Vulnerability Development mailing list archives

Re: A code red that could bring down the net?


From: Sven van ´t Veer <sven () vip br>
Date: Thu, 26 Jul 2001 08:49:54 -0300

Although I agree on the funny part, I would suppose that M$ has patched up it´s own servers ..


Actually, a rather nasty thing to do, would have been to set the worm up
to attack www.microsoft.com. If my guess is right, that site uses the same
pipe as support.microsoft.com or windowsupdate.microsoft.com. Had the
person done this, it would have effectly used microsoft's own bug against
it, and would have caused a big problem: how are the people supposed to
obtain the patch if the site holding the patch gets hosed? It's a scarry
thought, but funny one: A DDOS by microsoft's own software against itself.

- Lynn




Current thread: