ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Application development Toolkit

Microsoft spreads virus by accident

Published: 17 Jun 2002 08:45 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft accidentally sent the virulent Nimda worm to South Korean developers when it distributed Korean-language versions of Visual Studio .Net that carried the virus, the company acknowledged on Friday.

Microsoft's flagship developer tools picked up the digital pest when a third-party company translated the program into Korean, said Christopher Flores, lead product manager for Visual Studio .Net. Flores stressed that no other foreign-language versions of the program were found to carry the worm, and he said the worm had not actually executed on any developers' systems.

"There have been no recorded infections," Flores said. In fact, he added, it's almost impossible to get the worm to execute on computers with Visual Studio .Net installed.

The infected file is stored in the same location as the help files, Flores said, but it's a file created by Nimda, so the .Net program's help system doesn't know it's there and will never reference -- or open -- the file. It's unlikely, then, that Nimda would break loose, Flores said.

And if the worm did execute somehow, he said, it couldn't spread to the developer's system because the virus only runs on systems running Internet Explorer 5.5 and lower, and Visual Studio .Net requires version 6.0 of the browser.

"It's extremely unlikely that a developer would ever accidentally get infected by Nimda," said Flores. "They would have to try hard just to run the worm."

Still, the slip up is yet another stain on Microsoft's reputation as the company works to convince the public and the tech community that its products are secure. In a company-wide memo sent last January, Bill Gates trumpeted a "trustworthy computing initiative", calling on Microsoft's employees to put security above all else.

Nimda started infecting computers last September and quickly became an epidemic. However, since October, incidents of the worm have dropped.

The Redmond, Washington-based software giant released Visual Studio .Net in February, and the Korean version made it to market some 90 days ago, Flores said.

The Korean version of the developer tools picked up Nimda from the third-party "localisation" company Microsoft hired to translate the program's help system into Korean. That company had already been infected by Nimda and spread the virus to the help tools, which gained an extra, infected file.

Flores said that under Microsoft's security policy, the company normally scans every file being transferred to the master of a program. But in this case, the company only analysed files it expected to find. Since the Nimda-infected file had been added by the worm, the company overlooked it.

"We have been (scanning all files) in every one of our geographies," Flores said. "There was a loophole in our Korean side that caused us to miss files that we didn't expect to be there."

It wasn't until a Microsoft employee was adding the help documentation to the software giant's developer Web site that the worm was found. "We have to go through a conversion process to an online HTML format," said Flores. "During that process we found an extra file hanging around."

Microsoft has notified all its registered Korean customers, and the company posted a patch to its Web site Thursday night. It also plans to send clean copies of the program to every registered customer free of charge and is attempting to contact developers who may have bought the product but not registered it.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
67 out of 127 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Web Developer - 3 months - Council - South West - 150 per day

The person needs solid skills in ASP, net, C#, Visual Studio, TSQL/SQL Server 2005, HTML/CSS, Web Services / XML. Web Developer required to a council ...

Web Developer, Warwickshire, 28-33k

To apply, you will need experience in Web development using: ASP.net / C# Visual Studio 2005 SQL Server 2005 (T-SQL / Stored Procs) Any experience ...

Asp.Net- Visual Studio Web Developer- City 45k

Technical Skills: Database development and maintenance using SQL Server 2005/2000 Classic asp ASP.Net using Visual Studio 2005 Understanding and ...

Discussions

AdamW AdamW

Linux, Laptops and Dual Displays

Saturday 26 July 2008, 6:34 PM

2 comments
keithmv keithmv

Password Deadlock

Saturday 26 July 2008, 12:02 PM

2 comments

Featured Talkback

The fact is: Software developers today are really designers and not coders. The reason that business anlaysts exist today to model solutions is because they understand the value of designing software before writing it. All too often developers create code that has little value because they do not understand that business classes interact with other classes within the confines of a working model or pattern.

By: 1000165269

Read full story:
Making sense of agile modelling