  9. In related news ... by BabyDave · · Score: 5, Funny

    A flaw was found in AOL Instant Messenger relating to the A/S/L library.

  10. Re:Windows NT / 2000? by girgit · · Score: 5, Funny

    When was windows NT released again ?

    Most recently, Windows NT was released again as Windows Server 2003. Before that it was released again as Windows XP and before that by the loveable name of W2K.
    Hmmm. You asked when. Sorry, I don't know the dates.

  11. Re:Alert the media... by andih8u · · Score: 5, Funny

    Why would they want to report on a computer flaw that could affect millions when they could be filling us in on the latest happenings of the Jayson Blair, Kobe Bryant, Scott Peterson, and Martha Stuart trials; plus news on what Janet Jackson's nipple is up to today.

    --


    slashdot, news for crazed liberal socialist zealots
  12. Super Double Critical? by Saeed+al-Sahaf · · Score: 4, Funny
    From the story: "Microsoft, which learned about the flaws more than six months ago from researchers, said the only protective solution was to apply a repairing patch it offered on its Web site. It assessed the threat to computer users as "critical," its highest rating."

    So, if they fix a security flaw sooner than six months, what status does that get? Super Double Critical?

    --
    "Who are in control, they are not in control of anything - they don't even control themselves!" - Glen Beck
    1. Re:Super Double Critical? by Brent+Nordquist · · Score: 3, Funny
      So, if they fix a security flaw sooner than six months,

      Hypothetically, you mean?

      --
      Brent J. Nordquist N0BJN
  13. Sad state of affairs by glpierce · · Score: 4, Funny

    Sadly, I think that a file called "This_is_a_virus_-_do_not_open.exe" would be just as effective as any other.

    --
    G
  14. They finally released Longhorn? by Anonymous Coward · · Score: 1, Funny

    It's about time!

  15. Re:THIS IS NOT NEWS!!!! by musikit · · Score: 2, Funny

    if it was released without bugs or security flaws how would the product ever get into the news?

  16. To really bring attention to this.... by FerretFrottage · · Score: 2, Funny

    just have Janet Jackon do a "half-time" concert at the next major Windows conference. The promoters may even get Balmer to play the part of Timberlake.

    --
    "Look Lois, the two symbols of the Republican Party: an elephant, and a fat white guy who is threatened by change."
  17. Re:Note to crackers by Anonymous Coward · · Score: 2, Funny

    When they finally get laid. Which is to say... never.

  18. Poem for Bill by kyshtock · · Score: 1, Funny

    Windows is bad, Microsoft's blue, Security flaws suck And so do you. Signed: Clippy

    --
    Bite my shiny metal... oops... Nevermind!
  19. Re:Say it ain't so... by gid13 · · Score: 5, Funny

    Okay, so this is the least relevant post in the history of mankind, but tell me "vis-a-vis" wouldn't be the best word EVER for ebonics:

    "A prime exampizzle of racizzle can be seen vis-a-vizzle the ethnizzlicity of the indigenizzle pizzles of South Afrizzle."

    Well, that does it for me, karma be damned.

  20. U Can't Root This by Anonymous Coward · · Score: 5, Funny

    U Can't Root This
    By: MC GNU/Hammer

    Linux did ya some harm
    We just say, hey, an open sore
    But thank you, for rooting me
    To mind your site's security
    It's all good, when your server's downed
    Our dope coders will run GNU debug
    Cuz it's known as such
    That this is some software, you can't root

    I told ya script kiddie
    U can't root this
    Yeah that's why we're giving ya the code
    U can't root this
    Check out Torvalds, man
    U can't root this
    Yo let 'em bust more funky grep
    U can't root this

    Give 'em a bash prompt or C code
    Like no sweat they got the salts for your hash
    Now ya know
    You talk about Stallman, you're talking ideology
    GNU's not Linux, its GNU/Linux
    Coders still sweating so someone better write
    A patch for this
    What it's gonna take in '04
    To earn some root
    Legit, either secure or ya might as well quit

    That's the word because you know
    U can't root this
    U can't Root this

  21. They did it on purpose to abuse your computer by LoveOO · · Score: 2, Funny

    I think this was not a flaw but a design to enable MS to spy on your computer, introduce problems, etc. from central servers of their own in order to get you to upgrade, buy more software etc. and to give them a competitive advantage. When somebody discovered it, it took them six months to figure out how to maintain this and not be discovered for another ?? years. That is what the patch truly does.

