Windows 2000 source code posted online

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS
Microsoft is investigating how a file containing some protected source code to Windows 2000 was posted to several underground sites and chat rooms.

A spokesman said late on Thursday that incomplete portions of Windows 2000 and Windows NT were illegally posted to the Internet.

"It's illegal for third parties to post Microsoft source code," spokesman Tom Pilla said. "We obviously take that very seriously."

Microsoft said it is investigating how the code got on the Internet and is working with law enforcement. "We will take all appropriate legal actions as we move forward with the investigation," Pilla said.

Pilla said that the company has no indication that the posting was a result of someone breaching Microsoft's corporate network, and said at this point there should be no impact on customers. As for the long-term security impact, Pilla noted that "this is not buildable or executable code... nor is it the complete source code."

The 203MB file contains code from Microsoft's enterprise operating system, but the code was clearly incomplete, said Dragos Ruiu, a security consultant and the organiser of the CanSecWest security conference, who has examined the file listing.

"It was on the peer-to-peer networks and IRC [Internet relay chat] today," Ruiu said. "Everybody has got it; it's widespread now."

The 203MB file expands to just under 660MB, he said, noting that the final code size almost perfectly matches the capacity of a typical CD-ROM. The entire source code, he said, is believed to be about 40GB, meaning that the file circulating on Thursday contains only a fraction of the full code base.

"It looks real," he said. "You can't build Windows, however. It's just a bunch of chunks of the operating system."

Microsoft said it is looking into claims that file traders were swapping its proprietary source code.

Earlier on Thursday, a source located a file purporting to be the code on a Web site, but the file was removed from the Internet before it could be completely downloaded.

The releases of the source code created a buzz on the Internet but also worried some security experts.

"It's definitely not a good thing if black hats have the source code," said Oliver Friedrichs, senior manager with antivirus company Symantec's security response centre. "The underground can look at the code without legitimate security researchers being able to find vulnerabilities first."

But Microsoft downplayed any security issue.

In its statement, the company said that the main concern is the potential theft of its handiwork rather than the possible security threat that such a leak might pose.

"If a small section of Windows source code were to be available, it would be a matter of intellectual property rights rather than security," Microsoft said.

Microsoft zealously guards the source code to the various versions of its Windows operating system, sharing it only with universities and government agencies that sign agreements not to release the code. While working versions of Microsoft's operating system have occasionally leaked on to the Internet, actual source code leaks have been rare.

Although Microsoft chairman Bill Gates has publicly bragged about the security of Windows, even Microsoft fears the release of its code. In testimony during the Microsoft antitrust trial, Jim Allchin, the company's senior vice president for Windows, said opening up the company's source code could be devastating for the operating system's security.

"The more [that] creators of viruses know about how antivirus mechanisms in Windows operating systems work, the easier it will be to create viruses or disable or destroy those mechanisms," Allchin testified during a May 2002 antitrust trial.

Allchin made the statements while defending the company against legal remedies supported by nine states that would have compelled Microsoft to give away the source code to Internet Explorer.

Allchin's fears are not misplaced, said Thor Larholm, senior security researcher with security consultancy PiVX Solutions.

"Just look at the amount of vulnerabilities that are discovered without the source code," he said. "The majority of Windows servers are still running Windows 2000. Furthermore, Windows 2000 has a lot of shared code that is still being used by Windows XP and Windows Server 2003."

However, other security experts believe that fears about a leak leading to the widespread discovery of vulnerabilities in the code are misplaced.

"Theoretically, to a good reverse engineer, all code is open source," said a Microsoft security consultant who asked not to be identified. He added that the size of the compressed file that was being passed around the Internet sounded about right.

In the end, however, the mistake that made Microsoft's code public might result in benefits similar to open-source code, Ruiu said.

"Short term, there might be problem [as bugs are found], but long term it might be good for them," he said. "Their code might become more secure."

CNET News.com's Ina Fried contributed to this report.

Talkback

I guess this means that code will be returned back to the people it was stolen from

human knowledge belongs to the world! (Antiturst 2000)

via Facebook 13 February, 2004 10:54
Reply

Time for the Linux revolution! The source is open - take shelter, MS victims!

via Facebook 13 February, 2004 13:35
Reply

I don't think this is a "managed leak" by Microsoft, but consequently and certainly it pushes users of Win2K or NT into upgrading their current OSes to Win2K3 Server.

via Facebook 14 February, 2004 08:43
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Freebies202

Duplicate comments are not made intentionally. Its very good to know that now you are keeping check on this problem because sometimes a commenter...

43 minutes ago by Freebies202 on Microsoft fixes blog comments, speeds up blogs with open source
kevinmchapman

"the very significant number of users" and "many (most) of us" - you have no evidence for these statements. It is a fact that most users are saying...

9 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
Marg Menzies Harrison

Another grammar faux pas is the improper use of "you". When sitting down down in a restaurant, for example, I get cringe when the waitress...

10 hours ago by Marg Menzies Harrison via Facebook on 10 flagrant grammar mistakes that make you look stupid
zdnetukuser

And NOW, folks, for Canonical's next trick... Kubuntu is late. Here's a pencil. Draw your own conclusions. cf.:...

11 hours ago by zdnetukuser on Linux Minterface
Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

13 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

14 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

16 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

16 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

16 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

17 hours ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

19 hours ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

1 day ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

1 day ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

1 day ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

1 day ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

1 day ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

1 day ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

1 day ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint