Windows XP leak confirmed after user compiles the leaked code into a working OS
zdnet.com
zdnet.com
refs: https://web.itu.edu.tr/~dalyanda/mssecrets/other/Startup.htm
In order to perform these operations, execute the following command from within a razzle window, whose current directory is %sdxroot%.
· perl tools\timebuild.pl
https://careers.microsoft.com/us/en/job/869511 Experience with “Timebuild”, razzle, and the Windows build system> #gamingjobs
Heh. Someone needs to tell Microsoft recruiting to dial back the "fellow kids" :P
Also, people do boomerang to companies they've worked at before.
Wouldn't posting a job that an external candidate has no chance of obtaining still violate the intent of that law?
Is this like recruiters looking for 20 years of Go experience lol?
Large OEM partners that need to do driver development, academics, and government customers are all granted source access licenses.
> The complete list of depots follows [...]
> Admin, Base, COM, Drivers, DS, EndUser, InetCore, InetSrv, MultiMedia, Net, PrintScan, Root, SdkTools, Shell, TermSrv, Windows
...which bears a striking resemblance — both back then and to this day — with the root-level categories that divide up the features in the "Add or Remove Windows Features" chooser in the Control Panel.
I guess those root-level categories in the chooser (which were always pretty meaningless) turn out to represent which particular Microsoft source repo the component's code can be found in.
As a wild guess, the "Add or Remove Windows Features" chooser is the way it is, because it's the runtime representation of what's actually mostly a build-time feature selection system; where disabling a component at build time speeds up your build, at the cost of that component being forcibly greyed out in the "Add or Remove Windows Features" chooser for that build. Basically the same as disabling the building of a kernel module in a Linux modular build.
As Raymond Chen would say, "it makes sense with kernel-tinted glasses."
1. Windows developers did not build large parts of the product on any regular basis. Windows took ~18 hours to build on incredibly powerful build lab hardware -- as soon as it took longer, it was time to buy a new build lab. Incremental rebuilds were notoriously flaky, at least in the days before https://github.com/microsoft/BuildXL. The most common dev loop that I saw was to install a recent dogfood build (so APIs and binary interfaces were reasonably recent) and then repeatedly rebuild and clobber binaries on that install.
2. The only real build-configuration options for timebuild were architecture and compile mode (dbg, chk, fre, opt). There wasn't an option to build or not build parts of the tree.
3. raymondc's reference to "kernel-colored glasses" is about viewing things from the kernel side of API guarantees. This is more an applied lesson in Conway's Law.
I suppose this wouldn't have resulted in an installable release, though. (At least on its own. I guess the populatefromvbl.pl script described in the memo is there to bodge a partial clean build of individual components, together with "the rest of Windows" from some parent release, to form a test build?)
also, what a strange email to be public. not that it's a hot secret, but who cares about sdx outside of MS 10 years ago?
I’ve seen a ton of stuff on Empire that wouldn’t have a direct link and Empire is gone now
And afaik it was not buildable. It was a large chunk of the source code that iirc had leaked from a 3rd party who was tasked with making some component, perhaps related to the image library.
[1] https://web.archive.org/web/20100213105753/https://www.micro...
Anyone else think the smartest move for microsoft here is to leave it up, unless another copyright holder complains?
Not only has XP been sunset many times, many years ago, it might finally have all of its bugs picked clean and unofficial patches made to shore up any systems too embedded to move off XP still.
It makes sense, I don't think MS cares about Windows anymore in the azure/O365 era.
OPs hypothesis isn't totally outlandish.
So if people want to take this tree as a base to start releasing unofficial patches, they have 16 years of work to catch-up on just to reach parity.
I'm not trying to argue that unofficial patches would be a bad thing. I just don't think a source tree from 2003 is a good place to start. Any binary you build off this codebase will be missing 16 years of microsoft's patches. Until such a project caught up with all the changes made 2003-2019, any binary you build off this is likely to cause more harm than good (eg, you fix one issue, and reintroduce every issue that was fixed after 2003.)
The idea's good. This sourcetree isn't. Let's just say 2003 was not XP's golden age. If this was at least SP3 onwards, but preferably 2014+, sure. But it's not, it's SP1.
That's a lot of work for what is essentially a gross intellectual property violation as well as a leak of trade secrets.
Tk protect your trademark, you absolutely must go after trademark violations. Any build labeled "Windows" that results from this source code must be taken down if Microsoft wants to keep the trademark on things like "Windows".
Too embedded to move off XP but they're going to install a home brew version of WinXP? Extremely doubtful.
https://devblogs.microsoft.com/oldnewthing/20121218-00/?p=58...
They don't make software like they used to! /s
From https://web.archive.org/web/20190108095105/https://blogs.msd...
