ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Application development Toolkit

Flaw found in MS security patch

Margaret Kane CNet

Published: 14 Feb 2002 15:04 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A flaw in a software tool just released by Microsoft could lead software developers to inadvertently write programs that are vulnerable to attack, according to security specialists who discovered the flaw.

The security problem is said to lie with the compiler that accompanies the new Visual C++.Net, just one of several tools included in Visual Studio.Net that Microsoft shipped on Wednesday. Visual Studio.Net comprises new versions of the company's software development tools, including Visual Basic, Visual C++ and its new Java-like language, C#.

Software security company Cigital says the compiler contains a flaw that would allow a type of attack called a "buffer overflow" to be initiated. A compiler is software that translate the code that programmers write into the language that computers understand.

Ironically, Microsoft may have created the flaw in trying to stop another type of security risk. That risk involves buffer overflows, which allow a specially formatted command to cause a computer to crash or execute arbitrary or malicious code.

"There's this place called a stack where you keep track of which function calls which (other) function. The stack holds all sorts of information (such as) local variables and pointers to places," said Gary McGraw, chief technology officer at Cigital, which discovered the problem. "A buffer overflow is a way of causing the return of address, where the program is going to go, after a subroutine is finished, to go to an attacker code."

Microsoft could not immediately be reached for comment.

Since the software was just released, it is unlikely that it presents a serious problem right now, McGraw said.

"This is pretty complicated -- it's not easy for people to do -- but this is a flaw in a tool meant to produce software," McGraw said. "If (developers) rely on this security feature, they will have a false sense of security.

As yet, there have been no reports of problems from developers. Although the tool bundle was released on Wednesday, Microsoft said that more than 3.5 million developers had beta test copies of Visual Studio.Net. It was the largest beta test program in Microsoft's history.

In its attempt to prevent a buffer-overflow attack, Microsoft apparently adopted a technology known as StackGuard, which is used in the open source community to produce compilers that are resistant to such attacks, McGraw said.

But StackGuard itself has vulnerabilities, which McGraw said had been detailed in a hacker magazine.

The news comes as Microsoft has made a highly public effort to step up security in its programs. After the software giant suffered a series of embarrassing security problems, chairman Bill Gates sent a memo to all employees last month announcing a new "trustworthy computing" initiative that sets security as the "highest priority" for the company.

Adding the new feature to the compiler program was supposed to help developers using the software make their own software safer.

Cigital had been considered for participation in a review of Microsoft's .Net security technology but was not selected, leading some to speculate that Cigital publicised the flaw out of spite.

"(That is) completely, totally unrelated," McGraw said. "We do software security work for many, many firms that produce software all over the world. We talk to lots of people about doing work. There's nothing special about this situation."

The security company had programmers' best interests at heart, McGraw said. "All we're trying to do is tell people, 'Don't use this security feature, don't depend on it. Write the code properly, design it properly, test it properly and don't count on the compiler to magically add security for you.'"


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
71 out of 124 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

C# App. Dev./Visual Studio 2005,C++,SQL/Leicester/30000-40000

Technologies:C#, C++ Visual Basic 2005 SQL Server 2005 Ideal Background: C#, C++, Visual Basic 2005 and SQL server 2005 are essential for the role. ...

Senior VC++ Software Engineer - MFC / Visual Studio/ SQL - Basingstoke

Senior Software Engineers - C++ using Microsoft Visual Studio and MFC. Key technical skills will include strong skills in C++ using Microsoft Visual ...

C#, ASP.NET, Visual Studio, Web Services - Oxford

C#, .NET 2.0, ASP.NET, Visual Studio, Web Services, XML & SQL Server 2005 My client requires a software developer who has strong skills in C#, .NET ...

Featured Talkback

The fact is: Software developers today are really designers and not coders. The reason that business anlaysts exist today to model solutions is because they understand the value of designing software before writing it. All too often developers create code that has little value because they do not understand that business classes interact with other classes within the confines of a working model or pattern.

By: 1000165269

Read full story:
Making sense of agile modelling