Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Busting the Worm Writers
Tim Mullen, 2003-11-24

Microsoft deserves praise for offering a cash reward to catch people who criminally exploit their bugs.

Comments Mode:
Busting the Worm Writers 2003-11-24
dlEEb (1 replies)
If you truly believe that statement -software always will have security problems - then you indeed make a good shill for MacroSleeze. Software tends to have 'bugs' (design criteria for error s/b "MINIMIZE", not done in M$ case...), and old-timers know to keep patch-level current for a given release ...

[ more ]  [ reply ]
Busting the Worm Writers 2003-11-29
jarhead
I truly can not believe that there are still people out there that think M$ deserves to be defended. M$ releases a product that is not up to the standard and then expect to be excused. "people should fix there own proplems" that is what the people that attack M$ are doing forcing M$ to fix there pro...

[ more ]  [ reply ]
Hats Off To Mullen 2003-11-24
MULLET HEAD (1 replies)
Got to hand it to the guy...he's always writing about stale news after stitching together everyone else's prior comments, opinions and editorials. What is it with the guy...is he unable to come up with anything original?

Oh and his pro-MS template is throughout his stale writings

1. Anything ...

[ more ]  [ reply ]
Hats Off To Mullen 2003-11-25
Anonymous (2 replies)
Not nearly as boring as having you basically cut and paste the same crap you posted on his last article. Looks like it is the same 4 people who post here. Penguinistolistocrapo is next for sure. I just can't wait.

...

[ more ]  [ reply ]
Hats Off To Mullen 2003-11-25
Anonymous
LOL - he was too! So predictable......

[ more ]  [ reply ]
Hi, Sweetheart! 2003-11-25
Penguinisto (1 replies)
Nice to see that I occupy so much of your limited time and faculties.

Just to let you know, I'd already responded further on down. Now... you have something constructive or useful to add, or are you just here for the bile? ;)

/P...

[ more ]  [ reply ]
Oh my... 2003-11-28
Anonymous (1 replies)
Penguin,

What is it with you calling everyone a "Sweetheart", is there something about yourself that you would like to divulge to the group? Something you would like to get out in the open? Something out of the 'closet' maybe?...

[ more ]  [ reply ]
Why yes, yes there is. 2003-11-28
Penguinisto (1 replies)
I want you to have my children. You know you dream of it... come, make it your reality.

XOXO.
(and ROTFLMAO...)

/P...

[ more ]  [ reply ]
Why yes, yes there is. 2003-12-03
Anonymous
/me runs....

[ more ]  [ reply ]
Busting the Worm Writers 2003-11-24
Anonymous
Nice article, I agree with many of your points. All software is buggy, this is true. I however do not think 5million dollars is nessecary. Cut that figure in half and hire 50-100 people to audit code all day. :/...

[ more ]  [ reply ]
Busting the Worm Writers 2003-11-24
Anonymous (1 replies)
(posted here since it was rejected when i attempted to post it to the mailing list)

Please.

I am still a conspiracy theorist on this one, I think Microsoft released this worm to the wild.

Take a hard look at it. This exploit gave *full admin access* to *any* NT4, W2K, or XP machine connect...

[ more ]  [ reply ]
Busting the Worm Writers 2003-11-25
Anonymous
Are you sure it wasn't Santa Clause who released it? Maybe it was the Easter Bunny, or even the Tooth Fairy.

You should follow those routes: I think you are really on to something. ...

[ more ]  [ reply ]
Busting the Worm Writers 2003-11-24
Anonymous
It cheaper the fixing them. They just gave up. Now I really think my server are SECURE(sic)!!! Now the only way a system will get patch for abug when we get broken into and data compromised.

...

[ more ]  [ reply ]
Busting the Worm Writers - Hmmmmm 2003-11-24
Terry
For his 2c worth I'd give Tim M. $5 dollars to take up another profession..... Maybe it would be better for MS to offer £1000 for every "confidential" bug reported with a possible fix - That?s 250 fixes in the bag and those that exploit might like the income....

:)
...

[ more ]  [ reply ]
Busting the Worm Writers 2003-11-24
Anonymous (1 replies)
This article does not address why Microsoft stil has a plethora of bugs and holes and they have been in this state for years. This appears to be a weak attempt at spin control that the writer of this article has bought into....

[ more ]  [ reply ]
Busting the Worm Writers 2003-11-25
Anonymous (1 replies)
Sure he does- it was in the part about "all software having bugs" or whatever. Linux has a plethora of bugs. So does everything that is actually used by people (just in case there is some OpenBSD troll in the group). ...

[ more ]  [ reply ]
Remote vs. local exploits 2003-11-26
Anonymous
I expect bugs, but Windows seems to have far more remotely exploitable bugs than any other OS. Sure, Linux has a lot of local DoS and privilage-escalation bugs, but who actually gives people shell access these days?

Currently there are several holes in IE that rogue websites are using to infec...

[ more ]  [ reply ]
Busting the Worm Writers 2003-11-24
Anonymous
Not the first time a "vendor" has put up cash to ferret out something.

Daniel J. Bernstein the author / vendor of qmail put up a cash reward in 1997 (of $500 granted) that is still open today for anyone that can find a "verifiable security hole in the latest version of qmail". QMail is still at ...

[ more ]  [ reply ]
Life... anyone!? 2003-11-25
Anonymous (3 replies)
I just hope the author is reading these lines!


I've been following your articles for a while, and what I clearly understand is the following:

Either youre paid damn well to jump "eyes wide shut" style into the IT world, shooting harsh airheaded statements, or youre really stupid (the "...sec...

[ more ]  [ reply ]
Life... anyone!? 2003-11-25
Anonymous
Hmm. Actually it was posts like this that I thought of when I read the abused housewife analogy. Bet this is how you talk to beginners on "other OS" lists. One of the causes of security problems is arrogant know it alls, that is probably why many more non-MS systems have been hijacked for DDoS attac...

[ more ]  [ reply ]
Life... anyone!? 2003-11-25
Anonymous
Looks like you won't dare to use a spell-checker either. These are the typical, ignorant responses I have grown accustomed to in comments posted to Mr. Mullen's articles.

Any time he says something positive toward Microsoft, he is charged with being bribed for his opinion. Any time he defends so...

[ more ]  [ reply ]
Life... anyone!? 2003-11-26
Stefan (1 replies)
> I wouldn't dare to mention Microsoft,
> security and my name at the same sentanse!

That would sound more intelligent if you spelled "sentence" properly. Somehow I suspect Microsoft Security doesn't want to be associated with you either, so it's at least it's a mutual thing.


> Imagine ...

[ more ]  [ reply ]
Life... anyone!? 2003-11-26
Anonymous (1 replies)
" Isn't that what happened to all those Linux servers when the "Slapper" worm came out?"

No more than 15,000 hosts at any one time were hit with the Slapper worm at its height : http://www.f-secure.com/slapper/

OTOH, How many IIS boxes were taken down (including the ones at Microsoft.com) du...

[ more ]  [ reply ]
Life... anyone!? 2003-11-27
Stefan (1 replies)
> No more than 15,000 hosts at any one
> time were hit with the Slapper worm at
> its height :
> http://www.f-secure.com/slapper/

Don't change the subject. The topic was CLEARLY about whether the patch was released before or after the worm. I correctly stated that's *NEVER* happened with M...

[ more ]  [ reply ]
Life... anyone!? 2003-11-28
Anonymous
" Don't change the subject."

You brought up 'slapper' as your big defense, and I merely slapped it down (geddit? "slapped"? tee hee hee... I kill me sometimes!)

"I correctly stated that's *NEVER* happened with Microsoft, and it *has* happened with other O/S makers."

Other OS makers want to ...

[ more ]  [ reply ]
Typical Responses 2003-11-25
John Carroll (4 replies)
If you say Microsoft is doing anything remotely right, then you are automatically a shill, or confused, or failing to acknowledge reality, or something along those lines.

I wonder if in a few years, when people wake up with a Microsoft OS that DOESN'T get hit by viruses (the result of that securi...

[ more ]  [ reply ]
Typical Responses 2003-11-25
Penguinisto
"I wonder if in a few years, when people wake up with a Microsoft OS that DOESN'T get hit by viruses..."

Good question. I honestly hope that happens some day. (assuming they don't muck it up with DRM and enough bloat to make the by-then Pentium 8's scream in overloaded agony ;) )

Okay, okay......

[ more ]  [ reply ]
Typical Responses 2003-11-25
Anonymous
Well said. ...

[ more ]  [ reply ]
Typical Responses 2003-11-26
Oregon
John it must be sad to live in the same world of smoke and mirrors at little Timmy there. Wake up and smell the coffee, MS did so some things good in the computer age but most importantly they burnt out the home user with their "...this next upgrade will fix the past" game, people are just not fall...

[ more ]  [ reply ]
I'll believe it when I see it... 2003-11-26
Anonymous
"I wonder if in a few years, when people wake up with a Microsoft OS that DOESN'T get hit by viruses (the result of that security initiative which IS generating results), will the naysayers know what to do with themselves?"

I'll believe it when I see it. The fact that many of the same bugs seem ...

[ more ]  [ reply ]
abused housewife 2003-11-25
aeonflux
Ahh yes Tim, lets forgive Microsoft again. You're constant never ending bypass is unveiled yet again. People like you are a little like battered domestic house wifes. Maybe next year, bill gates wont beat you.... stay with him.... maybe next year......

Yes there's a place for microsoft, and m...

[ more ]  [ reply ]
Actually, it's a semi-good idea, but will it work? 2003-11-25
Penguinisto
You seem kinda paranoid lately, Timster...

Personally, I think it's about time Microsoft started owning up to the mess it inadvertantly helped to create. It does have some benefits (if they'd up it to $500K they may get further, but it's a start.)

I can see a small bit of opportunity for abus...

[ more ]  [ reply ]
Busting the Worm Writers 2003-11-25
AF
Tim,

When you wake up in the morning, look in the mirror and say "I love you man, I care about you, everything's going to be OK"

...

[ more ]  [ reply ]
Busting the Worm Writers 2003-11-26
Anonymous
Mate,
Internet security is not a Microsoft problem. It is not a Linux problem. It is a people problem.

Well spoken.
...

[ more ]  [ reply ]
Busting the Worm Writers 2003-11-26
Pee
Busting kids writing abit of code? does it seem right to you either?, ok they are criminals so what, you give a locksmith a padlock with packaging "the most secure padlock in the world" and expect him not to try and pick it, NO.

They are missing the point they are trying to convict 10-20 year old...

[ more ]  [ reply ]
Busting the Worm Writers 2003-11-26
Rob McQuillen
I think the reason this move is condemned is because it's a bad approach, and a poor solution, to the problem.

Paying people to catch worm authors isn't going to make the problem go away. Worms are not created because of bad software, but they are made possible by bad software.

If you buy a ho...

[ more ]  [ reply ]
How old is Mullen? 2003-11-27
Please do not use HTML in your replies. HTML tags will be filtered. (1 replies)
Does anyone know? This article, like all his others reads like a high school paper. Good thing securityfocus.com isn't a subscription service. I'd rather go and buy drugs with my money....

[ more ]  [ reply ]
How old is Mullen? 2003-11-28
JHC (1 replies)
I think his columns are excellent. In fact, I look forward to them.

Posts like yours do little for anyone. You have not even discussed the topic, and are simply wasting space.

Further, the monthly "I can't believe Security Focus prints this" posts like this have the reverse effect than you...

[ more ]  [ reply ]
How old is Mullen? 2003-11-28
Captain Kirk hahaha (1 replies)
Aye JHC that's the rub laddie. We come to learn and do oor job then we read the Mullen Wisdom's from start to finish and we find its KRUP.

By the way how auld are you if you think tisn't KRUP....

[ more ]  [ reply ]
How old is Mullen? 2003-11-28
JHC
Sounds more like Scotty than Kirk. I'm old enought to know that.

Oh, and you forgot the "I know you are but what am I" comment. ...

[ more ]  [ reply ]
Busting the Worm Writers 2003-12-01
Michal
M$ should give these rewards to people who find bugs in their software, not to informers -traitors. This way M$ will become IT police soon. And who would like Bill to be a policeman...?...

[ more ]  [ reply ]
Busting the Worm Writers 2003-12-02
Rihards
I think Tim just wanted to say that MS is changing and that our old thinking - Smoking is bad, drugs are bad, MS is bad - this has to be left in past. Ja, there are problems with big "P", but things are changing and if they do we must change our attitude. MS IS TRYING. So, lets try we too. What to t...

[ more ]  [ reply ]
Is Mullen Looking for a Job at Microsoft? 2003-12-03
Matthew Murphy
Tim,

I used to read your articles for their technical content. That is a habit I have broken. More often than not, I find myself reading them because of how incredibly humorous said reading turns out to be.

Stating that security vulnerabilities are a fact of life is a far more shallow assump...

[ more ]  [ reply ]







 

Privacy Statement
Copyright 2009, SecurityFocus