Hard Light Productions Forums

Off-Topic Discussion => General Discussion => Topic started by: Kamikaze on February 12, 2004, 06:56:33 pm

Title: Disconnect your network cables, hide in the bunkers...
Post by: Kamikaze on February 12, 2004, 06:56:33 pm
http://slashdot.org/articles/04/02/12/2114228.shtml?tid=109&tid=187

MS Windows NT and 2k source code leaked.

Bye bye security.
Title: Disconnect your network cables, hide in the bunkers...
Post by: GeistKrieger on February 12, 2004, 06:59:08 pm
O man this sucks!
Title: Disconnect your network cables, hide in the bunkers...
Post by: Taristin on February 12, 2004, 06:59:54 pm
...lovely...

Linux, here I come...
Title: Disconnect your network cables, hide in the bunkers...
Post by: redsniper on February 12, 2004, 07:04:04 pm
and since XP is based off of 2k...
Title: Disconnect your network cables, hide in the bunkers...
Post by: Taristin on February 12, 2004, 07:07:03 pm
Quote
Actually, I think it would be funny to see the open source community release a security patch for win2k before Windows does, proving that open source is more secure since it can be patched faster with more eyes looking at it.


:lol:

I can't wait. :p
Title: Disconnect your network cables, hide in the bunkers...
Post by: redsniper on February 12, 2004, 07:09:42 pm
heh, watch it really happen.
Title: Disconnect your network cables, hide in the bunkers...
Post by: GeistKrieger on February 12, 2004, 07:11:20 pm
Yeah watch all the hackers on earth take advantege of this too.
Title: Disconnect your network cables, hide in the bunkers...
Post by: Kamikaze on February 12, 2004, 07:50:09 pm
MS comments that they're not sure of the validity.

http://www.internetnews.com/ent-news/article.php/3312451

http://zdnet.com.com/2100-1104_2-5158496.html
Title: Disconnect your network cables, hide in the bunkers...
Post by: redsniper on February 12, 2004, 08:04:07 pm
Quote
from Kamikaze's sig
Last edited by Setekh on 07-05-2004 at 09:54 AM

How is that possible?
Title: Disconnect your network cables, hide in the bunkers...
Post by: Taristin on February 12, 2004, 08:19:50 pm
Quote
Originally posted by redsniper

How is that possible?


It's not. :p
But you, too, can have one just like that...
Title: Disconnect your network cables, hide in the bunkers...
Post by: Grey Wolf on February 12, 2004, 08:27:08 pm
It's his sig. It hasn't actually been edited by Setekh.
Title: Disconnect your network cables, hide in the bunkers...
Post by: redsniper on February 12, 2004, 08:45:33 pm
I figured that was the case, right after I posted. Just sorta freaked me out at first.
Title: Disconnect your network cables, hide in the bunkers...
Post by: Carl on February 12, 2004, 08:56:22 pm
it's been in his sig for a long time.
Title: Disconnect your network cables, hide in the bunkers...
Post by: redsniper on February 12, 2004, 08:57:34 pm
ok, so I'm inobservant :p
Title: Disconnect your network cables, hide in the bunkers...
Post by: Taristin on February 12, 2004, 09:00:49 pm
I fell for it a little while back too... but when I did, the date was a few monthe before the post...
Title: Disconnect your network cables, hide in the bunkers...
Post by: phreak on February 12, 2004, 10:28:25 pm
well if windows is 35 million lines of code and fs2_open is around 400,000 and it takes fs2_open about 7 minutes to compile, how long will it take for windows to compile

*waits for CP*
Title: Disconnect your network cables, hide in the bunkers...
Post by: Bobboau on February 12, 2004, 10:41:27 pm
10 hours 12 minutes and 29.88 seconds
Title: Disconnect your network cables, hide in the bunkers...
Post by: Singh on February 12, 2004, 10:46:19 pm
*moves back to trusty ol 98*
2000 gave me too little resource control anyway......at least this way i know I can actualyl END that pesky program without windows complaining.....
Title: Disconnect your network cables, hide in the bunkers...
Post by: Beowulf on February 12, 2004, 10:57:32 pm
Windoze == :shaking:

Sorce of Windoze == :shaking:

Leaked == :shaking:

I == :mad:
Title: Disconnect your network cables, hide in the bunkers...
Post by: Stryke 9 on February 12, 2004, 11:08:34 pm
And it's confirmed.



