And now, Windows NT has a problem

By R.Ramasubramoni | 21 Jun 1999

For the world's largest software company Microsoft, glitches in its software have been uncomfortably and surprisingly large and too frequent. Its last release of the operating system software Windows 98 left behind a trail of crashed PCs initially and took several rounds of patches to rectify the software. Now this legacy is hitting a very crucial area- network operating systems.

A small, 9-man software company in California, eCompany LLC discovered the glitch that allows a person to gain access to computers running the Microsoft Internet Information Server software. A hacker could easily get into the Internet server and cover up his tracks after doing the damage, with the system administrator blissfully unaware of it. Microsoft Internet Information Server is a part of Windows NT operating system for networks, which is one of the leading networking operating systems along with Unix. More than 20 percent of web servers are run on this operating system.

This flaw in the operating system is a serious threat to network security to the extent that the federal body CERT co-ordination centre at the Software Engineering Institute in Pittsburgh rated it 95 on a scale of 100 for seriousness of the problem.

The flaw was discovered at eCompany when they were testing their new networking security audit software. They claim that they had informed Microsoft about it and found them slow to react and downplaying the threat. This forced them to publish both the tool to exploit this loophole and the patch to rectify the error. It took two days for Microsoft to react and publish a fix on the Internet.

Clearly, this is another of those 'avoidables' for Microsoft who find themselves fighting a anti trust lawsuit (see story 'Giant plays the bully') on one side and such problems on the other. This is especially crucial, coming as it does a few months ahead of its release of another new operating system software, Windows 2000. (see story Microsoft plays safe with Windows 2000).