    --
    Gungah dah lungha.... So I've got that going for me.
  22. Re:Note to crackers by pyros · · Score: 3, Funny

    kettle: pot, you're black.

  23. Re:ASN.1: same issues as in OpenSSL by koh · · Score: 2, Funny

    But you'd think if Microsoft would go so far as to copy the code they'd be smart enough to copy the patch, too, instead of sitting on it for six months

    You don't need to be that smart to copy someone else's code, and that may be the problem.

    --
    Karma cannot be described by words alone.
  24. Re:MyDoom by Theatetus · · Score: 2, Funny

    None, other than the Stupid User Who Runs Untrusted Executable Files vulnerability, for which the only patch is a baseball bat.

    --
    All's true that is mistrusted
  25. Re:The Rest of the Update - Remove Unacceptable Sy by niall2 · · Score: 2, Funny

    Not Janet Jacksons breast again! Damn you Viacom.

    --
    Today is a gift. Save the receipt.
  26. Re:Note to crackers by Mod+Me+God · · Score: 2, Funny

    It was an ironic comment, couldn't you see that? I remember the mag PCW used the term M$ way back in '94 and it was old then.

    --
    --

    FreeNET user? Comfortable with the adverse selection?
  27. Re:Alert the media... by kfg · · Score: 2, Funny

    Just because you're paranoid, doesn't mean they're not after you - Kurt Cobain quoting Woody Allen.

    Any minute now SCO is going to claim that they own Woody's IP and sue Kurt. When informed that Kurt is dead they'll claim IP rights to suicide technology, double their claim and add Dr. Kevorkian to their suit.

    When they hear of this exploit they'll blame it on Linux terrorists, point and shout "Look, Janet's nipple!" and then run the other way when everyone looks.

    KFG

  28. Other Goverments. by DAldredge · · Score: 1, Funny

    Thank God that no other goverments have the source code to windows! Because if they did then they could have found this bug first and used it to steal US Goverment secrets! I guess MSFT was right when they said reveling the windows codebase would put the Security of the USA at risk!!!

    Oh, wait...

  29. No, I'm New Here by New+Here · · Score: 0, Funny

    No, I'm New Here

  30. Re:Note to crackers by sqlrob · · Score: 2, Funny

    Oracle's open source? That's news to me.

  31. Re:Note to crackers by happyfrogcow · · Score: 2, Funny

    The GPL is the reason why you Lunix kiddies don't have Photoshop, MS Office, and games

    Yes, the "viral" GPL sure has made Neverwinter Nights become liscensed under the GPL now, hasn't it.

    troll.

  32. Re:Note to crackers by somekindofuniguy · · Score: 3, Funny

    profeccional
    Like a spelling checker, you mean?

  33. Re:Note to crackers by inode_buddha · · Score: 2, Funny
    Wonder of wonders, an AC actually used "affecting" correctly, and I'm responding...

    /me weeps for this world... (tolerant non-kiddie)

    --
    C|N>K
  34. Re:Note to crackers by zulux · · Score: 5, Funny



    Like a spelling checker, you mean?

    I don't need a spellchecker on Slashdot.

    I just wait for a tool like you do it for me.

    --

    Moneyed corporations, non-working 'poor' and criminal prisoners are turning productive citizens into tax-slaves.

  35. stuff by Tom · · Score: 4, Funny

    I guess this is in the "Stuff that matters" category then, since it certainly isn't "News" by any stretch of imagination.

    --
    Assorted stuff I do sometimes: Lemuria.org
  36. Re:Alert the media... by AnonymousNoMore · · Score: 5, Funny

    You forget that the U.S. was founded by people who left Europe to find a level of self imposed repression not available to them in the old world.

  37. Re:Note to crackers by jrockway · · Score: 4, Funny

    A professional tool like Windows? You may want to think that, but every day there's a new windows virus that almost brings down the internet. That's not professional. That's stupid.

    Now, if M$ decided to patch vulnerabilities like OSS did (there are lots of exploits in OSS software, but they're usually fixed in an hour), then they would be professional. But they sit on the knoweledge and litigate against people that tell them there are problems. That's not professional. That's nazi.

    --
    My other car is first.
  38. Re:Note to crackers by Le+Marteau · · Score: 3, Funny

    How long will it take LUNIX kids to stop using infantile terms like M$

    Never, as long as it continues to piss dweebs like you off.

    --
    Mod down people who tell people how to mod in their sigs
  39. Re:Alert the media... by Anonymous Coward · · Score: 1, Funny

    supprising as both men and women have nipples.

  40. Re:Alert the media... by Dirtside · · Score: 2, Funny

    Another version: The U.S. was founded by people so staid and uptight that England threw them out.

    --
    "Destroy science and religion. Science would re-emerge exactly the same; but not religion." - Penn Jillette, paraphrased
  41. i've got yer competition right here by d34thm0nk3y · · Score: 2, Funny

    The Master Control Program has chosen you to serve your system on the game grid.

  42. Why? by Warhaven · · Score: 4, Funny

    These kinds of companies and organization are somewhat of an interest to me, in that they resemble the Battered Wife syndrome.

    Here they are, putting all their effort into helping fix MS's products to make the software work better, only to get brushed off and ignored for six months. Then they go and complain about how horrible of a company MS is and how horrible the software is.

    Two weeks later, they're at it again, trying to help solve MS's problems, and will yet again be brushed off and ignored. They'll complain and rant, and in another month when the next vulnerability is discovered, they'll be back at MS's side again trying to fix it. Repeat...

    Why bother investing the time and money into a company that doesn't care? If you're going to be putting in the effort, go with something like Linux where you aren't ignored, can apply the patching yourself, release the patch, and say, "Hey, we fixed the problem. Here's the patch everyone," instead of groveling at MS's feet and trying to convince the company that they should not give every 3rd-rate script kiddie admin access.

  43. Re:More to come... by Anonymous Coward · · Score: 2, Funny

    In the time it took you to whine about the non-link you could have copy and pasted the text into your browser.

  44. Re:Note to crackers by Frankensloot · · Score: 4, Funny
    by the way, the Gimp is AS GOOD AS PHOTOSHOP
    That's utterly retarded. I found your statement so strikingly indicative of a delusional and/or willfully ignorant state of mind, in fact, that I could not help but allow the hint of a smirk to break across my otherwise stony face. I have created this account, Frankensloot, for the express purpose of stalking you as you post comments in the future and pointing out all the idiotic things you are sure to say. My hope is that I shall gain some modicum of amusement from your continued displays of foolishness.

    Upon encountering your ridiculous assertion that "the Gimp is AS GOOD AS PHOTOSHOP," some souls, less driven, might merely shake their heads, titter nervously, and walk away. I am not that sort of man, and I am not prepared to let your stupidity fade away unnoticed.

    Cheerio.
  45. Re:Note to crackers by Grishnakh · · Score: 2, Funny

    This is your company's fault for making the stupid decision to get themselves locked-in with a single vendor. Smarter companies try to avoid being locked in, and hopefully will eventually put you out of business.

    In the meantime, every time MS decides to raise their licensing prices, you have no choice but to bend over and take it.

    [boss] Well, your performance was outstanding in 2004. Very good. I'm recommending you for only a 10% pay cut this year.

    [bjtuna] Pay cut??? Why? You just said my performance was outstanding!

    [boss] Sorry, but all the non-managerial workers are getting a pay cut this year. Microsoft forced us to upgrade to Licensing 7, which is going to cost us a lot of money, which of course had to be taken from someplace else. Just be glad your performance wasn't rated "adequate", in
    which case you'd get a 30% pay cut.

    [bjtuna] What about you?

    [boss] I'm getting a 10% raise. You don't think we managers would give ourselves a pay cut, do you?

    [bjtuna] Maybe we should look into porting some of our apps to *nix to save on these licensing costs.

    [boss] That's a pipe dream. It'd cost too much to rewrite all the ASP and MS-SQL stuff. It's easier and cheaper to just stick with MS, and cut everyone's salary.