Eh, not such a big deal. After an initial burst of ****bags taking advantage of newfound and probably rather serious flaws (during which, yeah, might be smart to leave the computer offline permanently), it'll all stabilize out, get to be not much worse than normal. Be interesting to see if this leads to multiple unauthorized versions of Microsoft like the Linux exploits, though.
Title: Disconnect your network cables, hide in the bunkers...
Post by: Bobboau on February 12, 2004, 11:32:05 pm
that's what I'm hopeing for
Title: Disconnect your network cables, hide in the bunkers...
Post by: Sandwich on February 13, 2004, 02:49:04 am
*installs Linux*
Title: Disconnect your network cables, hide in the bunkers...
Post by: Windrunner on February 13, 2004, 03:28:01 am
oh crap...
if this is comes to more hacker attacks, i don't know what i'll do.
i am so sick and tired of installing new securety patches from MS
Title: Disconnect your network cables, hide in the bunkers...
Post by: Singh on February 13, 2004, 05:14:53 am
i just realized something...
MS has dug itself into a grave here.
Why?
Any GOOD programmer with some sense of Morals wont speak up where they got the code from, because of fear from the insinuating lawsuits that MS might put on their future work - its more assured that VERY few will say they actually saw it, if any at all.

Any Bad programmer is just going to keep it to themselvesand hack away at it like nobody's business. They dont need to tell anyone - the world will see it in the virri that comes out.

Either way, MS's own legal and greedy policy have done themselves in.
Title: Disconnect your network cables, hide in the bunkers...
Post by: Grug on February 13, 2004, 05:21:44 am
this doesnt include xp tho does it...

but it does use ntfs doesnt it...  hmm

yes big doo doo i thinks

-Grug
Title: Disconnect your network cables, hide in the bunkers...
Post by: Ashrak on February 13, 2004, 06:53:45 am
lets hope my firewall can defend itself
Title: Disconnect your network cables, hide in the bunkers...
Post by: Bobboau on February 13, 2004, 06:56:25 am
for those of you who want to know how closely related XP is to 2000 here is a little snipet from the leaked source


Code: [Select]
              /* printf("Welcome to Windows 3.1");    */
               /* printf("Welcome to Windows 3.11");   */
               /* printf("Welcome to Windows 95");     */
               /* printf("Welcome to Windows NT 3.0"); */
               /* printf("Welcome to Windows 98");     */
               /* printf("Welcome to Windows NT 4.0"); */
               printf("Welcome to Windows 2000");
Title: Disconnect your network cables, hide in the bunkers...
Post by: Beowulf on February 13, 2004, 09:10:42 am
Quote
Originally posted by Bobboau
for those of you who want to know how closely related XP is to 2000 here is a little snipet from the leaked source


Code: [Select]
              /* printf("Welcome to Windows 3.1");    */
               /* printf("Welcome to Windows 3.11");   */
               /* printf("Welcome to Windows 95");     */
               /* printf("Welcome to Windows NT 3.0"); */
               /* printf("Welcome to Windows 98");     */
               /* printf("Welcome to Windows NT 4.0"); */
               printf("Welcome to Windows 2000");
[/B]


I don't know whether to:
:lol:
or
:wtf:
Title: Disconnect your network cables, hide in the bunkers...
Post by: Skippy on February 13, 2004, 09:36:37 am
Quote
Originally posted by Beowulf


I don't know whether to:
:lol:
or
:wtf:


Let's use :lol:  ;)
Title: Disconnect your network cables, hide in the bunkers...
Post by: Corsair on February 13, 2004, 09:36:46 am
Balls. :shaking:
Title: Disconnect your network cables, hide in the bunkers...
Post by: kasperl on February 13, 2004, 09:37:32 am
oh my god, if that's normal operating procedure, i don't want to know how big that codefile is.
edit: bob, where did you get that, do you have a full copy of the source?
Title: Disconnect your network cables, hide in the bunkers...
Post by: karajorma on February 13, 2004, 11:08:51 am
Quote
Originally posted by Bobboau
for those of you who want to know how closely related XP is to 2000 here is a little snipet from the leaked source


Code: [Select]
              /* printf("Welcome to Windows 3.1");    */
               /* printf("Welcome to Windows 3.11");   */
               /* printf("Welcome to Windows 95");     */
               /* printf("Welcome to Windows NT 3.0"); */
               /* printf("Welcome to Windows 98");     */
               /* printf("Welcome to Windows NT 4.0"); */
               printf("Welcome to Windows 2000");
[/B]


:lol: That is one of the funniest programming things I've seen in a long time :D

From the article I was reading apparently the code expands to around 600MB of data. Given this example they probably only got away with the source code for wordpad! :D

Seriously though this is pretty worrying. 2k and XP share enough code that a lot of exploits will work on both. Even if they don't there are plenty of 2K boxes out there.

Singh does make a good point that very few white hat programmers will admit to having seen the source cause of MS's legal habits.
Title: Disconnect your network cables, hide in the bunkers...
Post by: kasperl on February 13, 2004, 11:12:51 am
so, what we're looking at is that "nobody" as seen "anything" while people who have seen it will primarily use it to do bad, instead of people doing good by releasing patches to stuff the holes. i already see MS sueing someone who emails them a patch for a security hole.
Title: Disconnect your network cables, hide in the bunkers...
Post by: karajorma on February 13, 2004, 11:25:48 am
Exactly. The white hats might detect a flaw in the code, make an exploit for it and then contact MS but by doing so they give the black hats just as much time to make their own version.

MS should realise what a disaster this is and offer rewards for help rather than trying to squash it.

The worst thing is that whole mess wouldn't make MS look any worse if they handle it properly. It's probably not their fault that the code leaked. Sure their OS is full of holes but anyone computer literate already knew that. The computer illiterate may not have known but by pumping up the "stolen code" angle they could have avoided it being seen as their fault.

Instead they're claiming that nothing is wrong which means that they will take the blame when things start to go wrong.

Hopefully though the code will turn out to be part of Word or something else that doesn't access the net and therefore is reasonably safe from hacking exploits.
Title: Disconnect your network cables, hide in the bunkers...
Post by: Martinus on February 13, 2004, 12:49:44 pm
[color=66ff00]Completely hypothetically speaking; if one were to want to get ones hands on a copy of the aforementioned source code what avenue would one procure this fine intellectual™ property™ of Microsoft™™™ from?


[/color]
Title: Disconnect your network cables, hide in the bunkers...
Post by: kasperl on February 13, 2004, 12:53:30 pm
Kara, the problem is IMHO that if anyone says to MS: "look, i saw the source, here's the leak, and here's a complete patch for it." they'd put every bit of legal power they have to sue that person for seeing and editing the code, and creating a work based on it (that patch). therefor, no one, no one at all would dare to tell MS anything. the only thing MS can do now is release the source completely, and into the linux groups as well, and hope that people  are willing enough to help out.
Title: Disconnect your network cables, hide in the bunkers...
Post by: aldo_14 on February 13, 2004, 12:56:15 pm
Ms will probably use it as a reason to upgrade to XP or some crap...and this is after they took something like 200 days to fix a system critical bug!?
Title: Disconnect your network cables, hide in the bunkers...
Post by: Arc on February 13, 2004, 12:57:13 pm
BetaNews is reporting that the source code is part of Win2000 Service Pack 1, the leak came from a company called MainSoft that creates *nix native versions of Windows applications.

http://www.betanews.com/article.php3?sid=1076674118
Title: Disconnect your network cables, hide in the bunkers...
Post by: Liberator on February 13, 2004, 01:00:49 pm
Okay, now we know why XP is a bloated POS.  The entire source code for 2k was admitted to being nearly 40GB.  Umm, I'm thinking nobody could figure it out, and M$ is too apathetic to write new code that does what they want so they just add in on top.  40gb...that's just a little excessive to me.  A full uncompiled distro of Linux slides in at just under 2gb, libraries and all.
Title: Disconnect your network cables, hide in the bunkers...
Post by: kasperl on February 13, 2004, 01:00:59 pm
not a usefull compile, i am not sure what to say about that. it makes it harder to use it for bug fixing, but it doesn't seem to do much in terms of exploit seeking.
Title: Disconnect your network cables, hide in the bunkers...
Post by: an0n on February 13, 2004, 01:56:37 pm
Y'know. They coulda done it on purpose.

This way they get all their holes fixed without having to pay programmers or release Windows as an open-source, free-to-download product.
Title: Disconnect your network cables, hide in the bunkers...
Post by: aldo_14 on February 13, 2004, 02:01:10 pm
Quote
Originally posted by an0n
Y'know. They coulda done it on purpose.

