All the latest UK technology news, reviews and analysis

'Backdoor' found in Microsoft software

by John Geralds in Silicon Valley

17 Apr 2000

Be the first to comment

  • Tweet this

Microsoft has acknowledged that its engineers substituted certain file names with the phrase, "Netscape engineers are weenies," in some of its internet software.

This 'backdoor' password could allow hackers to gain unauthorised access to potentially thousands of websites using Frontpage 98 extensions. The web authoring software tool requires that special software code, or extensions, be present on the website for the features to be available.

Steve Lipner, manager of Microsoft's security response centre, said the backdoor password is "absolutely against the company's policy", and that the as yet unidentified employees responsible for the backdoor would be sacked.

Microsoft is expected to publish an email bulletin and an advisory statement on its corporate website. The company urged users to delete the computer file, called 'dvssr.dll', which contains the offending code.

Lipner said that although the file is installed on Microsoft internet server software with Frontpage 98 extensions, the problem does not affect internet servers running Windows 2000 or the latest version of its server extension included in Frontpage 2000. He added that Microsoft isolated the problem within a few hours after it was discovered.

There have been no reports of site access through the code, but experts point out the risk was greatest at commercial internet hosting providers, which maintain hundreds or thousands of separate websites for different companies.

The software code was apparently written three years ago near the peak of Microsoft's rivalry with Netscape Communications over versions of the internet browser software.

A security consultant known as 'Rain Forest Puppy' notified Microsoft about the backdoor in an email message last Thursday morning after an employee at ClientLogic contacted him.

A Europe-based employee of ClientLogic, which provides outsourced marketing and fulfilment services to ecommerce companies, discovered the glitch.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

27%

1%

13%

59%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

IT Service Desk Technician

Working within the central Service Desk Team of a well...

GIS Technician

GIS Applications Engineer - circa £35k Excellent opportunity...

Senior C++ Developer x 2 - Embedded C++ Developer

Senior C++ Developer x 2 - Senior C++ Software Engineer...

Information security SOC specialist for world leading organisation

We are actively searching for Information security specialists...

To send to more than one email address, simply separate each address with a comma.