<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel> 

	<title>Comments on: Comments on 7084</title>
	<link>http://www.metafilter.com/7084//</link>
	<description>Comments on MetaFilter post Comments on 7084</description>
	<pubDate>Wed, 18 Apr 2001 08:56:20 -0800</pubDate>
	<lastBuildDate>Wed, 18 Apr 2001 08:56:20 -0800</lastBuildDate>
	<language>en-us</language>
	<docs>http://blogs.law.harvard.edu/tech/rss</docs>
	<ttl>60</ttl>

	<item>
		<title>Post number 7084</title>
		<link>http://www.metafilter.com/7084/</link>	
		<description>&lt;a href="http://dailynews.yahoo.com/h/cn/20010417/tc/simple_attack_hurts_microsoft_server_product_1.html"&gt;Bring down MeFi in one easy step.&lt;/a&gt; Matt, does this affect you?</description>
		<guid isPermaLink="false">post:www.metafilter.com,2001:site.7084</guid>
		<pubDate>Wed, 18 Apr 2001 08:51:32 -0800</pubDate>
		<dc:creator>redleaf</dc:creator>		<category>brokenlink</category>		<category>win2k</category>		<category>exploit</category>
	</item>	<item>
		<title>By: starvingartist</title>
		<link>http://www.metafilter.com/7084/#70165</link>	
		<description>&lt;i&gt;An attacker can take advantage of the vulnerability by sending the server a request to view a Web page with an unusually large address--for example, one with the letter A repeated 3,000 times, SecureXpert Labs said. Sending such a request will prevent the ISA software from letting computers inside its network view outside Web pages or letting outside computers view inside pages.&lt;/i&gt;&lt;br&gt;
Is it just me, or does it seem vaguely irresponsible to actually explain how to make this attack work in the article?  How many bored people with a penchant for anarchy are going to try this now, before the patch is sufficiently implemented around the net?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.7084-70165</guid>
		<pubDate>Wed, 18 Apr 2001 08:56:20 -0800</pubDate>
		<dc:creator>starvingartist</dc:creator>
	</item>	<item>
		<title>By: redleaf</title>
		<link>http://www.metafilter.com/7084/#70172</link>	
		<description>When I first read that my thought was what site do I know running Win2k that I could test this out on? Then my conscious kicked in.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.7084-70172</guid>
		<pubDate>Wed, 18 Apr 2001 09:06:42 -0800</pubDate>
		<dc:creator>redleaf</dc:creator>
	</item>	<item>
		<title>By: PWA_BadBoy</title>
		<link>http://www.metafilter.com/7084/#70174</link>	
		<description>Yes, I often feel the need to hack into websites while in an unconscious state too. 

Sorry for the jab..... I think you meant &quot;conscience.&quot;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.7084-70174</guid>
		<pubDate>Wed, 18 Apr 2001 09:08:32 -0800</pubDate>
		<dc:creator>PWA_BadBoy</dc:creator>
	</item>	<item>
		<title>By: holloway</title>
		<link>http://www.metafilter.com/7084/#70177</link>	
		<description>starvingartist: I prefer exposure as Microsoft have been slack in the past when it comes to patches and hopefully public embaressment spur them on. Really though - I like people considering products other than Microsoft.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.7084-70177</guid>
		<pubDate>Wed, 18 Apr 2001 09:15:19 -0800</pubDate>
		<dc:creator>holloway</dc:creator>
	</item>	<item>
		<title>By: Spanktacular</title>
		<link>http://www.metafilter.com/7084/#70183</link>	
		<description>Starvingartist, if the vulerabilities are not made public, Microsoft has a proven record of not doing anything about them until they *are* made public.  Besides, from what I read in the article, the vulnerability only occurs with NT servers running a particular kind of firewall software.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.7084-70183</guid>
		<pubDate>Wed, 18 Apr 2001 09:31:05 -0800</pubDate>
		<dc:creator>Spanktacular</dc:creator>
	</item>	<item>
		<title>By: starvingartist</title>
		<link>http://www.metafilter.com/7084/#70192</link>	
		<description>Ow!  Ow!  Stop with the beating!  ;-)&lt;br&gt;
Seriously, though.  I don&apos;t have a problem with the article itself.  I agree that M$&apos;s errors should be made public.  I just question the move of giving the general public the knowledge to actually bring down a server.  Granted, this is a very specific attack to a specific server combination, but how does disabling some small company&apos;s server affect Bill in any way?  Isn&apos;t it enough to say &quot;This program has a serious security flaw&quot; and let the L337 hax0rs figure out how to do it?&lt;br&gt;
It seems to me like publishing the recipe for napalm in the name of freedom of the press.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.7084-70192</guid>
		<pubDate>Wed, 18 Apr 2001 09:40:16 -0800</pubDate>
		<dc:creator>starvingartist</dc:creator>
	</item>	<item>
		<title>By: samsara</title>
		<link>http://www.metafilter.com/7084/#70193</link>	
		<description>Am I the only one that notices the strange irony of Microsoft&apos;s Internet Security and Acceleration (&lt;a href=&quot;http://www.sqlmag.com/Articles/Index.cfm?ArticleID=20094&amp;Key=Industry%20News&quot;&gt;ISA&lt;/a&gt;) being the very thing that was so easily hacked?  Or is this just a product that is just three buzz words and a price tag?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.7084-70193</guid>
		<pubDate>Wed, 18 Apr 2001 09:41:58 -0800</pubDate>
		<dc:creator>samsara</dc:creator>
	</item>	<item>
		<title>By: Mocata</title>
		<link>http://www.metafilter.com/7084/#70207</link>	
		<description>Didn&apos;t seem to work for me.  But then I&apos;m an idiot.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.7084-70207</guid>
		<pubDate>Wed, 18 Apr 2001 09:57:53 -0800</pubDate>
		<dc:creator>Mocata</dc:creator>
	</item>	<item>
		<title>By: jammer</title>
		<link>http://www.metafilter.com/7084/#70236</link>	
		<description>Starvingartist, yours is a debate that often goes back and forth in computer security circles; the issue is full disclosure vs. limited disclosure.  With open source software, full disclosure is obviously the better option -- the more people know about the problem, the more someone is likely to be motivated enough to fix it.  

However, the issue is slightly more complex with closed source software, as, no matter who knows about the problem, there is a very small number of people with the ability to fix it.  However, as has been mentioned previously, criMosoft has a track record of not fixing security holes until there&apos;s a widespread public knowledge of the issue.  It&apos;s not worth their time to put out a quality product, otherwise, apparently.

In this case, it could be argued that it&apos;s for the public good to detail these things generally, in order to prompt a more rapid fix.  One way or another, most of the people who *really* could use this information in a negative manner will have it, whether mainstream mags post it or not.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.7084-70236</guid>
		<pubDate>Wed, 18 Apr 2001 10:54:28 -0800</pubDate>
		<dc:creator>jammer</dc:creator>
	</item>	<item>
		<title>By: anildash</title>
		<link>http://www.metafilter.com/7084/#70258</link>	
		<description>ISA has more of a corporate audience, designed not just to be a firewall, but also to cache pages for viewers on an Intranet. It&apos;s not (likely) the sort of thing Matt would have running on a one-server operation like MeFi&apos;s box.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.7084-70258</guid>
		<pubDate>Wed, 18 Apr 2001 11:14:36 -0800</pubDate>
		<dc:creator>anildash</dc:creator>
	</item>	<item>
		<title>By: redleaf</title>
		<link>http://www.metafilter.com/7084/#70265</link>	
		<description>&lt;i&gt;Sorry for the jab..... I think you meant &quot;conscience.&quot;&lt;/i&gt;

Err ya... Doh. Spell check let me down on that one.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.7084-70265</guid>
		<pubDate>Wed, 18 Apr 2001 11:22:49 -0800</pubDate>
		<dc:creator>redleaf</dc:creator>
	</item>	<item>
		<title>By: fooljay</title>
		<link>http://www.metafilter.com/7084/#70267</link>	
		<description>&lt;i&gt;I just question the move of giving the general public the knowledge to actually bring down a server. &lt;/i&gt;

How do you think they found out about it?  Typically, reports come to these security agents from the field (the general public) and they are tested internally, then reported to Microsoft.  Usually M$FT sits on it.  At that point, forced disclosure is the only option.  It&apos;s almost like a bureaucratic process.   &quot;No, sorry.  We can&apos;t devote resources to that.  It&apos;s not public.&quot;  &quot;Oh OK, hey Cnet...&quot;

Besides, there are many &lt;a href=&quot;http://www.google.com/search?q=%22Microsoft+Windows+2000%22+vulnerability&amp;num=50&amp;hl=en&amp;lr=&amp;newwindow=1&amp;safe=off&amp;start=0&amp;sa=N&quot;&gt;other Microsoft vulnerabilties&lt;/a&gt; out there for all the world to see, some even of the &lt;a href=&quot;http://www.google.com/search?num=50&amp;hl=en&amp;lr=&amp;newwindow=1&amp;safe=off&amp;q=%22Microsoft+Windows+2000%22+%22buffer+overrun%22&quot;&gt;same type&lt;/a&gt;.  What makes one more that significant?  

Anyway, most systems which are hacked are not exploited through the latest and greatest, but through some relatively ancient hole that the system administrator was too lazy to patch.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.7084-70267</guid>
		<pubDate>Wed, 18 Apr 2001 11:25:18 -0800</pubDate>
		<dc:creator>fooljay</dc:creator>
	</item>	<item>
		<title>By: willnot</title>
		<link>http://www.metafilter.com/7084/#70269</link>	
		<description>It looks like the linked story left out the &lt;a href=&quot;http://www.microsoft.com/technet/security/bulletin/MS01-021.asp&quot;&gt;important fact&lt;/a&gt; that this only works when the web page request is submitted from inside the network.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.7084-70269</guid>
		<pubDate>Wed, 18 Apr 2001 11:26:15 -0800</pubDate>
		<dc:creator>willnot</dc:creator>
	</item>	<item>
		<title>By: jessamyn</title>
		<link>http://www.metafilter.com/7084/#70471</link>	
		<description>&lt;i&gt;How many bored people with a penchant for anarchy...&lt;/i&gt;

Actually, &lt;a href=http://www.infoshop.org/faq/secA1.html#seca11&gt;anarchists&lt;/a&gt; are really mostly in favor of a system of society without coercive government, where &quot;individuals freely co-operate together as equals&quot; and are rarely bored.

And, apropos of this topic, we&apos;d probably all behave a bit better if our actions were exposed to public scrutiny. Microsoft made this bed, they can lie in it.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.7084-70471</guid>
		<pubDate>Wed, 18 Apr 2001 17:28:41 -0800</pubDate>
		<dc:creator>jessamyn</dc:creator>
	</item>
	</channel>
</rss>