This way they get all their holes fixed without having to pay programmers or release Windows as an open-source, free-to-download product.


They tried something similar before, didn;t they?

  Releasing an 'open source' version of the code to companies  (in exchange for...er...getting to fix the bugs in the code themselves & report the fix to MS).

NB:  I think it actually takes an entire network of computers about 12+ hours to compile Windows....it's the definition of 'bloatware'.
Title: Disconnect your network cables, hide in the bunkers...
Post by: kasperl on February 13, 2004, 02:03:04 pm
40 gigs of source seems a bit large, really. i mean, i know an OS does a lot of stuff, but if linux can do it in 2GB, it seems a bit gigantic.
Title: Disconnect your network cables, hide in the bunkers...
Post by: aldo_14 on February 13, 2004, 02:08:07 pm
Quote
Originally posted by kasperl
40 gigs of source seems a bit large, really. i mean, i know an OS does a lot of stuff, but if linux can do it in 2GB, it seems a bit gigantic.


Odds on that at least 5% of that code is actually completely useless, but it's so undocumented (and probably written by the work experience boy) that nonone can figure out if they can remove it or not.


At a guess

12.5% is probably the random crash routines.

25% is the bug report & id routines.

30% is the faulty security hole routines put in there to make people upgrade

10% is the code to support that stupid arse paperclip which ALWAY FECKING ANNOYS ME!!!!! *cough*

~0.00000000000125% is the error handling code. (currently commented out)
Title: Disconnect your network cables, hide in the bunkers...
Post by: Darkage on February 13, 2004, 02:15:35 pm
*Installs Solaris9 x86*
Title: Disconnect your network cables, hide in the bunkers...
Post by: Stryke 9 on February 13, 2004, 03:04:12 pm
Quote
Originally posted by aldo_14


They tried something similar before, didn;t they?

  Releasing an 'open source' version of the code to companies  (in exchange for...er...getting to fix the bugs in the code themselves & report the fix to MS).


Well, the two do have something to do with each other, though not exactly in that way. Apparently the person it got leaked from is an idiot and left a trail a mile wide. Including a tag MS had left in there specifying the company the OS snippet was loaned to and (I think) the user name.
Title: Disconnect your network cables, hide in the bunkers...
Post by: mikhael on February 13, 2004, 06:25:02 pm
Quote
Originally posted by Darkage
*Installs Solaris9 x86*



Mmmm. Slowlaris X86. It doesn't get much worse than that. ;)
Title: Disconnect your network cables, hide in the bunkers...
Post by: Darkage on February 13, 2004, 06:28:54 pm
Quote
Originally posted by mikhael



Mmmm. Slowlaris X86. It doesn't get much worse than that. ;)



If you can get me a cheap SunBlade or a Sparc station with a software packages then it isn't so bad:D

I never had any problems with it.

I use it at work but there we actualy use Sun Microsystem hardware/software.
Title: Disconnect your network cables, hide in the bunkers...
Post by: diamondgeezer on February 13, 2004, 06:33:55 pm
Quote
Originally posted by an0n
Y'know. They coulda done it on purpose.

This way they get all their holes fixed without having to pay programmers or release Windows as an open-source, free-to-download product.

I'd have said that if they'd have had Longhorn or whatever it is ready to launch
Title: Disconnect your network cables, hide in the bunkers...
Post by: aldo_14 on February 13, 2004, 06:38:07 pm
Quote
Originally posted by mikhael



Mmmm. Slowlaris X86. It doesn't get much worse than that. ;)


It's probably the only Os I've used that slows down to a crawl when more then one netscape window is open........  there's actually an semi-inquest going in our Cs department as to why the JVM (in aprticular) is so god-damn slow on the Solaris boxes.....
Title: Disconnect your network cables, hide in the bunkers...
Post by: Darkage on February 13, 2004, 06:46:26 pm
hmmm...we don't have that problem. Weird
Title: Disconnect your network cables, hide in the bunkers...
Post by: aldo_14 on February 13, 2004, 06:52:23 pm
Quote
Originally posted by Darkage
hmmm...we don't have that problem. Weird


Yup... that seems to be the consensus, based on what one of the lab assistants said.
Title: Disconnect your network cables, hide in the bunkers...
Post by: Darkage on February 13, 2004, 06:57:36 pm
We use allot of sparct statiosn. Moslty Ultra 5/10 and 60 boxes. We do also use some SunBlades. All put into a network not to big around 50 systems.

Did they offer a patch or other sollution for that problem?
Title: Disconnect your network cables, hide in the bunkers...
Post by: aldo_14 on February 13, 2004, 07:02:08 pm
Quote
Originally posted by Darkage
We use allot of sparct statiosn. Moslty Ultra 5/10 and 60 boxes. We do also use some SunBlades. All put into a network not to big around 50 systems.

Did they offer a patch or other sollution for that problem?


I have no idea what they're doing about it - if anything.  

All I know is that it got mentioned during a lab session, because the mobile agent system we were using was screwing up in new and inexplicable ways.
Title: Disconnect your network cables, hide in the bunkers...
Post by: Sandwich on February 14, 2004, 04:28:23 am
You know, while Windows has plenty of security holes, the main way of hackers exploiting those holes is through executable files on their target's computer. To do that, they need to get an executable up and running on said computer, a task which is normally accomplished through a virus. And while there are of course many ways in which viruses can spread, I'd hazard a guesstimate that about 70-90% spread through vulnerabilities in Internet Explorer (which is the basis for the Outlook Express and Outlook email rendering engines).

The solution? Use Mozilla (or Opera - does it have a mail client though?). I remember many many virus-infected email I received in the Mozilla mail client - for the most part I could even view the email without any worries that the virus would self-execute. Not that that's a good idea mind you, but still... it's to prove the point that while your car may have a 40-gallon gas tank, all that gas needs to enter through the one little opening. Make sure that opening is secure, and you've secured the whole system.
Title: Disconnect your network cables, hide in the bunkers...
Post by: HotSnoJ on February 14, 2004, 09:35:48 am
@sandwich
Yes, Opera has a simple email client built in. BUT it's pretty crappy, so you wouldn't want to use it anyway.
Title: Disconnect your network cables, hide in the bunkers...
Post by: karajorma on February 14, 2004, 10:27:55 am
Quote
Originally posted by kasperl
Kara, the problem is IMHO that if anyone says to MS: "look, i saw the source, here's the leak, and here's a complete patch for it." they'd put every bit of legal power they have to sue that person for seeing and editing the code, and creating a work based on it (that patch). therefor, no one, no one at all would dare to tell MS anything. the only thing MS can do now is release the source completely, and into the linux groups as well, and hope that people  are willing enough to help out.


That's what I meant.  As a result any white hat programmers will have to make an actual exploit and claim to MS that they came up with it independant of the source before they'll feel safe to go to MS. Then they'll have to wait for MS to find the dodgy piece of code in the source (something the white hat already knew) and fix it.

All in all an incredibly stupid turn of events.
Title: Disconnect your network cables, hide in the bunkers...
Post by: mikhael on February 15, 2004, 01:39:38 am
Quote
Originally posted by Darkage



If you can get me a cheap SunBlade or a Sparc station with a software packages then it isn't so bad:D

I never had any problems with it.

I use it at work but there we actualy use Sun Microsystem hardware/software.


Should have said something while I still worked at Cisco. I threw out more working Sparc stations than I can count, and a couple of sunblades and sunrays (dumb terminals for connecting to sunblades) and we had just ditched all our 2.8 licenses for 2.9.
Title: Disconnect your network cables, hide in the bunkers...
Post by: Darkage on February 15, 2004, 06:49:28 am
damn i could have used one of those stations.:)
Title: Disconnect your network cables, hide in the bunkers...
Post by: Sandwich on February 18, 2004, 04:28:53 pm
http://www.theregister.co.uk/content/55/35611.html
Title: Disconnect your network cables, hide in the bunkers...
Post by: aldo_14 on February 18, 2004, 04:40:47 pm
I think i may downgrade to win 98................
Title: Disconnect your network cables, hide in the bunkers...
Post by: karajorma on February 18, 2004, 05:50:25 pm
I'm uddenly glad that I swapped over to Mozilla FireFox and Thunderbird earlier in the week. Won't cut out everything but a lot of exploits are going to be aimed at IE and Outlook Express.
Title: Disconnect your network cables, hide in the bunkers...
Post by: HotSnoJ on February 18, 2004, 06:35:10 pm
Quote
Originally posted by karajorma
I'm uddenly glad that I swapped over to Mozilla FireFox and Thunderbird earlier in the week. Won't cut out everything but a lot of exploits are going to be aimed at IE and Outlook Express.
me too, though I'm just about to install thunderbird.