hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

Full Version: Source Leaked?
Kpz
/. post here

ph34r.gif
phaeton
Yes its leaked and yes there are copies floating around the internet.

Look hard enough and you will find it.
x1`
do u know any other web sites with the aritcle slashdot is always server busy
nolimit
http://news.bbc.co.uk/1/hi/business/993933.stm

it's real

203MB file circulating the net
Kpz
That URL is doing the rounds.

Its *4* years old. Check before you post wink.gif
SLiM577
yep source leaked i copped it my self from sites : Windows.2000.SOURCE.CODE.LEAK-iND



you know what this means right???????? soon LOTS of new holes will be open and microsoft going get ripped apart ..... =]
Kpz
Which sites? I can't find it anywhere :\
SLiM577
not websites top sites
nolimit
This will still cause a huge flurry of exploits, and since Win2K is built off WinNT4, and WinXP is built off of Win2K........

BET theres a LOT of common code


MSFT gonna be (filtered). I'd short MSFT afterhours atm and buy up any internet security stocks you can find. Make a killing tomorrow.
Kpz
(assuming its real)
moskaman
edit:
due to the nature of this,
the board won't condone the sharing of these files.

Anybody who wishes to disagree can settle with a ban from the forum.

--dissolutions
SeNe
i had the oportunity to take a look, and it seems real, cant wait to see the rain of exploits that soon gonna be.
Kpz
I wanna copy so I can get to writing them!

cool.gif
zera
i had a look to NT4 and win2k source
thats gr8
smile.gif
saetji
QUOTE
This will still cause a huge flurry of exploits, and since Win2K is built off WinNT4, and WinXP is built off of Win2K........



win2k was its own code - not based on nt.
crash3rzz
yeh i have source code.. and few proggies that were leaked
microshit sux dunky dick
and if it seems real.. i really dont know
im just viewing it riite now, and checkin wats up
Kpz
QUOTE (saetji @ Feb 13 2004, 01:04 AM)
win2k was its own code - not based on nt.

It's largely based on NT.
x1`
i wonder if it has anything to do with the new flaw ms vunrabulty and ms thought they would put a patch out before people figure it from the source code ...fishy
Kpz
There are a whole shitload more vulns in there than just the ASN.1 integer overflows wink.gif
Hellraiseruk
haha find this so funny..good old haxors biggrin.gif
Zekk
ahh damn this is just too damn cool.
archphase
QUOTE (saetji @ Feb 13 2004, 01:04 AM)
QUOTE
This will still cause a huge flurry of exploits, and since Win2K is built off WinNT4, and WinXP is built off of Win2K........



win2k was its own code - not based on nt.

as if the Based on NT Technolgy wasn't a clue enough?

If it is true though and the file is around ~200 megs I can't wait to go ring0 under nt.
KeeBLeR904
ive seen it on a few sites but i dont wanna touch it, im scared of microsofts wrath.. lol
DrI
What would you even do with it? I bet not even 1% of members on this board would even be able to compile it - much less comprehend at least 1% of source itself.
Stoney
i heard the source was incomplete? is that true

yea ur right im looking and i couldnt compile it if i wanted to
gman24
QUOTE (Stoney @ Feb 13 2004, 12:49 AM)
i heard the source was incomplete? is that true

yea ur right im looking and i couldnt compile it if i wanted to

No real need to compile it, you can buy a copy for that.

You can look and see how everything works.
Axl
QUOTE (gman24 @ Feb 13 2004, 08:07 AM)
QUOTE (Stoney @ Feb 13 2004, 12:49 AM)
i heard the source was incomplete? is that true

yea ur right im looking and i couldnt compile it if i wanted to

No real need to compile it, you can buy a copy for that.

You can look and see how everything works.

a shame, i really wanted to compile a version of Solitaire and i'd call it like QuantumSpades wink.gif
OaKz
editted
Kpz
Microsoft confirms http://www.microsoft.com/presspass/press/2...ndowssource.asp source code leak.

The files are incomplete, the total Windows source (30mil lines of code) is 40-50GB. The leaked code is 660mb uncompressed.

Hf smile.gif
Stoney
QUOTE (Dinos @ Feb 13 2004, 08:19 AM)
It was reported as being here ...
http://host.com/windows/

um.. yea it was posted in another thread that shareing of this file wasnt aloud on this board
Gurou
look here, the "internal" news release of microsoft biggrin.gif

http://www.k-otik.com/news/02.13.Win2kOpenSource.php

ph34r.gif
Paul
Scared to know if you got win2k laugh.gif
ShadowRun
i can't read and i have posted a link to the site, My posting permissions have now been suspended for approximately 1 month.

And this is because I think your a benefit to the forum.

