Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Question on Microsoft Windows Source Code Leak

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » The DU Lounge Donate to DU
 
bluestateguy Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Feb-14-04 12:09 PM
Original message
Question on Microsoft Windows Source Code Leak
The Windows source code was put onto the Internet the other day and is apparently bieng used by hackers. My question is if we can expect Microsoft to come out with a patch to protect against this (if this is possible). I checked the windows update page and found nothing new.
Printer Friendly | Permalink |  | Top
JailForBush Donating Member (753 posts) Send PM | Profile | Ignore Sat Feb-14-04 12:26 PM
Response to Original message
1. I heard they issued a patch, but it had a security issue.
You need to download their security-patch patch.

In fairness, Microsoft has good reason to be a little unorganized. First, they inadvertently outsourced their webmaster to Pakistan, rather than India. Also, Microsoft's attorneys got mixed up and blackmailed Microsoft's security department, rather than a public school district.

If all the Windodws XP computers are destroyed, people can always move back to the buggier Windows Millennium.
Printer Friendly | Permalink |  | Top
 
Kellanved Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Feb-14-04 12:27 PM
Response to Original message
2. if a problem is identified, then probably yes
This is a rather interesting situation. In a good software product knowledge of the source *should* not be of any help for a hacker.
Reality is another matter and the first reports about the sources seem to indicate dire bugs and security issues.

It was Microsoft, who always said that Open Source is a security risk ("Security by obscurity"). I guess the first thing updated will be their marketing campaign.
Printer Friendly | Permalink |  | Top
 
Kellanved Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Feb-16-04 11:14 AM
Response to Reply #2
4. Here they come: first exploit based on the leaked source
Edited on Mon Feb-16-04 11:24 AM by Kellanved
The poster on full disclosure seems to be a jerk (sorry, but see for yourself), however he has a point. He found a way to create an overflow in IE 5.x and Outlook Express with a manipulated bitmap.

http://lists.netsys.com/pipermail/full-disclosure/2004-February/017364.html


Guess it's true: Windows with a firewall :
Printer Friendly | Permalink |  | Top
 
Commie Pinko Dirtbag Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Feb-16-04 11:30 AM
Response to Reply #4
5. I am ashamed that such a person is a C programmer. (nt)
Printer Friendly | Permalink |  | Top
 
thermodynamic Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Feb-14-04 12:44 PM
Response to Original message
3. The source code leaked was incomplete...
On www.zdnet.com/zdnn theere's an article. Somebody said that the whole of Windows source code is close to 40 Gigabytes.

A 220Mb zip file that, when extracted, expands to 660Mb is nothing by comparison.

It's not going to help hackers.

Anything found from the source can't be used in court.

The hackers can't do MS a favor and fix the buggy bloaty code and give it back to them...

This is no different than stealing an encyclopedia and looking up human skeletal structure. (of course, the encyclopedia maker would keep said encyclopedias under strict guard, inaccessible to all...)

Closed source is bollocks anyway. It gives the unscrupuled the means to be as sloppy as they want, with nobody to check up on them.

It's a myth that open source leads to hacker heaven, not when there are controls in place. Otherwise we'd have heard tons of stories from corporate america who rely on Linux and got hacked...
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Thu Dec 26th 2024, 07:08 AM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » The DU Lounge Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC