Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

News: Microsoft spreads virus--by accident
Special to ZDNet News ^ | June 14, 2002, 9:20 AM PT | By Robert Lemos

Posted on 06/14/2002 5:22:49 PM PDT by amigatec

By

Robert Lemos


Special to ZDNet News

June 14, 2002, 9:20 AM PT

Microsoft accidentally sent the virulent Nimda worm to South Korean developers when it distributed Korean-language versions of Visual Studio .Net that carried the virus, the company acknowledged Friday.

Microsoft's flagship developer tools picked up the digital pest when a third-party company translated the program into Korean, said Christopher Flores, lead product manager for Visual Studio .Net. Flores stressed that no other foreign-language versions of the program were found to carry the worm, and he said the worm had not actually executed on any developers' systems.

"There have been no recorded infections," Flores said. In fact, he added, it's almost impossible to get the worm to execute on computers with Visual Studio .Net installed.

The infected file is stored in the same location as the help files, Flores said, but it's a file created by Nimda, so the .Net program's help system doesn't know it's there and will never reference--or open--the file. It's unlikely, then, that Nimda would break loose, Flores said.

And if the worm did execute somehow, he said, it couldn't spread to the developer's system because the virus only runs on systems running Internet Explorer 5.5 and lower, and Visual Studio .Net requires version 6.0 of the browser.

"It's extremely unlikely that a developer would ever accidentally get infected by Nimda," said Flores. "They would have to try hard just to run the worm."

Still, the slip up is yet another stain on Microsoft's reputation as the company works to convince the public and the tech community that its products are secure. In a company-wide memo sent last January, Bill Gates trumpeted a " trustworthy computing initiative," calling on Microsoft's employees to put security above all else.

Nimda started infecting computers last September and quickly became an epidemic. However, since October, incidents of the worm have dropped.

The Redmond, Wash.-based software giant released Visual Studio .Net in February, and the Korean version made it to market some 90 days ago, Flores said.

The Korean version of the developer tools picked up Nimda from the third-party "localization" company Microsoft hired to translate the program's help system into Korean. That company had already been infected by Nimda and spread the virus to the help tools, which gained an extra, infected file.

Flores said that under Microsoft's security policy, the company normally scans every file being transferred to the master of a program. But in this case, the company only analyzed files it expected to find. Since the Nimda-infected file had been added by the worm, the company overlooked it.

"We have been (scanning all files) in every one of our geographies," Flores said. "There was a loophole in our Korean side that caused us to miss files that we didn't expect to be there."

It wasn't until a Microsoft employee was adding the help documentation to the software giant's developer Web site that the worm was found. "We have to go through a conversion process to an online HTML format," said Flores. "During that process we found an extra file hanging around."

Microsoft has notified all its registered Korean customers, and the company posted a patch to its Web site Thursday night. It also plans to send clean copies of the program to every registered customer free of charge and is attempting to contact developers who may have bought the product but not registered it.




TOPICS: Business/Economy; Front Page News; Technical
KEYWORDS: hehehehe; microsoft; nimda; techindex
Navigation: use the links below to view more comments.
first 1-2021-4041-52 next last
This is nice instead of waiting to get another MS virus, MS now supplies for you. Some "trustworthy computing"
1 posted on 06/14/2002 5:22:49 PM PDT by amigatec
[ Post Reply | Private Reply | View Replies]

To: Bush2000; Don Joe; Dominic Harr; innocentbystander

And a big ol' ping to you all!!!


2 posted on 06/14/2002 5:25:36 PM PDT by amigatec
[ Post Reply | Private Reply | To 1 | View Replies]

To: amigatec
unbelievable bump sheeeeeeeesh what is the next microsoftflub?
3 posted on 06/14/2002 5:27:58 PM PDT by TaRaRaBoomDeAyGoreLostToday!
[ Post Reply | Private Reply | To 1 | View Replies]

To: amigatec
Ah yes...pinging the "PC" Hatfields and the "Mac" Coys. You will find me in the bomb shelter.
4 posted on 06/14/2002 5:32:07 PM PDT by tubebender
[ Post Reply | Private Reply | To 2 | View Replies]

To: tubebender
Ah yes...pinging the "PC" Hatfields and the "Mac" Coys.


5 posted on 06/14/2002 5:34:15 PM PDT by steve-b
[ Post Reply | Private Reply | To 4 | View Replies]

To: amigatec
I thought "Virus Free" meant "contains no viruses", not "virus included at no extra charge".
6 posted on 06/14/2002 5:35:39 PM PDT by steve-b
[ Post Reply | Private Reply | To 1 | View Replies]

To: amigatec;Tech_index
I'm getting mighty tired of Microsuck screwups.

I don't care if Bill Gates is richer than the Aga Khan. I don't care if he has more money than any 5 countries picked at random.

I purely hate the software he puts out.

Worse, since everyone else (99%) is using this obscene software I have to use it for file compatability.

Is there any other supplier that produces good software with Microsuck file compatability?

7 posted on 06/14/2002 5:41:34 PM PDT by LibKill
[ Post Reply | Private Reply | To 1 | View Replies]

Comment #8 Removed by Moderator

To: amigatec
Flores stressed that no other foreign-language versions of the program were found to carry the worm, and he said the worm had not actually executed on any developers' systems.

Whooooo, boy. Korean version. Nobody was affected. Care for any cheese with your whine? Weak.
9 posted on 06/14/2002 5:52:12 PM PDT by Bush2000
[ Post Reply | Private Reply | To 1 | View Replies]

To: LibKill
I purely hate the software he puts out.

Yeah, we can tell: Hate is the mind-killer.
10 posted on 06/14/2002 5:53:11 PM PDT by Bush2000
[ Post Reply | Private Reply | To 7 | View Replies]

To: Bush2000
Did you just get off the phone with Bill?

Is he still trying to some way to worm out of this one. I thought according to MS only GPL software sent out patches with Virus's in them?

This is what he has been telling the world.

11 posted on 06/14/2002 5:56:38 PM PDT by amigatec
[ Post Reply | Private Reply | To 9 | View Replies]

To: Bush2000
Whooooo, boy. Korean version. Nobody was affected. Care for any cheese with your whine? Weak.

Could have been the English Version.

It just happened to be the Korean Version.

12 posted on 06/14/2002 5:58:26 PM PDT by amigatec
[ Post Reply | Private Reply | To 9 | View Replies]

To: amigatec
I would suggest that Windows itself is a computer virus.
13 posted on 06/14/2002 5:58:27 PM PDT by magellan
[ Post Reply | Private Reply | To 1 | View Replies]

To: Bush2000
Yeah, we can tell: Hate is the mind-killer.

Bzzzzzzt! Wrong!

Re-read the 'Dune' series by Frank Herbert.

Fear is the mind-killer.

14 posted on 06/14/2002 6:01:47 PM PDT by LibKill
[ Post Reply | Private Reply | To 10 | View Replies]

To: amigatec
Did you just get off the phone with Bill?

Don't know the man. You?

Is he still trying to some way to worm out of this one. I thought according to MS only GPL software sent out patches with Virus's in them? This is what he has been telling the world.

Where did you read this? Reference, please.
15 posted on 06/14/2002 6:11:56 PM PDT by Bush2000
[ Post Reply | Private Reply | To 11 | View Replies]

To: LibKill
Bzzzzzzt! Wrong! Re-read the 'Dune' series by Frank Herbert. Fear is the mind-killer.

And you wonder why Linux is doomed to always live in the server rooms with the geeks. You guys can't even make the mental leap from fear to hate.
16 posted on 06/14/2002 6:14:29 PM PDT by Bush2000
[ Post Reply | Private Reply | To 14 | View Replies]

To: amigatec
Could have been the English Version.

Ah, but it wasn't.

It just happened to be the Korean Version.

When was the last time you booted up the Korean version of Visual Studio or IIS? Don't you have anything better to do than troll over this? This is weaaaaaaaaaaaaak...
17 posted on 06/14/2002 6:15:49 PM PDT by Bush2000
[ Post Reply | Private Reply | To 12 | View Replies]

To: libkill
ya gotta admit, his posts are pretty witty. :)
18 posted on 06/14/2002 6:17:36 PM PDT by RedBloodedAmerican
[ Post Reply | Private Reply | To 16 | View Replies]

To: Bush2000
And you wonder why Linux is doomed to always live in the server rooms with the geeks. You guys can't even make the mental leap from fear to hate.

Give me good software that does what I tell it to do, AND, file compatability with Microsuck.

There will be one more Linux geek. :)

19 posted on 06/14/2002 6:18:33 PM PDT by LibKill
[ Post Reply | Private Reply | To 16 | View Replies]

To: LibKill
Give me good software that does what I tell it to do, AND, file compatability with Microsuck.

Don't you have spell checkers under Linux? Or haven't you progressed the point of learning to use one?
20 posted on 06/14/2002 6:25:54 PM PDT by Bush2000
[ Post Reply | Private Reply | To 19 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-52 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson