Darket Diaries
Darket Diaries

57: MS08-067

Hear what goes on internally when Microsoft discovers a major vulnerability within Windows. Guest Thanks to John Lambert for sharing this story with us. Sponsors Support for this episode comes from ProCircular. Use the team at ProCircular to conduct security assessments, penetration testing, SIEM mo

Featured Speakers

Jack Rhysider HostJohn Lambert GuestJack Resider Guest

Topics Discussed

Episode Summary

Executive Summary: Jack discusses the shared responsibility for cybersecurity using a road safety analogy. John Lambert from Microsoft recounts discovering the MS08-067 vulnerability, a wormable zero-day in Windows that allowed remote code execution. Despite a rapid out-of-band patch, the Conficker worm exploited unpatched systems, infecting millions globally. The story highlights the critical need for patching, collaborative defense, and the complex dynamics between software vendors, attackers, and even government agencies like the NSA.

Main Topics: Shared Cybersecurity Responsibility (Priority: 5/5): Using a road safety analogy, Jack argues that keeping networks secure requires effort from users, software makers, law enforcement, and standards groups—not any single party. Discovery of MS08-067 (Priority: 5/5): John Lambert explains how he found a new zero-day exploit by analyzing crash reports (WER) showing an 'egg hunt' technique, leading to the discovery of a critical, wormable vulnerability in Windows. Microsoft's Crisis Response and Patch Dilemma (Priority: 4/5): The team mobilized a SERP process, decided to release an out-of-band patch to counter active attacks despite risk of copycats, and patched 400 million machines in the first week. Conficker Worm Outbreak (Priority: 5/5): Conficker adopted MS08-067 as a spreading mechanism, infecting over 10 million computers across 190 countries due to slow patching, causing massive disruption. NSA-Microsoft Relationship and Zero-Days (Priority: 4/5): Discussion of NSA's dual role: finding and reporting bugs for public safety (e.g., EternalBlue, recent crypto bug) vs. weaponizing vulnerabilities for offensive operations. Conficker Investigation and Arrests (Priority: 3/5): The Microsoft Cabal coalition reverse-engineered the worm; FBI arrested three Ukrainians and a Swede, Mikkel, who profited $71 million from scareware, though Conficker's ultimate purpose remains debated. Ongoing Relevance of Patching (Priority: 4/5): Despite the patch being over a decade old, 400,000 systems still run Conficker. The episode stresses patching as the single most effective defense.

Key Arguments: Cybersecurity is a collective responsibility involving users, vendors, law enforcement, and standards bodies—not just developers. Crash telemetry (Windows Error Reporting) can reveal zero-day exploits when attackers' tools fail, enabling early detection before widespread damage. Rapid out-of-band patching can mitigate active attacks but creates risk by revealing the vulnerability to broader hacker community, leading to copycat exploits. Patching is the most effective individual defense; even a small percentage of unpatched systems (1%) can yield millions of victims for worm outbreaks. Government agencies like NSA both protect and threaten security—their discovery of bugs can lead to responsible disclosure or weaponization. The Conficker worm's lasting presence shows that legacy vulnerabilities persist due to organizational constraints like compatibility issues and slow update cycles. Collaborative industry coalitions (e.g., Microsoft Cabal) are essential to combat large-scale threats that no single entity can handle alone.

Data Points: Lines of code in Windows XP: 45 million - Illustrates the immense complexity making bug-free software impossible. Microsoft employees (2008): 91,000 - Demonstrates scale needed to manage security at a large software company. Crash reports to Microsoft per month: over a billion - Sheer volume of telemetry data that had to be filtered to find security signals. Bugs fixed in Vista via static analysis and WER: 100,000 - Scale of proactive bug removal to improve reliability and security. Windows computers patched in first week: 400 million - Effectiveness of Windows Update for rapid inoculation. Windows computers in world (2008): about 1 billion - Total addressable vulnerable population. Countries affected by Conficker: 190 - Global reach of the worm. Computers infected by Conficker: 10 million - Scale of the outbreak, making it the largest worm ever. Conficker-infected computers still present (2020): 400,000 - Persistence of legacy systems after many years. Reward for Conficker creator info: $250,000 - Microsoft's incentive for identifying the worm's author. Mikkel's scareware profit: $71 million - Financial motivation behind one suspect's cybercrime operations.

Pivotal Quotes: "I called that dialing into the crash buckets to find any information I could about how often this was occurring. And I was able to bring back this situational awareness to the crisis response that said, okay, I saw it five more times today. It just spread from Malaysia to Japan to Singapore to whatnot." — John Lambert: Describes tracking the spread of the zero-day exploit via crash reports as it moved across Asian countries. "We need users to be smart at what they click on and do. And we need software makers to design the software to be secure. And we need the cops to arrest people when they break the law. And we need groups who set up industry standards that guide us to safety." — Jack Resider: Summarizing the shared responsibility model for cybersecurity using the road safety analogy. "The look was the look that a security researcher has when they found something. There's a goofy, happy smile that is also full of, holy cow, I can't believe how serious this thing is that I just found. He said, I found a vulnerability." — John Lambert: Recalling the moment colleague Andrew confirmed the existence of the wormable vulnerability.

Implications: This episode reinforces that patching is the single most effective defense, but systemic delays in updating leave millions vulnerable. It also highlights the complex role of government agencies in cybersecurity—both as defenders and as potential threats. For the industry, collaborative coalitions are vital to combat fast-spreading worms.

🔓 Sign Up for Unlimited Episode Search

About Darket Diaries

Explore true stories of the dark side of the Internet with host Jack Rhysider as he takes you on a journey through the chilling world of hacking, data breaches, and cyber crime.

View all episodes from Darket Diaries