A Basic Timeline of the Exchange Mass-Hack
krebsonsecurity.com
krebsonsecurity.com
Some of the vulns existed in the Exchange codebase for 10 years.
Microsoft faces perverse incentives. When their customers get compromised, Microsoft benefits from accelerated upgrades and cloud subscriptions.
Yet their customers blame foreign threat actors and not Microsoft, so Microsoft suffers no reputational damage.
With these incentives, why would any rational corporation spend resources hardening their software or responding rapidly to new disclosures?
First: what if the fix really took 2 months?
Second: I'm not well versed in this kind of software; is this on-prem stuff that clients have to manage (update) themselves, or is this SaaS cloud stuff that MS can immediately update without clients in the loop?
Just because Microsoft has software powering very important things globally doesn’t exclude them.
With these incentives, why would any rational government spend taxpayer money on this company's software.
The canned response for every problem with Microsoft today seems to be "Well, nothing more can be done, except what Microsoft (and other "experts") tells us to do." The company that creates the problems is deemed to be the only one who could ever attempt to solve them. This is pure nonsense. With few exceptions, this goes virtually unquestioned,
The "experts" have perverse incentives. Business is good just the way it is. If problems are actuallly solved, business would likely decline.
Microsoft runs their software through multiple code scanners looking for weakneses. Developers do unit testing, and then there is acceptance testing. Microsoft conducts internal penetration tests on their software. Microsoft hires 3rd parties to conduct penetration tests on their software. Large corporations conduct internal penetration tests on Exchange, and hire 3rd party companies to conduct penetration tests on Exchange, just to be sure. Governments conduct penetration tests on Exchange.
A lot of people have been poking at Exchange for years, and years, and years, and this bug was just discovered, and it's been present in the code base for at least 7 years, I'd say that's pretty damn good, it seems like a hardened product to me, not a slipshod product as you suggest.
You are so funny. First you complain that Microsoft has no incentive to deliver quality software, then you complain that they can't delivery quality software quickly.
I guess they would have been better off not bother to conduct all the testing necessary to ensure that they didn't fix one problem and create two more.
https://docs.microsoft.com/en-us/exchange/decommission-on-pr...
When something is wrong with any of a domain's services, your organization is breached.
There is variation in details like in how to exploit vulnerabilities or how to move laterally...
But AD is a SPOF, cloud or not.
Many of these orgs should have learned this after [CVE-2020-0688](https://www.thezdi.com/blog/2020/2/24/cve-2020-0688-remote-c...)
If it's a hybrid environment, it doesn't need to be exposed.
That doesn't solve MS problem of coming up with a better solution though
It'd be interesting to see more info in the timeline about when that might have happened. Just feels like this info is entirely based on what the research community was seeing, not based on any info from the adversary side of this event (not that collecting that kind of data is easy, so fair enough).
I suspect that the researchers involved all saw how bad it was and didn't feel that it was safe to let Microsoft wait, as (although I don't think it's particularly common) they may drag their feet on a patch. Leaking this vulnerable forces MS's hand sooner. So it's not really necessarily totally off from what I've seen in the past. Just not very common.
This tends to happen when researchers discover the zero day is ALREADY pervasive in the wild.
There were multiple groups conducting attacks? Is there evidence of that?
i don't see an issue here
microsoft patched a bug within a 90-day disclosure timeline and even released patched before the agreed date when it learned they were exploited
why is krebs making a big deal out of it