Read next time.
randalizm
i thought it was 45 million lines of code as to nt4s 13million
and win 2k server n shit is nt5
winsoc
@ QuantumTopology :

Look in here : windows_2000_source_code\win2k\private\windows\shell\games\sol

Lol


This shit is good, theres raw source on socks, ftp, inet all sorts of shit to mess with.
Damn I'm never gonna get of this damn box now biggrin.gif
Kpz
I'm not sure its quite as fatal as made out.

There is no code for the net facing services in there (that I can see).
gwon
I haven't posted on here for a while..But I had to come take a look when I read bout this leak..

I have a hold of the source now (didn't take much looking :/)...and I'll probably have a look tomorrow...I'm not really seeing it as a major threat that all the news sites seem to claim it is (especially if thats true about the net facing code not being out there)

Like I say I'll have a look tomorrow and come back and start talking about the ammount of GPL code I'm expecting to find in there wink.gif

MHSICKNESS
QUOTE (winsoc @ Feb 13 2004, 03:56 PM)
@ QuantumTopology :

Look in here : windows_2000_source_code\win2k\private\windows\shell\games\sol

After checking the code i'm now 100% sure that patience = exploitable...
LOL j/k
</offtopic>
<ontopic>
Axl
QUOTE (winsoc @ Feb 13 2004, 03:56 PM)
@ QuantumTopology :

Look in here : windows_2000_source_code\win2k\private\windows\shell\games\sol

Lol


This shit is good, theres raw source on socks, ftp, inet all sorts of shit to mess with.
Damn I'm never gonna get of this damn box now biggrin.gif

Yea i know the dir just not how to compile it uh yea... i compiled the resource script.
nmcog
There is no GPL code in the leaked source and unlikely in any Microsoft software product. The company policy is Microsoft programmers are not allowed to look at any GPL code.

There is however BSD code (e.g. strings ftp.exe)
Illu-OSFXP
NT4 and 2000 source code were sent around. it's been proven that the NT4 code was fake (if anyone has any doubts) but the portions of code of 2000 are infact real. it's interesting stuff smile.gif

roto
its not very crucial code to the operating system apparently tho, i got a copy myself havnt had a change to look at it yet tho
Mastering
I heard that the leaked code didn't include any networking code, so it won't be a big Impact on Security (do i hear a "damn" or a "yippieh" ?) happy.gif
As previously said the file is arround 200 mb big (must be like <1/6th of whole code)... I downloaded parts of it but all sources are gone. Looks like too many people want to stare at something they dont understand and they cant use.
B^A^D
It can be found on IRC......just look
nolimit
QUOTE (Kpz @ Feb 13 2004, 10:56 AM)
Microsoft confirms http://www.microsoft.com/presspass/press/2...ndowssource.asp source code leak.

The files are incomplete, the total Windows source (30mil lines of code) is 40-50GB. The leaked code is 660mb uncompressed.

Hf smile.gif

Hmmm.. 40GB of raw C++ code compiles into 650MB for fitting on a CD. doubtful, even with compression. Anything I've ever compiled becomes bigger then the source code, granted includes raise the size, but still.
Neoankt
Yes, it does seem to be unbelievable yet you can shrink the size and limit the strings pulled out of the include file...
Maybe they have other alterns. to the method but still i cant come up with a reason on how they'd shrink that 39 Gig +
Kpz
QUOTE (nolimit @ Feb 17 2004, 02:25 AM)
QUOTE (Kpz @ Feb 13 2004, 10:56 AM)
Microsoft confirms http://www.microsoft.com/presspass/press/2...ndowssource.asp source code leak.

The files are incomplete, the total Windows source (30mil lines of code) is 40-50GB. The leaked code is 660mb uncompressed.

Hf smile.gif

Hmmm.. 40GB of raw C++ code compiles into 650MB for fitting on a CD. doubtful, even with compression. Anything I've ever compiled becomes bigger then the source code, granted includes raise the size, but still.

Obviously not.

However, not all the source gets into the distro.

The 40-50GB quote (which was from MS) is the size of the source *tree*. Includes all the revisions and so on.

There is alot of fluff in the code, old bits that have been ripped, duplicates of code for Hydra, things that don't make the cut etc.

It is entirely possible that 40-50GB worth of code and resources gets onto a 660MB cd smile.gif
digitalk2003
Even if you did get your hands on the 203 mb of compacted microsoft code, most of it is primary code for IE 5. On top of this, an exploit is already available for it, though I don't know how much good it would do. Anybody who's on a windows system would have installed the latest service patch, fixing this issue.

Now if somebody could find a way to use the asn 1 with some shellcode, that could get interesting. rolleyes.gif

Ciau...

digitalk ph34r.gif
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.