Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Busting the Worm Writers
Tim Mullen, 2003-11-24

Microsoft deserves praise for offering a cash reward to catch people who criminally exploit their bugs.

Comments Mode:
Busting the Worm Writers 2003-11-24
dlEEb (1 replies)
Busting the Worm Writers 2003-11-29
jarhead
Hats Off To Mullen 2003-11-24
MULLET HEAD (1 replies)
Hats Off To Mullen 2003-11-25
Anonymous (2 replies)
Hats Off To Mullen 2003-11-25
Anonymous
Hi, Sweetheart! 2003-11-25
Penguinisto (1 replies)
Oh my... 2003-11-28
Anonymous (1 replies)
Why yes, yes there is. 2003-11-28
Penguinisto (1 replies)
Why yes, yes there is. 2003-12-03
Anonymous
Busting the Worm Writers 2003-11-24
Anonymous
Busting the Worm Writers 2003-11-24
Anonymous (1 replies)
(posted here since it was rejected when i attempted to post it to the mailing list)

Please.

I am still a conspiracy theorist on this one, I think Microsoft released this worm to the wild.

Take a hard look at it. This exploit gave *full admin access* to *any* NT4, W2K, or XP machine connected to the internet without a decent firewall. You could delete user accounts, rename user accounts, delete files, you name it
- you could do it with this exploit.

Imagine what would happen if a worm was released that used a RNG to change the administrator account name and password on 500,000 windows machines.

Imagine what would happen if a worm was released that deleted *.doc, *.xls, *.mdb, and *.txt from every location imaginable. Or hell, how about %systemroot%\*.*?

This exploit could have been a disaster to Microsoft, and they knew it...so they fixed it.

How do you cover up such a thing? Why, attack yourself! Yes! We'll make a time-delayed DDoS on "windowsupdate.com", it will get a few days of strong publicity, and all we'll have to do is remove a DNS record!

Either MS released this, or a 12 year old did. Someone who was serious about this would have done more than a crappy attempt at a DDoS on windowsupdate.com. Yes, they broke the RPC service on XP boxes...but since that wasn't intentional, it doesn't count. I'm still curious why the RPC service is set to reboot the computer on failure instead of just restarting the service. But hey, whatever.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/199/23839#23839
Busting the Worm Writers 2003-11-25
Anonymous
Busting the Worm Writers 2003-11-24
Anonymous
Busting the Worm Writers 2003-11-24
Anonymous (1 replies)
Busting the Worm Writers 2003-11-25
Anonymous (1 replies)
Remote vs. local exploits 2003-11-26
Anonymous
Busting the Worm Writers 2003-11-24
Anonymous
Life... anyone!? 2003-11-25
Anonymous (3 replies)
Life... anyone!? 2003-11-25
Anonymous
Life... anyone!? 2003-11-25
Anonymous
Life... anyone!? 2003-11-26
Stefan (1 replies)
Life... anyone!? 2003-11-26
Anonymous (1 replies)
Life... anyone!? 2003-11-27
Stefan (1 replies)
Life... anyone!? 2003-11-28
Anonymous
Typical Responses 2003-11-25
John Carroll (4 replies)
Typical Responses 2003-11-25
Penguinisto
Typical Responses 2003-11-25
Anonymous
Typical Responses 2003-11-26
Oregon
I'll believe it when I see it... 2003-11-26
Anonymous
abused housewife 2003-11-25
aeonflux
Busting the Worm Writers 2003-11-26
Anonymous
Busting the Worm Writers 2003-11-26
Pee
Busting the Worm Writers 2003-11-26
Rob McQuillen
How old is Mullen? 2003-11-27
Please do not use HTML in your replies. HTML tags will be filtered. (1 replies)
How old is Mullen? 2003-11-28
JHC (1 replies)
How old is Mullen? 2003-11-28
Captain Kirk hahaha (1 replies)
How old is Mullen? 2003-11-28
JHC
Busting the Worm Writers 2003-12-01
Michal
Busting the Worm Writers 2003-12-02
Rihards







 

Privacy Statement
Copyright 2009, SecurityFocus