SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Information Architecture >> Service Oriented Architectures

Eight worst Windows flaws of the decade

Eight worst Windows flaws of the decade

By:  Andrew Brandt  On: 06 Oct 2008 For: InfoWorld (U.S.) 

Errors buried in millions of code have steered great corporations and turned the tide of fortunes. It's high time these flaws get the credit they deserve...

June 25, 1998, and June 30, 2008, marked two important milestones in Microsoft's evolution of the Windows OS -- the passing of the torch from Windows 95 to Windows 98, and the less seemly transition from XP to Vista.

In the 3,659 days between, users of Windows have been forced to bear witness to another evolution of sorts: bugs that left Windows open to exploits that appeared almost as fast as you could say, "On the Origin of Species."

Uncovering -- and exploiting -- Windows vulnerabilities has made sport for many and careers for many more .

Entire industries have sprung up to protect Windows users from previously unknown flaws, while malware authors have matured their practices from juvenile pranks to moneymaking criminal enterprises.

Caught in the middle of this never-ending onslaught is the innocent PC user and the besieged IT admin -- you. And though Microsoft and the entire software industry have labored tirelessly to handle zero-day exploits and to develop protocols for reporting potential security problems, we've seen and experienced several colossal security meltdowns thanks to the humble Windows bug.

These errors, buried in millions of lines of code, have steered great corporations and turned the tide of fortunes. It's high time they got the credit they deserve. Here are the worst Windows flaws we've endured since the introduction of Windows 98.

Password "password" would have been more secure

Bug identifier: VCE-2000-0979, MS00-072

Description: Share Level Password vulnerability

Alias: Windows 9x share password bypass

Date published: Oct. 10, 2000

Windows 9x introduced a nifty little concept wherein users could host a password-protected mini file server, aka a share, on their PCs. The idea was simple: Allow users of networked computers to host and share files securely. Only the padlock Microsoft used to lock the door came equipped with a gaping hole that rendered it useless.

"When processing authentication requests for a NetBIOS share, Windows 95/98 would look at the length of the password sent by the attacker and then only compare that number of bytes to the real password," writes vulnerability expert H.D. Moore, who manages the Metasploit Framework project.

Oops. "This let the attack specify a password of zero bytes and gain access to the share," without actually knowing the password at all, Moore explains.

"The real damage," he continues, "was that by trying all characters of incrementing lengths, they could literally obtain the password for share from the server."

Upshot: Rather than functioning as a lock on a door, the password authentication scheme for Windows 95/98's File and Print Sharing acted more like a nail through a hasp -- to open the door you only needed to pull out the nail, with hardly any effort.


Sign up for our Newsletters












Print |  Views: 1588   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Andrew Brandt Andrew Brandt is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

No patch for Excel zero-day flaw next week
No patch for Excel zero-day flaw next weekMicrosoft will deliver three critical security patches on Tuesday but there's still no fix for Excel vulnerability being exploited by attackers now
Microsoft gets short on security update
Microsoft gets short on security updateIt's that time of the month again as Microsoft gets ready to issue November's monthly security update, which fixes known flaws in the company's Windows operating system. Don't be surprised, however, if the list of security updates is unusually short this time around.
Microsoft leaves 98 to the hackers
Microsoft leaves 98 to the hackersMicrosoft Corp. has defended its decision not to patch a critical security flaw in Windows 98. Support for the operating system officially ends next month on July 12. The vulnerability exists in Windows Explorer and the way it handles Component Object Model objects, whereby a malicious Web site could force a connection to a remote server where Explorer could fail, executing arbitrary code and giving the attacker complete control of the OS.
The Conficker conflaguration
three months is a pathetic response time for pretty much every business issue, but it’s particularly pathetic when you’re talking about an issue that could cripple your employee’s ability to work at all. and yet, as the conficker/downadup worm continues to wreak havoc across enterprise it networks, security researchers are saying that many firms still haven’t deployed the patch microsof

Comments (0)

No Comments!
Name: (required) eMail: (optional)

Your email address will not appear online and will be used only if the editor wishes to contact you personally for additional comments.