Full Disclosure mailing list archives
Re: alert: the 111111 bug
From: Valdis.Kletnieks () vt edu
Date: Tue, 05 Jul 2005 00:59:53 -0400
On Mon, 04 Jul 2005 00:03:02 BST, lsi said:
I noticed one of my customers using the "special" date of 11/11/11 in their database.
*yawn*. IBM mainframe systems coded expiration dates on the machine-readable volume labels on tapes in a YYDDD format. One popular tape management system from the late 80s and early 90s assigned special meaning to 98000 and 99000. Somehow, things didn't go bonkers when 1998 or 1999 started. Of *bigger* concern is that of all the Y2K mitigation work done 5 years ago, up to 70% didn't actually widen the data fields to 4-digit years, but instead modified the code to use "windowing": "If NN < 30 then year = 20NN else year equals 19NN". Of course, some programs used 30, some 40, some 45, and so on, so there's lots of little disasters waiting to go boom every 5 or 10 years for the next half-century. Ob-Security: The clever attacker can probably figure out how to use this to make the bank think an account was opened 101 years ago, and collect the interest, or similar hacks based on causing an over/underflow. The first batch of windowed programs should be ripening in about 4.5 years. :)
Attachment:
_bin
Description:
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Re: alert: the 111111 bug, (continued)
- Re: alert: the 111111 bug Paul Schmehl (Jul 03)
- RE: alert: the 111111 bug Larry Seltzer (Jul 04)
- Re: alert: the 111111 bug Thomas Binder (Jul 04)
- Re: Re: alert: the 111111 bug Gabriel Moutinho (Jul 04)
- Re: Re: alert: the 111111 bug Paul Kurczaba (Jul 04)
- Re: Re: alert: the 111111 bug Ron DuFresne (Jul 06)
- Re: alert: the 111111 bug Ron DuFresne (Jul 06)
- Re: alert: the 111111 bug Paul Schmehl (Jul 06)
- Re: alert: the 111111 bug Steve Friedl (Jul 06)
- Re: alert: the 111111 bug Paul Schmehl (Jul 03)
- RE: alert: the 111111 bug Aditya Deshmukh (Jul 04)
- Re: alert: the 111111 bug Valdis . Kletnieks (Jul 04)
- Re: alert: the 111111 bug mbs (Jul 05)
- Re: alert: the 111111 bug Ron DuFresne (Jul 06)