ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Could stolen Microsoft code lead to more security mishaps?

Will Knight ZDNet.co.uk

Published: 27 Oct 2000 15:07 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Computer security experts are concerned that the possible theft of Microsoft source code may lead to widespread security problems with its software, if malicious crackers gain access to key hidden features.

Experts say it is possible that access to the source code could allow crackers to develop new techniques for attacking computer systems using Microsoft software.

"The biggest and best hacks right now are buffer overflows," says Dr Neil Barrett, senior security analyst with security firm IRM. "These are hard if you don't have source code but if you've got access to code it is going to be extremely easy to do."

A buffer overflow allows a malicious user to work around the inherent security of a piece of software by sending an unusually large amount of data. This may allow them to execute usually restricted commands or give them access to normally hidden data on an operating system.

Antivirus vendors are also concerned that access to source code could give virus-writers the upper hand. "If they did get the source code, chances are that they could make a virus with more stealth capabilities," says Sal Viveros, director of marketing for Network Associates in the UK.

Ironically, Microsoft has often defended its decision not make source code publicly available on the grounds that this would make it more vulnerable, a policy dubbed "security by obscurity". Others, particularly those behind the increasingly popular open source Linux operating system argue precisely the opposite. They claim that openness and peer review are key to maintaining the security of a piece of software.

Microsoft says it is examining every file in the compromised area and is also examining the source code of a number of applications including Windows Me, Windows 2000, Outlook, Outlook Express, and Microsoft Office, according to a report in the Wall Street Journal.

Although details surrounding the theft of data from Microsoft remain sketchy, Microsoft's UK director of corporate marketing Shaun Orpen says the company is confident its source code has not been compromised. "You don't leave the intellectual property of a company lying around on a network," he says. "It will have been secured. We feel comfortable with the security in place," he says.

The hackers, however, had access to Microsoft's network for a month. Even if the source code was encrypted, says Barrett, there may have been plenty of opportunity to capture it in plain text in this time.

The hackers are thought to have used a Trojan horse program known as QAZ to capture and send network passwords to an email address in St Petersburg, Russia. Microsoft initially investigated the breach itself but then decided to bring in the FBI.

Statements made by Microsoft directors saying that "of course" all their important data was secure have all the reassuring comfort of statements by John Selwyn Gummer about the hamburger he fed his daughter. Guy Kewney simply doesn't believe the people at Microsoft when they say that no damage was done to their corporate secrets. Go to AnchorDesk UK for the news comment.

To have your say online click on the TalkBack button and go to the ZDNet News forum.

Let the editors know what you think in the Mailroom. And read what others have said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
49 out of 104 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:









Related Jobs

Senior Software Engineer

Accelrys combines experience and intellectual property developed during 25 years of serving research organisations with modeling and simulation, ...

C++ Venture for great developers 30,000-35,000 North West

My client is seeking a C++, GUI, multi-threading, openGL, MFC, Qt, motion capture, CAD VR, 3D graphics experience? My client works with motion ...

C# ASP.NET DEVELOPER - AGENCY - LONDON - 40K

It exists to design and develop software products and services that provide commercial benefit to RICS by monetising intellectual property assets or ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment