TechSpott - Computer and technology forums

Go Back   TechSpott - Computer and technology forums > News
News Find here the latest news on windows and other popular windows related software!

Reply
 
Thread Tools Display Modes
Old April 4th, 2010, 11:55 PM   #1 (permalink)
News Bot
Fetches News For TechSpott From Various Internet Sources
 
News Bot's Avatar
 
Join Date: Mar 2010
Posts: 6,463
Thanks: 0
Thanked 0 Times in 0 Posts
News Bot is an unknown quantity at this point
Post Microsoft runs fuzzing botnet, finds 1,800 Office 2010 bugs

Quote

Finds, fixes huge number of Office 2010 bugs by tapping idle company PCs.

Microsoft uncovered more than 1,800 bugs in Office 2010 by tapping into the unused computing horsepower of idling PCs, a company security engineer said today.

Office developers found the bugs by running millions of "fuzzing" tests, said Tom Gallagher, senior security test lead with Microsoft's Trustworthy Computing group.

Fuzzing, a practice employed by both software developers and security researchers, searches for flaws by inserting data into file format parsers to see where programs fail by crashing. Because some crash bugs can be further exploited to successfully hack software, allowing an attacker to insert malicious code, fuzzing is of great interest to both legitimate and criminal researchers looking for security vulnerabilities.

"We found and fixed about 1,800 bugs in Office 2010's code," said Gallagher, who last week co-hosted a presentation on Microsoft's fuzzing efforts at the CanSecWest security conference in Vancouver, British Columbia. "While a large number, it's important to note that that doesn't mean we found 1,800 security issues. We also want to fix things that are not security concerns."

Gallagher declined to quantify the number of flaws found via fuzzing that qualified as vulnerabilities, saying only that the Office 2010 team did uncover security bugs in the process and patched them during development. Some of those vulnerabilities have already been addressed in older editions of Office, Gallagher added, because information obtained by fuzzing Office 2010 code was checked against the code in earlier versions -- such as Office 2007 and Office 2003 -- then patched during Office 2010's development.

Non-security bugs discovered in Office 2010 that also exist in previous editions will be fixed in those versions' upcoming service packs, Gallagher said.

Microsoft was able to find such a large number of bugs in Office 2010 by using not only machines in the company's labs, but also under-utilitized or idle PCs throughout the company. The concept isn't new: The Search for Extraterrestrial Intelligence (SETI@home) project may have been the first to popularize the practice, and remains the largest, but it's also been used to crunch numbers in medical research and to find the world's largest prime number.
原帖地å€: TechSpott - Computer and technology forums http://www.techspott.com//showthread.php?p=4355

"We call it a botnet for fuzzing," said Gallagher, referring to what Microsoft has formally dubbed Distributed Fuzzing Framework (DFF). The fuzzing network originated with work by David Conger, a software design engineer on the Access team.

.................................................. .................................................. ........................



More on ComputerWorld
News Bot is offline   Reply With Quote Share with Facebook
Reply

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Free Office 2010 Copies via the Office Excitement Kit News Bot News 0 April 2nd, 2010 12:38 PM
Forthcoming movies nghy Movies & Music 0 March 20th, 2010 02:06 PM
Microsoft warns against using 64-bit Office 2010 amitash News 0 March 9th, 2010 09:06 PM
Microsoft confirmed Office 2010 will RTM next month amitash News 0 March 5th, 2010 01:51 PM
Microsoft Decapitates Waledac Botnet amitash News 0 March 1st, 2010 03:48 PM

 
Forum Stats
Members: 14,375
Threads: 20,386
Posts: 27,878
Total Online: 49

Newest Member: AAccedlyGolo

Latest Threads

Advertisements

Support our advertisers!

Amazon
Sears
Macys
1800flowers.com
Drugstore.com


Carbonite Online-Backups
Tiger Direct
Tech Depot
Buy.com
Office Depot
Fatcow
HostGator


TripsNow.us
Marriott
Expedia
CheapTickets.com
OneTravel
Hotwire

Are you a Fan?

Share this on Facebook

Tag Cloud

Partner Links


Contact Us - Home - Archive - Privacy Statement - Top - Copyright © 2009-2010, TechSpott - All times are GMT -4. Time is 09:40 PM

Powered by vBulletin® Copyright © Jelsoft Enterprises Ltd. :: SEO by vBSEO