Feeds

MS blocks staff dial-in access after ‘minor’ hack

If you're safe now, why cut off 39,000 employees for the weekend?

  • alert
  • submit to reddit

Remote control for virtualized desktops

According to Microsoft it knew about the hacker's intrusion almost immediately, it tracked the hacker's movements through its network, and it shut down all of the accounts used by the hacker last week. So how come it blocked access to its corporate network for all of its employees, globally, over the weekend?

Since Friday the company has been mounting a determined effort to convince the world that its systems, its software and its source code are secure, and if you take the story according to Microsoft at face value, the threat from the hacker was minor, was finite, and has now passed. A "Microsoft official" quoted in today's Wall Street Journal even went as far as suggesting that the company has detailed information that will help pinch the perpetrator.

So if it's all over bar the arresting, the only reasons for shutting down access must surely be that Microsoft has belatedly concluded that there are - as we suggested yesterday - serious problems with the way it runs its network security. In this context Microsoft's explanation of why it originally said the hacker could have been loose for six weeks, rather than the 12 days it now claims, is significant.

The six week period takes us back to when the corporate email system was taken down because of a virus outbreak, and Microsoft's security team initially feared - so it said - that the two might have been connected. But the real connection is their awareness of the fact that the methods of propagation for both were the same. If Microsoft staff and Microsoft systems are vulnerable to viral email attachments, then they must also be vulnerable to QAZ Trojans intended to break into the network. And besides, under current circumstances there's a high probability of copycat attacks.

Microsoft is clearly beginning a long, hard look at its network security, and Register sources suggest this is not before time. Said one: "MS source control is not very locked down. Pretty much every MS employee can commit to the tree. Which means if you're hacked in and you know this, you can commit your own backdoor code into Windows that might stand a chance of going gold."

This doesn't sound entirely plausible, although the large teams Microsoft has working on code would tend to make it more difficult to police security, and possible easier for rogue code to get through. A tale from Microsoft Germany, however, sounds all too convincing:

"Where I work, I have a colleague who has worked at MS Germany. He once mentioned that he had set up himself a dial-up server with callback in one of the labs there. This server remained active more than a year after he left. To quote: 'Need a new Office - no problem just keep leeching a weekend or so - it's callback, so it's for free.' Of course it was against security-policy (' ...and of course I had turned-off all logging').

"The server was only removed presumably during a full restructuring of the lab, where it was probably found to be superfluous and shut down..."

All companies are of course like this, but as Microsoft is probably the biggest, fattest, most tempting target for hackers, it really can't afford to be like this for much longer. ®

Related Stories:
MS hacked! Russian mafia swipes WinME source?
Redmond strives to cram Great MS Hack back in box

Intelligent flash storage arrays

More from The Register

next story
Nexus 7 fandroids tell of salty taste after sucking on Google's Lollipop
Web giant looking into why version 5.0 of Android is crippling older slabs
Be real, Apple: In-app goodie grab games AREN'T FREE – EU
Cupertino stands down after Euro legal threats
Download alert: Nearly ALL top 100 Android, iOS paid apps hacked
Attack of the Clones? Yeah, but much, much scarier – report
SLURP! Flick your TONGUE around our LOLLIPOP – Google
Android 5 is coming – IF you're lucky enough to have the right gadget
Microsoft: Your Linux Docker containers are now OURS to command
New tool lets admins wrangle Linux apps from Windows
Bada-Bing! Mozilla flips Firefox to YAHOO! for search
Microsoft system will be the default for browser in US until 2020
prev story

Whitepapers

Choosing cloud Backup services
Demystify how you can address your data protection needs in your small- to medium-sized business and select the best online backup service to meet your needs.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Managing SSL certificates with ease
The lack of operational efficiencies and compliance pitfalls associated with poor SSL certificate management, and how the right SSL certificate management tool can help.
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.