Hacked via Microsoft Servers!

From: GlowOfSunsetREMOVE_at_Yahoo.com (GlowOfSunset_at_yahoo.com)
Date: 05/01/04


Date: 1 May 2004 10:42:46 -0700

Microsoft Corporation,

I wrote this because I hope that the corporate officers of Microsoft
will hear of the complaint. So PLease do not remove it...move it
upstream to them if anything.

I am currently learning about Microsoft Windows protocols and
applications regarding the securing of Windows XP Pro and Windows
Server 2003. I have just concluded attending the Microsoft Security
Summit and an additional class through New Horizons here in Chicago,
Illinois regarding group and security policy administration. That is
what piqued my interest in the available applications.

Last night through the Microsoft Corporate website, a site I trusted
to be able to obtain documention from considering that I might use
documentation that was not accurate from elsewhere I attempted to find
the ability for batch or script group and local security policies. It
was at that time that I began being severely hacked by what appently
looks like none other than Microsoft Corporate system administrators.
Most if not all of what was hitting my system was through
microsoft.com. Can you explain what I have just said?

I admit thaat I looked at well over 100 to 150 documents and was on
the Microsoft domain for well over four hours but that is how long it
took to find what I was looking for. Your document base is not
properly stemmed nor is it set up for system administrators who are
migrating from entry level to advanced administrators. In order to
become an advanved user of your online systems it probably takes any
individual well over a year given the services and document base that
you have. This is not going to happen overnight. I absolutely could
not find what I was looking for and that is why I had to continuously
run searches and pour through as many documents as I had. I have
better things to do woth my time such as performing the actual systems
security.

I did eventually see the "Threats and Countermeasures Guide," which is
part of the information that I sought. I still have not download
"Windows XP Professional Resource Kit" or "Windows Server 2003
Resource Kit Tools" because I was under some very heavy fire. Nice
hack on instanciating the WMI and Print Spooler services though I do
not know what you were up to. It certainly pisses me off.

Now, I've been more than polite, but I would say that if you think you
are going to beat Google at indexing any documentation that you had
better start with a consolidation of your own documentation on your
own hosted systems, consider better stemming mechanisms for your
database systems and stop hacking individuals looking for
documentation regarding support until you develop better mechanisms to
find the documents that you have.

That is about all I can say, because if I say much more I think we
will both lose respect for each other. I would tone down your server
security team and any other anuses hanging around that think that they
own the world.



Relevant Pages

  • [NT] Cumulative Security Update for Internet Explorer (MS04-025)
    ... Get your security news from a reliable source. ... * Microsoft Windows NT Workstation 4.0 Service Pack 6a ... Navigation Method Cross-Domain Vulnerability ...
    (Securiteam)
  • SecurityFocus Microsoft Newsletter #120
    ... Strengthening Network Security: FREE Guide Network security is a ... MICROSOFT VULNERABILITY SUMMARY ... Microsoft Windows File Protection Signed File Replacement... ... PlatinumFTPServer Information Disclosure Vulnerability ...
    (Focus-Microsoft)
  • SecurityFocus Microsoft Newsletter #176
    ... MICROSOFT VULNERABILITY SUMMARY ... Microsoft Windows XP HCP URI Handler Arbitrary Command Execu... ... PHPNuke Category Parameter SQL Injection Vulnerability ... Microsoft Baseline Security Analyzer Vulnerability Identific... ...
    (Focus-Microsoft)
  • SecurityFocus Microsoft Newsletter #242
    ... MICROSOFT VULNERABILITY SUMMARY ... PostNuke Blocks Module Directory Traversal Vulnerability ... Groove Networks Groove Virtual Office COM Object Security By... ... The Microsoft Windows IPV6 TCP/IP stack is prone to a "loopback" condition initiated by sending a TCP packet with the "SYN" flag set and the source address and port spoofed to equal the destination source and port. ...
    (Focus-Microsoft)
  • [NT] Vulnerability in HTML Help Allows Code Execution (MS05-001)
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... * Microsoft Windows XP Service Pack 1 and Microsoft Windows XP Service ...
    (Securiteam)