View Full Version : Microsoft Programs at Risk from Web Worm
Dark Blaze
27th January 2003, 13:50
Good day everyone,
Here is something that might interest you to know about.. I've known about this since Saturday night, but I was able to post it just now..
Microsoft Corp. said on Saturday that a virus-like attack against its key database software, which slowed Internet traffic around the globe, could spread to its other less frequently used programs unless users protected themselves with key software updates.
Although the spread of the computer worm had passed its peak and was coming under control, Microsoft Chief Security Strategist Scott Charney urged companies, the main buyers of Microsoft's SQL (pronounced 'sequel') Server 2000 and other related programs, to download security patches from the world's largest software maker's Web site.
"It was a vulnerability. We knew about it, but someone is exploiting it," Charney told Reuters, "We want our customers to be as secure as possible and install the patches."
In the worst widespread Web attack in a year and a half, the worm clogged network pipelines around the globe, nearly shutting down Internet providers in South Korea, disrupting a majority of Bank of America Corp.'s automatic teller machines and made online surfing and e-mail access difficult.
A key component of the SQL Server software, called "Microsoft SQL Server 2000 Desktop Engine," is particularly vulnerable to the malicious computer worm, which quickly propagates itself and seeks out other systems to infect.
Since MSDE is deployed not only in SQL software but in other programs used for software development, such as Visual Studio .NET and Office XP Developer Edition, it could spread beyond the database servers, Charney said.
"The unfortunate thing about this is when you know that this was a problem and they (customers) hadn't updated," Charney said, "That's a bit frustrating."
Charney was hired by Microsoft nearly a year ago, just when Chairman and co-founder Bill Gates issued a mandate that the company focus on "Trustworthy Computing," a campaign aimed at making its software more protected, secure and reliable.
Charney said Saturday's attack "showed how relevant that policy was."
"To respond to those threats, we need cooperation," Charney said.
Patches, or fixes, for programs using MSDN as well as for SQL are available on Microsoft's TechNet support page ( http:/www.microsoft.com/technet ), the company said.
Source Reuters & CNN News
That's all for now.. I might reply to a bit of more threads, check a few emails, but that's just about it as I will be returning to my warm bed seeking relief from a cold I obtained...
Have a nice day,
luck777jojo
28th January 2003, 07:16
ok I'm not quite sure but..... didn't they say on saturday that it was a DDos attack on the entire web in general not just a worm which targets microsoft based servers..... I dunno
Dark Blaze
28th January 2003, 10:04
Yes that's quite right.. I have a feeling that came afterwards, right after the worm was spread. But not the entire web.. About 20% of the Internet was brought down to its knees.. Mostly banks, airport booking systems, ATMs, and so on..
I wonder who it was...
Btw, did you know that a very known hacker got out of jail recently?
luck777jojo
28th January 2003, 10:29
nope didn't hear that.... makes you wonder, eh?
Dark Blaze
28th January 2003, 12:20
yeah, it certainly does...
luck777jojo
29th January 2003, 03:23
did he just get out of jail or was there conditions for his parole, a.k.a. not being closer then 10feet to a computer, I know they do this sometimes for big hackers.
[MPC]MeTwoWhat
10th February 2003, 23:25
i bet he could do it from a palmpilot eh?
thats kinda amazing to think about.. only gettin out of jail and already gathered a large enough botnet to bring 20% of the internet to a halt? :S
Rookie-1
11th February 2003, 03:40
i wouldn't go pointing to quick at the guy.....the gov is worried that thats just what the terriosts will do......give the guy alittle bit of a break.....when he went in there wasn't much of a internet.....
Dark Blaze
7th March 2003, 13:32
Consider this possibility, he had already designed one interesting worm if he did so, with coding designed to work in such ways to affect the 20%, all he needed to do was perfect it afterwards..
luck he probably has the usual conditions most of the hackers of that level gone to jail get... He can't get anywhere near 10feet or so of a computer or anything with an internet connection..
NightNinja
7th March 2003, 22:24
Originally posted by Dark Blaze
Consider this possibility, he had already designed one interesting worm if he did so, with coding designed to work in such ways to affect the 20%, all he needed to do was perfect it afterwards..
luck he probably has the usual conditions most of the hackers of that level gone to jail get... He can't get anywhere near 10feet or so of a computer or anything with an internet connection..
^^ thats the worst thing u can do to a person...everyone needs computer access...especially with internet. Life without a computer is not life... eh thats all i have to say.
luck777jojo
8th March 2003, 03:59
NN there was a story about that witten by Isaac Asimov, very good short story actually, if you get a chance read it ;)
bigtimestuff
12th March 2003, 02:55
Thanks for the info DB ill check that sight to see if there're any patches i need. Pretty amazing about 20% of the web being hacked...just think if he had gotten those atms to spit out money...:ninja:
Dark Blaze
13th March 2003, 23:00
You're welcome :)
consider this even... having made those atms spit out money and you being right in front of them to collect the money ;) :D
KeKs
14th March 2003, 17:23
hmm a ddos on the entire web seems unreal kinda...
Dark Blaze
14th March 2003, 17:45
I personally don't knowing offhand what most if not all of you peeps know... The Web is linked (thus a web) by trillions of computers.. So if a few can be DDoSed, then more, then even more after that, why would it be hard to imagine the entire or part of the web be DDoSed?
KeKs
14th March 2003, 17:50
becuz of trillions of conputers...
hmm but i bet u know better i think ive learned something today :D
KillKin
18th March 2003, 00:58
can this be scanned for?
luck777jojo
18th March 2003, 04:44
this shouldn't really worry you that much anymore.... it happened a while ago and mostly affected servers not personal computers ;)
Dark Blaze
19th March 2003, 11:06
Everyone learns something new every day KeKs ;)
KillKin I offered links above in my first post.. check them out if you feel the need.
But yes, luck is right.. it shouldn't worry you at the time present as it happened a while ago and mostly affected the computers working as servers, and not all personal computers, but better be safe than sorry if you want to ;)
Dragula
23rd March 2003, 11:45
very good point. the possibilities are virtually endless.
Dark Blaze
2nd April 2003, 23:11
Precisely, thank you :)
luck777jojo
3rd April 2003, 05:24
heh well the only way to be completely secure is not to have a computer at all :p
Sparkomatic
10th April 2003, 12:52
wasnt the hacker in question kevin mitnick? I saw him playing on a computer on the screen savers, was playing BF1942, first time touching a computer since his conviction. kinda cool.
hey, i gotta get 30 posts some how....
Dark Blaze
10th April 2003, 17:33
Actually, the most secure way to use technology, is to use an old typewriter..
luck777jojo
11th April 2003, 09:02
and and remember what they were saying in 1999.... typewriters are Y2K compatable ;) :p
DarkCloud
11th April 2003, 09:40
Since when? hehe My typewriter when honky on me when I was surfing the net lol
Well, a computer with a dead battery for the clock is y2k compatible too :p
luck777jojo
11th April 2003, 10:30
yeah hehe forgot about that... my old mac classic II is Y3k compatable.... the date always stays 1967 :p
bigtimestuff
11th April 2003, 10:41
I cant believe everybody made such a mess about that like our computers were going to blow up and microwaves expload when nothing at all happened. To tell u the truth i was kinda hoping things would go to hell...so i could loot and riot:rambo:
o({})o
11th April 2003, 22:16
I don't really know what all the fuss was about, but eventually it will be another century and people will be worried...... Perhaps then they will learn their lesson ;).
DarkCloud
11th April 2003, 23:16
Kinda makes me wonder if the "matrix" is y3k compliant lol
luck777jojo
11th April 2003, 23:19
wel worse case scenario.... when it comes to Y3k we'll all just have our memories wipped clean and go back to living in the year 1900 ;)
Dark Blaze
12th April 2003, 00:09
heh :)
NightNinja
12th April 2003, 00:19
sure, especially since Y3k is really com'n up? how many years left? 998? Damn! thats closer than u think!!!! :p
Dark Blaze
22nd April 2003, 00:34
lol :D
luck777jojo
22nd April 2003, 08:46
hey I might be able to stay alive that long if I get chrinogenically frozen every day for 23 hours.... just enough time unfrozen to check the forums :p
DarkCloud
22nd April 2003, 08:53
*reaches for back of spine* no connecters... darn or do I think there is no connecters?
anyways, how do you know if we're not in the matrix right now and it rolled back to 1900? Perhaps we're not y3k or y4k compliant as we thing? hehe
luck777jojo
22nd April 2003, 10:32
whoa, hehe this whole thing is ALREADY giving me a headache, just goes t prove that we ARE in the matrix :p
hehe the matrix just modified something (I remeber answering that post of yours already ;))
Dark Blaze
22nd April 2003, 20:15
Actually guys, the real matrix was upgraded a few days ago, so you should not be able to realise those connection plugs located at the back of your head.
Btw, luck your idea might work, but remember.. MPC is addictive.. one hour a day just won't cut it ;)
luck777jojo
23rd April 2003, 06:15
well I guess if I spend two hours a day that should still be enough to stay alive untill the next millenium or untill a cure for death is found :p
Jacobus
27th April 2003, 20:46
Why not just dedicate your life to creating/finding the elixer, then put a 3inch thick layer of 'oil of Ulay' all over yourself when your 70, to make yourself 20 again, and bask......
p.s. just interested, I mean I know we all have oiur skills here (mine isnt typing), but is there NE1 on the forum that is at all any form of a decent hacker, with a tale to tell?
Pressuming your an average of what 17 now? and the average life expectancy is like 75 or somthing, thats 58 years left. thats (58*365 ish) 21,170 days, (21,170 * 24) 508080 hours left in your life.
That means youve got 508080 days left, if you only spend 1 hour a day unfrozen, on the forum
(2003 to 3000 = 997 years =) 363905 days till Y3k
You'll make it past 3000 no probs!
ok.. whos first to doubt my calculations?
bear in mind, Im 3 times champion (before you doubt me)
PACMAN
SPACE INCADERS
SNAKE
MINE FOREVER
vBulletin® v3.8.4, Copyright ©2000-2009, Jelsoft Enterprises Ltd.