Neoseeker : News : Was the WMF security hole a deliberate backdoor?
Hardware Newsletter:
Email:

Latest News
Tue, Nov 18
Mon, Nov 17
Sun, Nov 16
Sat, Nov 15
Fri, Nov 14
Thu, Nov 13

send article hardware newsletter   article comments (2)

Was the WMF security hole a deliberate backdoor?
William Henning - Friday, January 13th, 2006 | 11:11AM (PT)


Was it intentional? A way to let those in the know to run code?

Funny, I never saw "***NOW INCLUDES BACKDOOR FOR FREE!!!***" on windows packages.

Slashdot is running a story with a transcript of an interview with Steve Gibson, where Steve alleges that the recent vulnerability has to be deliberate. A summary of his reasoning is:

- WMF meta files do not need a Escape/SETABORTPROC call back hook meant for printer drivers

- in order for the vulnerability to be exploited, not only do you have to use a command that does not make sense for downloadable graphics metafile, you have to use it with an illegal length '1' that must be used to flag it to invoke the code

For all we know, it was a backdoor put in by a summer intern - however most of you do not know that I am also a software architect / systems analyst, and it boggles my mind to think that such a code path would escape code review.

There would literally have to be some code in windows something like the following pesudo code:

while (metafile_not_done) {

    switch (metafile[COMMAND_CODE]) {

         case SETABORTPROC:

              if (metafile[length] == 1)

                   CreateThread(&(metafile[length]+1),.........);

                   break;

     }

}

That is NOT something that would have survived one of my code reviews, nor can it be explained as an accidental bug.

The two likeliest explanations are those suggested by Steve:

- someone at Microsoft added it without managements approval and it slipped thru the cracks

- it was deliberately added by Microsoft as a back door for itself - honestly, I don't know why they would bother, Windows Update could be used to execute code on your machine any time it checked for fixes

Food for thought.

  Related Stories

back to news    comments or corrections
- This news story is archived and is closed to comments now -

Comments:

January 16th, 2006 12:15PM(PT)
Ace
January 18th, 2006 12:42PM(PT)
bhenning
Thanks Ace, I figured MS would not bother with a backdoor like this.

- This news story is archived and is closed to new comments now -

  RSS Feeds

Latest Comments
Most Comments

Latest Net Reviews:
Latest Inhouse:


Compare Prices

Motherboards
 Abit
 ASUS
 Gigabyte
 Intel
 iWill
 Shuttle
 Soyo
 Super Micro
 Tyan
 More...

Processors
 AMD
 Intel
 More...

Memory
 SDRAM
 RDRAM
 DDRAM
 More...

Video Cards
 ATI
 Visiontek
 PNY
 3Dfx
 More...

search for lowest prices
(0.2142/d/aeon)