Security Issue Found



After having been in contact with Microsoft Support in various countries,
both by mail and phone, what I was told to do is to post here.

Given that a few prerequisites are in place, I'm able to grant myself
access to data that I'm explicitly denied access to. No big surprise, this
is not the way it is supposed to be. I desperately want to get in touch
with someone working with security issues in Microsoft, as I do NOT want
the details to go public. But, before that happens, I have to thoughs:

- Why do I either have to pay and open a support case to report security
issues, or (even worse)
- Go public on this newsgroup?

I would strongly suggest that Microsoft make some "slightly" easier way to
report security issues with their software. I'm SO close to go public with
all the detials first, since it's so troublesome to report issues directly
to Microsoft.

Well, that's all for now.

--
Ole Kristian Bangås
MCT, MCDBA, MCDST, MCSE:Security, MCSE:Messaging
.



Relevant Pages

  • Re: Security Issue Found
    ... > After having been in contact with Microsoft Support in various countries, ... > access to data that I'm explicitly denied access to. ... > report security issues with their software. ...
    (microsoft.public.sqlserver.security)
  • Re: Import/Export Message
    ... Microsoft support, huh? ... assistance related to using Microsoft products and services. ... Its great for synchronizing befween computers. ... >>> no messages in the folder or folder is in use by another ...
    (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
  • Re: C00D11CD
    ... This isn't Microsoft support. ... You don't get answer directly from Microsoft ... Nero Burning ROM ... download to fix it, we might as well just get Real Player and go on with our ...
    (microsoft.public.windowsmedia.player)
  • Re: Workstations Already Deployed w/o Sysprep and w/ Novell Client
    ... something else were to happen down the line, would Microsoft support the ... workstations via disk duplication without using SYSPREP. ... Will Microsoft support instance of XP where the Novell Netware ...
    (microsoft.public.windowsxp.setup_deployment)
  • Re: no 64 bit upgrade support
    ... I do agree that Microsoft documentation has always been and continues to be an abject lesson in how NOT to deliver useful information to a non-technical audience. ... The last time I paid for Microsoft support it was because an early version of Excel kept yielding a simple mathematical error. ... simply the way it is for a company that considers individual users the icing on the cake for their main customer base in the business realm. ... Consider the Apple pretense that there are not serious structural problems with an OS that is patched more often than Vista. ...
    (microsoft.public.windows.vista.installation_setup)