Skip the navigation

Secret Windows code leaked on Internet

Microsoft downplayed any potential security concerns from the leak

By Joris Evers
February 13, 2004 12:00 PM ET

IDG News Service - Microsoft Corp. confirmed late yesterday that some of the secret code underlying its Windows NT and Windows 2000 operating systems has been leaked on the Internet. The company played down any potential security concerns the leak might cause.
Incomplete portions of Windows NT and Windows 2000 source code were "illegally made available on the Internet," Microsoft spokesman Tom Pilla said. Microsoft has no information on the source of the leak and has called in the FBI.
There is no indication that the leak was the result of any breach of the Microsoft corporate network or the company's internal security, Pilla said. Also, "at this point in time there is no known impact to customers," he said.
Source code is raw code in the form of readable lines of text, usually with comments. It can be compiled into code that can run but can't be read. The Windows code on users' PCs is all compiled code.
A breach of the operating systems' source code -- a mix of assembler, C and C++ code -- could expose users to an increase in cyberattacks because it would make it easier for hackers to find holes in the operating systems that they can exploit. It would also mean that Microsoft's closely guarded intellectual property is now out in the open, said Joe Wilcox, a Washington-based Jupiter Research senior analyst.
Those who say they have downloaded the source code claim to have a 200MB compressed file that expands into roughly 600MB of code. Microsoft officials told industry analysts that this is roughly correct and that it represents about 15% of Windows source code.
Wilcox said a much greater percentage of the Windows code may have leaked. "It was my understanding that Windows 2000 was about 35 million lines of code." People who have seen the leaked code say it contains about 13.5 million lines.
The code leak could lead to a host of new attacks on systems running Windows 2000 and Windows NT, said Thor Larholm, a senior security researcher at PivX Solutions LLC, in Newport Beach, Calif.
"Depending on what particular code was leaked, I would say this has a lot of potential for new security vulnerabilities. The next weeks to come will confirm whether we see a rise in exploits," he said.

But Rob Enderle, principal analyst at Enderle Group in San Jose, said that with the amount of Windows code already available through various Microsoft programs, the security implications are limited. "A release of source code on the Web is more embarrassing in these days of open-source then it is damaging," he said.
Microsoft enthusiast Web sites earlier yesterday reported that the code was leaked and had the software maker scrambling to investigate the reports. The source code of the two operating systems was rumored to be available on a peer-to-peer file-sharing network as well as on Internet Relay Chat.
Yesterday afternoon, discussion sites and mailing lists were abuzz with talk about the leak. Some sites offered screenshots or directly posted parts of what is said to be the source code.
IDG News Service was shown Web pages that appear to contain a directory listing of the packages of Windows 2000 and Windows NT source code. Experts said the listings represent source code for network protocols, parts of Internet Explorer, certificate handling and the Windows kernel. Microsoft declined to confirm if that is correct.
Windows 2000 and Windows NT are older Microsoft products but are still widely used. The products also formed the basis of the current Windows XP operating system.
In one posting on the Web site Slashdot.org, someone using the handle "Monkelectric" asked if the leak could be a ploy by Microsoft to get users to upgrade from Windows NT and Windows 2000 to newer operating systems in order to avoid an onslaught of security breaches. Other posters joked about Windows having gone open-source.
This is not the first time that Microsoft has faced a leak of its source code. In 2000, it confirmed that outsiders had accessed some of the code underlying a version of Windows as well as Office.
The company has offered controlled access to some of its source code through a program called the Shared Source Initiative. The program is meant for enterprise users, academics and others.




Reprinted with permission from IDG.net. Story copyright 2010 International Data Group. All rights reserved.
Additional Resources
Forrester Consulting - Optimizing Users and Applications in a Mobile World
WHITE PAPER
Solving application issues over the WAN requires careful consideration. Based on their independent research, Forrester Consulting offers recommendations on how to tackle application performance issues, insufficient bandwidth and the inability to quickly restore users in a disaster.

Read now.

Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Windows White Papers
VMware View Optimization Guide for Windows 7
This document provides guidelines for configuring a standard Windows 7 image to be used within a VMware View™ environment, providing administrators with the...
Microsoft Volume Licensing Comparison - Small/Med. Business
This quick-reference document lets small and medium organizations (i.e. those with five or more devices) to easily compare the available Microsoft Volume Licensing...
Microsoft Volume Licensing Comparison - Enterprise
With this quick-reference document, you can easily compare the available Microsoft Volume Licensing programs for enterprise organizations with 250+ devices, and tailor a...
Microsoft Open Value Program Guide
In this overview, see how Microsoft Open Value provides a flexible, affordable way for small to midsize organizations (i.e. those with five or...
HP Software Licensing & Management Solutions for Microsoft
See how HP Software Licensing & Management Solutions (SLMS) can help you identify the best Microsoft licensing program for your needs, get the...
All Windows White Papers
Windows Webcasts
Optimizing Networks for the Cloud
Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
Virtualize Business-Critical Applications with Confidence
Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®...
All Windows Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs