Great Circle Associates Firewalls
(June 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Securing NT Web servers
From: Craig Brozefsky <craig @ onshore . com>
Date: Thu, 26 Jun 1997 20:54:22 -0500
To: Robert Laird <rlaird @ panenergy . com>
Cc: firewalls @ GreatCircle . COM
In-reply-to: <97Jun26 . 155057cdt . 36939 @ igate . panenergy . com>

On Thu, 26 Jun 1997, Robert Laird wrote:

My understanding is not that they were hacked.  Todd Fast exploited the 
long URL bug (a bug, not a backdoor oranything like that) against their 
server and contacted them.  The few days were it seems damned near 
impossible to get to www.microsoft.com was not because horrid hackers had 
keel-hauled all the webmasters and hijacked the machines to server up 
zero day warez.  it was because some poor schmuck at microsoft has set 
the TTL of one of the www.microsoft.com A records to 8 hours, while the 
rest where down to like 6 minutes or something.  So the end result of 
that was that everyone was trying ot go to the same IP address, while the 
other servers just sat idle.

> <snip>
> >understand your risk level with a closed system (i.e., Microsoft
> >didn't even know their risk, and was taken off the 'net for two days
> >last week),
> 
> Where can I get the details (are any available???) on what happened
> to M$ last week?  I mean, I know they were hacked, and I know they
> went off-line, but how did it happen?  
> 
>   -- Robert
> 

Craig Brozefsky              craig @
 onshore .
 com
onShore Inc.                 http://www.onshore.com/~craig
Development Team             p_priority=PFUN+(p_work/4)+(2*p_cash)



References:
Indexed By Date Previous: FWXT_SRC_STATIC and FWXT_DST_STATIC translation of a host across a WAN
From: Ö Kenneth Phang Ö <kent @ dataprep . com . my>
Next: Re: Pulling out Checkpoint-1 firewalls
From: "Marcus J. Ranum" <mjr @ nfr . net>
Indexed By Thread Previous: Re: Securing NT Web servers
From: "John \"E.R.\" Jasen" <jjasen1 @ umbc . edu>
Next: RE: Securing NT Web servers
From: "Webb, Andy" <Andy . Webb @ swinc . com>

Google
 
Search Internet Search www.greatcircle.com