This is sent on behalf of Michael Starks (for balance purposes):
 
Mark,

I have read your recent comments on the Servers Alive mailing list in regards to my advisory. Since I have not been approved to post to the list and defend my research, I thought I'd drop you an e-mail in the hopes that a civil discussion ensues.

The bug listed in the advisory is a bug. Period. CERT agrees, the MITRE corporation agrees and colleagues I have discussed this with agree. This is a program design decision which allows a non-privileged user to obtain SYSTEM rights. VB does not make this happen; the programmer has to specifically code this to make it happen. The plain and simple fact is that a non-privileged user can elevate their privilege, exclusively and only because Servers Alive is installed on the system. I can appreciate the fact that you may consider SA to be a great app because of all the features. I do, too.

But don't let that cloud what is.

The advisory was released to give people an opportunity to know about this bug, and make an informed decision as to how they wanted to handle it. As an administrator myself, I want to know if there are risks by using the apps I use. With the knowledge comes the power to respond and be better protected.

Your comments that no one but an administrator should log on locally to the box are straight on. It is a best practice and exercising the concept of least-privilege is always a good idea. But that is just a mitigating factor.

The bug still exists. And even if you exercise best practices, not everyone else does or can. Some may have specific business needs to allow normal users to log on locally.

Please try to be objective and consider both sides of an issue before posting parodies and snide comments. I still consider Servers Alive to be a great application, will still use it and possibly even recommend it to others.

Yes, many other applications do contain this same bug. And many other vendors have also fixed it. Dirk has chosen not to. He has chosen to update documentation with the associated risks. That's fine I suppose, since the user can at least make an informed choice, thereafter.

Finally, consider that I acted in a completely ethical manner. Dirk was given fair opportunity to address the bug before public disclosure and discussion.

I could have posted anonymously. I put my name on my research and I stand by it.

With best regards,

Michael Starks

Reply via email to