yep source leaked i copped it my self from sites : Windows.2000.SOURCE.CODE.LEAK-iND
you know what this means right???????? soon LOTS of new holes will be open and microsoft going get ripped apart ..... =]
Kpz
Feb 12 2004, 11:47 PM
Which sites? I can't find it anywhere :\
SLiM577
Feb 12 2004, 11:48 PM
not websites top sites
nolimit
Feb 12 2004, 11:48 PM
This will still cause a huge flurry of exploits, and since Win2K is built off WinNT4, and WinXP is built off of Win2K........
BET theres a LOT of common code
MSFT gonna be (filtered). I'd short MSFT afterhours atm and buy up any internet security stocks you can find. Make a killing tomorrow.
Kpz
Feb 12 2004, 11:52 PM
(assuming its real)
moskaman
Feb 13 2004, 12:10 AM
edit: due to the nature of this, the board won't condone the sharing of these files.
Anybody who wishes to disagree can settle with a ban from the forum.
--dissolutions
SeNe
Feb 13 2004, 12:27 AM
i had the oportunity to take a look, and it seems real, cant wait to see the rain of exploits that soon gonna be.
Kpz
Feb 13 2004, 12:28 AM
I wanna copy so I can get to writing them!
zera
Feb 13 2004, 01:02 AM
i had a look to NT4 and win2k source thats gr8
saetji
Feb 13 2004, 01:04 AM
QUOTE
This will still cause a huge flurry of exploits, and since Win2K is built off WinNT4, and WinXP is built off of Win2K........
win2k was its own code - not based on nt.
crash3rzz
Feb 13 2004, 01:08 AM
yeh i have source code.. and few proggies that were leaked microshit sux dunky dick and if it seems real.. i really dont know im just viewing it riite now, and checkin wats up
Kpz
Feb 13 2004, 01:15 AM
QUOTE (saetji @ Feb 13 2004, 01:04 AM)
win2k was its own code - not based on nt.
It's largely based on NT.
x1`
Feb 13 2004, 01:20 AM
i wonder if it has anything to do with the new flaw ms vunrabulty and ms thought they would put a patch out before people figure it from the source code ...fishy
Kpz
Feb 13 2004, 01:24 AM
There are a whole shitload more vulns in there than just the ASN.1 integer overflows
Hellraiseruk
Feb 13 2004, 01:27 AM
haha find this so funny..good old haxors
Zekk
Feb 13 2004, 01:46 AM
ahh damn this is just too damn cool.
archphase
Feb 13 2004, 01:57 AM
QUOTE (saetji @ Feb 13 2004, 01:04 AM)
QUOTE
This will still cause a huge flurry of exploits, and since Win2K is built off WinNT4, and WinXP is built off of Win2K........
win2k was its own code - not based on nt.
as if the Based on NT Technolgy wasn't a clue enough?
If it is true though and the file is around ~200 megs I can't wait to go ring0 under nt.
KeeBLeR904
Feb 13 2004, 05:12 AM
ive seen it on a few sites but i dont wanna touch it, im scared of microsofts wrath.. lol
DrI
Feb 13 2004, 06:53 AM
What would you even do with it? I bet not even 1% of members on this board would even be able to compile it - much less comprehend at least 1% of source itself.
Stoney
Feb 13 2004, 07:49 AM
i heard the source was incomplete? is that true
yea ur right im looking and i couldnt compile it if i wanted to
gman24
Feb 13 2004, 08:07 AM
QUOTE (Stoney @ Feb 13 2004, 12:49 AM)
i heard the source was incomplete? is that true
yea ur right im looking and i couldnt compile it if i wanted to
No real need to compile it, you can buy a copy for that.
You can look and see how everything works.
Axl
Feb 13 2004, 08:19 AM
QUOTE (gman24 @ Feb 13 2004, 08:07 AM)
QUOTE (Stoney @ Feb 13 2004, 12:49 AM)
i heard the source was incomplete? is that true
yea ur right im looking and i couldnt compile it if i wanted to
No real need to compile it, you can buy a copy for that.
You can look and see how everything works.
a shame, i really wanted to compile a version of Solitaire and i'd call it like QuantumSpades
i can't read and i have posted a link to the site, My posting permissions have now been suspended for approximately 1 month.
And this is because I think your a benefit to the forum.
