Re: Security Issue Found



Ole,

I've worked with the security team on issues very much
like what you describe, and they are real professionals.

The URL Dan posted is the right one.  If you don't get
a quick response, refer them to this thread and tell them
that SQL Server MVP's Dan and Steve sent you.  ;)

Since what you describe is similar to an issue that is already
known and public (and on the Microsoft web site), I'll point to
this blog post, which refers to a Microsoft white paper on the topic:

http://sqlservercentral.com/cs/blogs/brian_kelley/archive/2005/11/25/334.aspx

Steve Kass
Drew University


Ole Kristian Bangås wrote:

After having been in contact with Microsoft Support in various countries, both by mail and phone, what I was told to do is to post here.

Given that a few prerequisites are in place, I'm able to grant myself access to data that I'm explicitly denied access to. No big surprise, this is not the way it is supposed to be. I desperately want to get in touch with someone working with security issues in Microsoft, as I do NOT want the details to go public. But, before that happens, I have to thoughs:

- Why do I either have to pay and open a support case to report security issues, or (even worse)
- Go public on this newsgroup?


I would strongly suggest that Microsoft make some "slightly" easier way to report security issues with their software. I'm SO close to go public with all the detials first, since it's so troublesome to report issues directly to Microsoft.

Well, that's all for now.



.



Relevant Pages

  • [NT] Cumulative Security Update for Internet Explorer (MS04-025)
    ... Get your security news from a reliable source. ... * Microsoft Windows NT Workstation 4.0 Service Pack 6a ... Navigation Method Cross-Domain Vulnerability ...
    (Securiteam)
  • SecurityFocus Microsoft Newsletter #75
    ... Microsoft's Internet Security & Acceleration Server with fault-tolerance ... The Microsoft UPnP Vulnerability ... Relevant URL: ...
    (Focus-Microsoft)
  • SecurityFocus Microsoft Newsletter #120
    ... Strengthening Network Security: FREE Guide Network security is a ... MICROSOFT VULNERABILITY SUMMARY ... Microsoft Windows File Protection Signed File Replacement... ... PlatinumFTPServer Information Disclosure Vulnerability ...
    (Focus-Microsoft)
  • Re: A 6% fix from Microsoft Security Bulletin MS03-040 - 828750
    ... Now if the geeks over at Microsoft could get "infected" with some of this ... The Internet is already mind blowing in the way it can bring people ... that creates an unacceptable risk of security compromise and we need to shut ... down all Internet browsing with IE. ...
    (microsoft.public.security)
  • Re: A 6% fix from Microsoft Security Bulletin MS03-040 - 828750
    ... Now if the geeks over at Microsoft could get "infected" with some of this ... The Internet is already mind blowing in the way it can bring people ... that creates an unacceptable risk of security compromise and we need to shut ... down all Internet browsing with IE. ...
    (microsoft.public.security.virus)