Microsoft shuts down online developer store

Microsoft Corp. today acknowledged that it shut down a Web site for an online Microsoft Developers Store last Thursday to look into a possible security vulnerability that could compromise customer information.

The alleged security problem involved a defective script used in the creation of the Web site, according to a posting by a developer at the SecurityFocus.com Web site. The script allegedly had a hole allowing access by an intruder, who could then obtain customer information from the site.

The store is a site used by software developers to download product betas, evaluation kits and other information.

Cesar Cerrudo, the developer from Argentina who posted the report about the alleged flaw on Thursday, said in his post, “I don’t know when they gonna fix it, so don’t put your personal info there until they fix it and you alredy do it humm…it’s your problem :). Hey, Microsoft people, why don’t you test your webapps?”

Cerrudo, reached today by telephone at his home in Parana, said he stumbled upon the security hole while he was shopping on the site for a beta copy of the latest Microsoft Visual Studio software. After he found the alleged flaw, he said he e-mailed Microsoft to notify the company but didn’t get a response after 14 hours.

That’s when he posted a message with SecurityFocus, he said. He still hasn’t heard back from Microsoft, he said.

A message posted by Microsoft on the Web site says the “Microsoft Developer Store is temporarily unavailable.”

A Microsoft spokeswoman said the site was shut down after the company was notified by a list moderator at SecurityFocus of Cerrudo’s posting. The site is hosted by a third-party vendor for Microsoft and isn’t linked to any Web sites on Microsoft’s own network, the spokeswoman said.

The company has been reviewing the post’s claim and is working to see if there are are any problems that need to be fixed, she said. “Microsoft as a company is vigilant about taking reports like this seriously,” the spokeswoman said. She wasn’t sure when the site would go back online.

Charles Kolodgy, an analyst at International Data Corp. in Framingham, Mass., said such security problems are everywhere.

“It just always goes back to the idea that software is complex,” Kolodgy said. “It’s a whole software thing. It’s not just a Microsoft thing. I think these things just continue to show that we need more discipline in the way that software is developed and coded.”

Microsoft Canada Co. in Mississauga, Ont., is at http://www.microsoft.ca/

Would you recommend this article?

Share

Thanks for taking the time to let us know what you think of this article!
We'd love to hear your opinion about this or any other story you read in our publication.


Jim Love, Chief Content Officer, IT World Canada

Featured Download

Featured Articles

Cybersecurity in 2024: Priorities and challenges for Canadian organizations 

By Derek Manky As predictions for 2024 point to the continued expansion...

Survey shows generative AI is a top priority for Canadian corporate leaders.

Leaders are devoting significant budget to generative AI for 2024 Canadian corporate...

Related Tech News

Tech Jobs

Our experienced team of journalists and bloggers bring you engaging in-depth interviews, videos and content targeted to IT professionals and line-of-business executives.

Tech Companies Hiring Right Now