Read next time.
randalizm
Feb 13 2004, 03:40 PM
i thought it was 45 million lines of code as to nt4s 13million and win 2k server n shit is nt5
winsoc
Feb 13 2004, 03:56 PM
@ QuantumTopology :
Look in here : windows_2000_source_code\win2k\private\windows\shell\games\sol
Lol
This shit is good, theres raw source on socks, ftp, inet all sorts of shit to mess with. Damn I'm never gonna get of this damn box now
Kpz
Feb 13 2004, 11:15 PM
I'm not sure its quite as fatal as made out.
There is no code for the net facing services in there (that I can see).
gwon
Feb 14 2004, 02:24 AM
I haven't posted on here for a while..But I had to come take a look when I read bout this leak..
I have a hold of the source now (didn't take much looking :/)...and I'll probably have a look tomorrow...I'm not really seeing it as a major threat that all the news sites seem to claim it is (especially if thats true about the net facing code not being out there)
Like I say I'll have a look tomorrow and come back and start talking about the ammount of GPL code I'm expecting to find in there
MHSICKNESS
Feb 14 2004, 02:33 AM
QUOTE (winsoc @ Feb 13 2004, 03:56 PM)
@ QuantumTopology :
Look in here : windows_2000_source_code\win2k\private\windows\shell\games\sol
After checking the code i'm now 100% sure that patience = exploitable... LOL j/k </offtopic> <ontopic>
Axl
Feb 14 2004, 02:48 AM
QUOTE (winsoc @ Feb 13 2004, 03:56 PM)
@ QuantumTopology :
Look in here : windows_2000_source_code\win2k\private\windows\shell\games\sol
Lol
This shit is good, theres raw source on socks, ftp, inet all sorts of shit to mess with. Damn I'm never gonna get of this damn box now
Yea i know the dir just not how to compile it uh yea... i compiled the resource script.
nmcog
Feb 14 2004, 02:27 PM
There is no GPL code in the leaked source and unlikely in any Microsoft software product. The company policy is Microsoft programmers are not allowed to look at any GPL code.
There is however BSD code (e.g. strings ftp.exe)
Illu-OSFXP
Feb 14 2004, 02:34 PM
NT4 and 2000 source code were sent around. it's been proven that the NT4 code was fake (if anyone has any doubts) but the portions of code of 2000 are infact real. it's interesting stuff
roto
Feb 16 2004, 02:29 AM
its not very crucial code to the operating system apparently tho, i got a copy myself havnt had a change to look at it yet tho
Mastering
Feb 16 2004, 05:38 PM
I heard that the leaked code didn't include any networking code, so it won't be a big Impact on Security (do i hear a "damn" or a "yippieh" ?) As previously said the file is arround 200 mb big (must be like <1/6th of whole code)... I downloaded parts of it but all sources are gone. Looks like too many people want to stare at something they dont understand and they cant use.
The files are incomplete, the total Windows source (30mil lines of code) is 40-50GB. The leaked code is 660mb uncompressed.
Hf
Hmmm.. 40GB of raw C++ code compiles into 650MB for fitting on a CD. doubtful, even with compression. Anything I've ever compiled becomes bigger then the source code, granted includes raise the size, but still.
Neoankt
Feb 17 2004, 02:13 PM
Yes, it does seem to be unbelievable yet you can shrink the size and limit the strings pulled out of the include file... Maybe they have other alterns. to the method but still i cant come up with a reason on how they'd shrink that 39 Gig +
The files are incomplete, the total Windows source (30mil lines of code) is 40-50GB. The leaked code is 660mb uncompressed.
Hf
Hmmm.. 40GB of raw C++ code compiles into 650MB for fitting on a CD. doubtful, even with compression. Anything I've ever compiled becomes bigger then the source code, granted includes raise the size, but still.
Obviously not.
However, not all the source gets into the distro.
The 40-50GB quote (which was from MS) is the size of the source *tree*. Includes all the revisions and so on.
There is alot of fluff in the code, old bits that have been ripped, duplicates of code for Hydra, things that don't make the cut etc.
It is entirely possible that 40-50GB worth of code and resources gets onto a 660MB cd
digitalk2003
Feb 18 2004, 08:10 PM
Even if you did get your hands on the 203 mb of compacted microsoft code, most of it is primary code for IE 5. On top of this, an exploit is already available for it, though I don't know how much good it would do. Anybody who's on a windows system would have installed the latest service patch, fixing this issue.
Now if somebody could find a way to use the asn 1 with some shellcode, that could get interesting.
Ciau...
digitalk
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.