MS refuse to fix a security problem...

Submitted by: Vinny

Source: http://www.vinny.f2s.com/WiN2k.txt



Yesterday Microsoft refused to fix a security problem in Windows 2000 RPC service. The bug in RPC service allows an attacker to put a Windows 2000 server out of service over the Internet.

Following standard practice, Microsoft was notified of the issue four weeks ago (July 20) at secure@microsoft.com , so
that they can come up with a fix before this information becomes public. After four weeks of inactivity, Microsoft yesterday refused to take any action on the issue. Most amazingly, Microsoft Security Response Team suggested us to post this information to "a newsgroup or other forums that
could give us a hint" about resolving the problem.

More information about this bug can be found in the URL (mind the caps! It's case sensitive).

What's to add...

No posts to display