Click to See Complete Forum and Search --> : explaination of the micro$oft incident..


Fandelem
10-31-2000, 07:40 PM
I'm going to grab some quotes.. if someone could explain them better..

(article I'm looking at: http://www.cnn.com/2000/TECH/computing/10/30/microsoft.hackers.ap/index.html )

okay.. the article starts out with this:

"A hacker had high-level access to Microsoft Corp.'s computer system for 12 days -- not up to five weeks, as the company had first reported -- and was monitored the entire time."

If they monitored it the entire time, then why wouldn't they stop it immediately?


The company was alerted to the break-in by the creation of new accounts giving users access to parts of Microsoft's computer network, Miller said. "We start seeing these new accounts being created, but that could be an anomaly of the system," Miller said. "After a day or two, we realized it was someone hacking into the system."

does this normally take this long to realize that someone might be hacking your system? if you were the admin (esp. managing a huge network like that), and noticed accounts were being created, wouldn't you want to make that a pretty high priority to check it out?

okay.. here is the kicker for this article:

If any attempts to download or transfer the source code were made, such activity was not recorded in Microsoft's logs, Miller said, adding that it is extremely unlikely any source code files were copied because of their immense size.

okay.. first off.. I have always been told that you can cover your tracks.. if their system was compromised, couldn't the hacker just delete their entries in the logfiles? I would think if someone could actually hack microsoft, they would at least have the intelligence to cover their tracks, no? and then that the fact that just because they were large files, assuming people wouldn't copy them, is preposterous.. at the very least, couldn't they view it, select all, then copy it to a file on their computer? microsoft has always bragged about how they can withstand DoS's because of their huge bandwidth.. if that's the case, I would think that downloading the file wouldn't be a problem..


Miller acknowledged the hacker could have been in the system for longer than 12 days, but he said the company is confident that high-level access occurred only between October 14 and October 25.

Isn't 12 days of "high-level access" enough to get virtually anything you want? I read Lance's security pages and I saw that a hacker got root in under 90 seconds! 12 days?!?


heh, any explanations on any of the italicized comments would be appreciated :}

Undernined
11-01-2000, 06:33 AM
my theory is the this breakin coinsides with the anouncement of the U.S. to equip it's new naval units with PCs running microsoft OS's. Or maybe not but they did say the the emails were traced to St. Petersburg. Maybe the members of the outfit that has replaced the KGB teamed up with the russian mob to gain access and breach the U.S. naval deffences? Yah right! Damn script kiddies. they ruin it for all the rest of us. They don't care about hacking for the good of man, and making information public. the just think it cool to breakin to someone's computer and cause mayham. They got something to prove some they ruin it for those of fus who just would like to know as much about everything as we can. If it turns out to be so form of military esponage it should be a wake up call to thee world the anyone can be hacked. If it is just some shmo with a computer that did it for malishous reasons I hope that the FBI eather arrests him/her or gives them a job. I'd like to hear others views on this topic. Feel free to reply to me with you comments. I'm real interested in how other view these events. And I'd like to point out I don't think that they got the source for windows. It's to big of a mess for even MS to deal wih, I don't think others would have much luck sorting through all that code trying to find a security hole. Besides it's not like you need the source to find holes in it. People find hole on a daily basis, they readily aparent to just about anyone who knows what to look for. And the number of people who know what to look for increases each day. If that is good of bad is up to how MS accepts criticism. If they lie and try to downplay flaws they get exploited. If MS would admit that it isn't almight I think more people would be willing to work towards making windows a much better OS. It would be more like the way people help to further GNU/Linux. If something is found to be wrong with some software on a linux machine people are willing gto try to help each other to fix it because we all have to live with it. I don't think that this is just cause the software is opensource in nature, but because if something is wrong it is acknowledged and fixed, as apposed to being denighed and lied about and pached in a service pack in the case of microsoft. I think that windows is a good OS, but along the way MS lost sight of what mattered. Yes money is important, but if something is worthwile to buy you'll still get money for it, most likily more so than if it is force opon us who can't use another OS for whatever reason. The fact that opensource is free doesn't mean that people wont pay for your work. And the fact that you hve to pay for closedsource doesn't mean that people will pay for it eather. We let MS get to were it is, and now that windows sucks we blame MS. It isn't their fault that they saw a chance to make ton's of money. We let them gain control of the market and now we whine that they are evil. We could have made MS a better company for us by helping instead of always complaining. I don't think that we should complain unless we have tried to help. GNU/Liunx has the potential to change to way we interact wiht technology but it also has the potential to become a big let down. Don't let money get in the way of making Linux the OS that could and not the OS the should. if we all help alittle it will get done!

Yeah I know, this post should be in with the other rants, but I saugh an opportunity and ran with it. tell me what you think.

conflict is a good thing, it helps to strengthen ones views and phocus on what must be done to agree.

This post is made possible by a grant of to much coffie and to little sleep, a combination that should not be taken for granted.

ille_pugil42
11-01-2000, 08:57 AM
There are multiple posts regarding this in the rants