> Cinematronics was founded by David Stafford, Mike Sandige and I in 1994, and Space Cadet was our first published game
> The deal David did with Microsoft was non-exclusive. As Danny noted, we were more interested in the exposure and didn't see much revenue from it. However, it did lead to our relationship and eventual acquisition by Maxis.
I had posted this on the Old New Thing comments at the time, but comments on all old posts were lost in the blog transition.
https://web.archive.org/web/20190108095105/https://blogs.msd...
That, and the NT series has already been extensively documented both publicly in various papers and by people like Mark Russinovich and leaked in the form of WRK, 2ksrc, etc.
I'd like all past and current Windows OSes to be open-source. I'd also like macOS and iOS to be open-source. Eventually, all source may be leaked anyway, so they could just do it.
Edit: This goes into some detail on the security aspect: https://security.stackexchange.com/questions/107546/old-os-m...
Has anyone written about it's inner workings as compared to NT?
There were a few books about it in the early 90s by Matt Pietrek and Andrew Schulman.
Windows XP service packs were based on, well, Windows XP. Because that's what service packs were. Lot s of new features have been developed for SP2 (and possibly some backporting from 2003 happened, too) but XP is still XP.
Thus, even though a few files are missing, you just need to include the few official missing ones, and the thing boots.
Source code is available at https://gitlab.com/escargot-chat .
Presuming they don't use any form of encryption (and I think that's a safe assumption for that era), one could keep the clients official, while routing the packets themselves using a virtual Ethernet driver (or via software-defined routing, if the relevant copy of Windows is running in a VM.)
Thanks for sharing, will look into it!
They had a LOT of fun with the fonts and animations, dancing pigs and that kind of thing.
The trouble is, Escargot is a real pain to set up. Certificates need to be patched into the hosts file every 30 days. The server must run on Windows 7 x64. The Windows XP client never worked for me; only on Windows 7 x32 and Windows 10.
If I were able to run an Escargot server from my MacBook Pro, that would make it a whole lot more fun. In practice it takes me hours just to set it up, while they'd rather be playing.
Sounds like a job for letsencrypt...
> The server must run on Windows 7 x64.
It's Python code, might just need some love to go crossplatform (?)
I remember when our office was cut from Internet. Many people did not notice, because Skype kept working like nothing happened.
Because the more general public (for a certain degree of generality) apparently didn't know about this until this week. Usenet is now seen mostly as a device for good ol' piracy.
[1] https://kobyk.wordpress.com/2008/10/29/oops-microsoft-privat...
Win 2k and NT4 sources have had a very very wide circulation for a long time. Probably there was no source copy directly at source level because they magically audited their codebase, somehow, and told us that this did not happen, BUT it at least means that it's easy for anybody not wanting to take the handwaving at face value to directly do a comparison themselves. And no magical process is going to produce virtually the same functions, including the internals, suddenly not a copyright violation, because of some random wishful thinking about how if you copy with some crazy extra steps and a cute little magical dance in the middle it becomes suddenly ok in the eye of the law. Maybe that idea would make lawyers laugh hysterically while randomly saying "AFC test", but I'm not it would have any other effect.
Just take the two trees and diff key functions and see by yourself. There is no way to justify it can't be reimplemented differently to implement even the same specification. Would MS want to destroy that project, I believe they would be able to do it, effortlessly, in a court. But I suspect it is not worth the potential PR backslash given how the narrative is already set that it is "clean", and the high number of free software enthusiasts believing it blindly for years without even checking by themselves.
How useful would this technique be to the ReactOS and Wine teams? Are there things that they don't know how to make work correctly that this source leak could help them with?
in reverse engineering there has to be an intermediate person. in other words, someone could read the source code and the documentation, however they CANNOT actually do the programming. They must write, IN THEIR OWN WORDS, steps and designs for the implementation of the feature and give it to someone else who then interprets and does the actual implementation. this is to ensure that anyone who question how the feature was implemented, they have documentation showing the steps and design of the feature.
again... i don't know what the laws and procedures are today as i'm going off of what i was told, so please someone correct me if i'm wrong.
I miss easter eggs.
Easter egg to me is a flight simulator in Excel or pinball in word etc.!
All of the actual content was available elsewhere as much smaller downloads. In particular, the Windows 2000 and XP leaks are distributed as a single 3 GB archive ("nt5src.7z").
The nt5src.7z src file can also be found on anonfiles and 4chan which was the actual source. It's around 7ish GB unpacked.
A good chunk of languages we take for granted today did not exist at that time, or were in the very first release. Perl came out in 1987, it was quite the thing in the late 90s.
2001, actually.
So it's a neat confirmation of the power of open source over proprietary software.
Notable, also, is that I didn't compile perl for my Linux distribution because perl's configuration system is terrible (there's an out-of-tree patch to make it less terrible, though).
There's some tcl involved.
What about Git? Last I knew, it required Perl to build.
https://github.com/torvalds/linux/blob/2324d50d051ec0f14a548...
That was added 11 years ago(!!) so it may be out of date.
There are tons of examples like this. My favorite is Apple using windows xp to make and test iphones https://www.businessinsider.com/apple-uses-windows-xp-in-iph...
If all of the debugging, testing and factory management tools are standardized on Windows - why rewrite them if you don’t need to? It seems like a waste of resources.
(This isn’t limited to Apple or even technology companies. It applies to tons of businesses.)
What else are you going to use? Batch? Python certainly hadn't caught on yet in the late 90's when XP was being written.
In 2013 when I was interning for a company making an audio driver for Windows, we used Perl to run our builds. While I hate Perl, it does make it real easy to run an executable and analyze its output.
I hope your company firewall does not block YouTube.
At the same time though, that would be hilarious. Someone is going to do it just so they can claim that they were the first person unauthorized by Microsoft to ever file a PR on Windows...
Not sure how big the repo would be though...
Incidentally, this is also why you should separate your work and personal life.
Source?
Arent decompilers and disassemblers pretty good today anyway?
Person A's Job:
- Decompile shit.
- Then write down the names of the functions with (1) input, (2) output, (3) a description of what person a think the code is doing (4) any side effect / preconditions / post conditions they can deduce.
Person B's Job:
- Take the spec created by person A and write code.
while(missingFunctionality.hasNext): goto Person A's Job
I realize that the idea is weird. Though, maybe we could start (or improve awareness of) a dialogue that concerns such kinds of questions?
"you can get it if you want it" is just lame.
m$ should, ideally, bite the bullet and do a (stripped if need be) source release of what they can, explain what they can't release. Everyone will then benefit from the relief from worry and lack of friction things like emulation and software archeology and etc will gain.
Plus a lot of people under-estimate the cost and difficulty in releasing the source code of previously proprietary software. You don't just slap it onto Github and everyone goes home, you often need a team of lawyers to look at third party licensing and go through the code file by file looking for potential liabilities.
Code that started out open source software has to narrow third parties to only specific licenses/waivers. Code that has for tens of years been closed source may contain licensed source code (e.g. decoder libraries) that they don't own the license to publish for just one example.
The source code has already been leaked, and I would bet that malware authors have no problem with acquiring it illegally. While security researchers working within the law may not be able to look at it at all. The current situation does a lot more to help botnets than it does to help honest customers.
>Plus a lot of people under-estimate the cost and difficulty in releasing the source code of previously proprietary software. You don't just slap it onto Github and everyone goes home, you often need a team of lawyers to look at third party licensing and go through the code file by file looking for potential liabilities. [...] Code that has for tens of years been closed source may contain licensed source code (e.g. decoder libraries) that they don't own the license to publish for just one example.
I'm sorry, I just have no sympathy for the trillion dollar company that trapped themselves in restrictive license agreements and then wants to cheap out on lawyers. It is entirely a problem of their own making, and I would expect them to pay to fix it.
You don't see people flying in trijets anymore as they are dangerous, likewise you don't want to encourage or incentivize people to use or build products on an insecure OS.
Sympathy doesn't matter in the business world, costs do. No normal company is going to undertake a legal review of an unsupported product; it simply isn't worth it.
Wikipedia notes it as a design issue: https://en.wikipedia.org/wiki/Trijet
There are documented cases where failure of the central engine has caused a loss of the rear stabilizer. This can be resolved via additional engineering -> which increases cost of manufacturing and maintenance (which as you note was the main factor in why they went away).
I don't follow where you're going with this. Why would they build the source or build products on it if they were not interested in deploying security fixes? There is no other developer interest there and no company would ship a white-labeled "XP 2020 Edition" to developers if it was instantly vulnerable to malware.
>Sympathy doesn't matter in the business world, costs do. No normal company is going to undertake a legal review of an unsupported product; it simply isn't worth it.
Right, that's why I don't buy these lines about how they can't afford it. If it becomes a serious security issue that causes them problems then it is worth it.
Companies have and will ship products with outdated or unsupported OS if they think they can harden them acceptably. See all the networking devices that run some variant of the Linux 2.x kernel that still appear on the market today as an example.
Embedded XP was also a thing and probably still is in many places.
What is it, 2000?
Also some interesting portions of the OS are under a 'view but do not touch' license already. Such as MFC, ATL, and the CRT and others. Depending on which SDK or Visual C++ you grab you can get whole examples of interesting bits of the code. I know for example one of the fun ones is the pipes screen saver code is an example in one of the Visual C++ disks (5.0 I think). I recompiled it years ago to make every joint a teapot and the hard one to find was the bend.
The real money is in Azure/Office/MSSQL anyway.