犬者
“说了你又不听,听又不懂,懂又不做,做又做错,错又不认,认又不改,改又不服,不服也不说,那叫我怎么办?!”

【电脑】Microsoft Says Parts of Source Code Were Leaked

By Brian Krebs
Special to The Washington Post

Friday, February 13, 2004; Page E01

Microsoft Corp. last night confirmed that portions of the source code for two versions of its Windows operating system have leaked onto the Internet, a security breach that could give hackers important intelligence about how to exploit flaws in software run by many of the world's computers.

"Today we became aware that incomplete portions of Windows 2000 and NT 4.0 source code was illegally made available on the Internet," Microsoft spokesman Tom Pilla said. "It's illegal for third parties to post Microsoft source code and we take that activity very seriously."

Pilla said the company does not know how much of the code was compromised, but he said Microsoft believes it was not a complete version of either operating system. There was no indication of a breach in Microsoft's internal network, Pilla said. He said the FBI is investigating.

Windows 2000 and NT are widely deployed in business networks; less so on home computers.

Computer security experts said the release of Windows source code could pose a threat to Internet security, depending on what portion of the code was leaked.

A leak of any portion "could dramatically increase the probability that new zero-day vulnerabilities will be found," said Alan Paller, director of research at the SANS Institute, a security training group based in Bethesda.

"Zero day" attacks exploit a security vulnerability before or at the same time a software maker learns of the flaw.

Thor Larholm, senior security researcher at Newport Beach, Calif.-based PivX Solutions, said the Windows source code file being traded on the Internet appears to be roughly 660 megabytes in size, about one CD-ROM's worth of data. That is far short of the estimated 40 gigabytes of data that make up the entire Windows code.

But even a partial leak "is a potentially very serious problem for Microsoft," Larholm said. "Just look at the vulnerabilities that are discovered by people who didn't have access to the source code."

Howard Schmidt, former head of security at Microsoft, said he was less concerned about the security implications of the leak than its potential threat to Microsoft's intellectual property.

"From a security standpoint, this is sort of like capturing a 1956 Russian fighter jet," said Schmidt, now chief security officer at online auction giant eBay. "Everyone has been beating on Windows 2000 and NT for a long time, and any flaws that may be found have likely been fixed long ago. Frankly, I'd be more worried that someone was going to use this as a base for developing software or another operating system based on Microsoft's proprietary code."

The Redmond, Wash.-based software giant closely guards the Windows source code but does license portions of it to security researchers and more than 50 universities under its "Shared Source Initiative."

Microsoft, in a competitive strike against the rival Linux operating system, last year said it would began sharing large portions of the source code with governments around the world that want to validate the security of the software before deploying it in national defense and other sensitive areas.

Unlike open-source software like Linux, the code comprising Windows is not open for public inspection. Linux users are encouraged to participate in an open, continuous cycle of modifications and upgrades that its proponents say results in systems that are more secure and reliable than those powered by proprietary code like Windows.

Brian Krebs is a reporter for washingtonpost.com. Staff writers Mike Musgrove and Jonathan Krim contributed to this report.

827
问天 @2/13/2004 1:38:41 PM
View blogs in this category:电脑


boko 在 2/13/2004 3:40:03 PM 说:

不开放源代码用户好过不了,可是开放了企业有没钱赚,矛盾矛盾。什么时候才能由矛盾走向统一呢
boko 在 2/13/2004 3:38:09 PM 说:

现在还没有操作系统能让大家满意的,唉 越琢磨越发现一个道理:一切反动派,哦,错了 是一切操作系统都是纸老虎!
katze 在 2/13/2004 3:20:29 PM 说:

linux where got better? @_@ i dun like linux
无名氏 在 2/13/2004 3:16:55 PM 说:

i think this is actually a fake news, Microsoft just want to get rid of their responsibility on 2000 and NT and ask people to buy XP and 2003
funchoate 在 2/13/2004 3:03:35 PM 说:

什么跟什么嘛。
boko 在 2/13/2004 2:29:38 PM 说:

假惺惺的
Wuvist 在 2/13/2004 2:12:02 PM 说:

“So, Linux is actually better ”--纯粹的臆测。
无名氏 在 2/13/2004 1:50:03 PM 说:

So, Linux is actually better

Please leave your comment here

 
  名字:
  主页:
  内容:
 

   


Navigation
Blogwind
犬者首页
Contact


个人档案


“说了你又不听,听又不懂,懂又不做,做又做错,错又不认,认又不改,改又不服,不服也不说,那叫我怎么办?!”



Categories
死结(27)
电脑(171)
心情(175)
天影(25)
乱弹(204)
博客(80)
音乐(18)
饕餮(30)
读书(19)
电影(27)
网摘(5)
希望(31)
汕头(10)
经济(5)
苹果(19)
跋涉(3)



Archive
2008年8月
2008年7月
2008年6月
2008年5月
2008年4月
2008年3月
2008年2月
2008年1月
2007年12月
2007年11月
2007年10月
2007年9月
2007年8月
2007年7月
2007年6月
2007年5月
2007年4月
2007年3月
2007年2月
2007年1月
2006年12月
2006年11月
2006年10月
2006年9月
2006年8月
2006年7月
2006年6月
2006年5月
2006年4月
2006年3月
2006年2月
2006年1月
2005年12月
2005年11月
2005年10月
2005年9月
2005年8月
2005年7月
2005年6月
2005年5月
2005年4月
2005年3月
2005年2月
2005年1月
2004年12月
2004年11月
2004年10月
2004年9月
2004年8月
2004年7月
2004年6月
2004年5月
2004年4月
2004年3月
2004年2月
2004年1月
2003年12月



My Links
5G
bloglines
时尚摄影师奇科的博客
我们的漫画
颜如玉
最爱卫斯理

RSS 2.0

Username:
Password:
 Remember me