Thanks to a prying eye and probably a stroke of luck, a user has managed to exploit Microsofts Newsgroups via Microsoft BetaNews. That user can gain access to any Beta newsgroup as long as he has a valid Microsoft BetaID and that person knows the ID number for the newsgroup.

A friend enabled us here at Neowin to access the microsoft.beta.longhorn developer preview groups that were opened in March for select developers. The newsgroups there aren't buzzing with activity since they received the official M4 build of Windows Longhorn Professional and not much else since.

We will be passing this information on to Microsoft so that they can review their security. Below is a screenshot of our entry to these newsgroups.

Update: We have contacted Microsoft Security, Some of the more sensitive newsgroups have now been locked down, but less important ones still seem to be affected

Screenshot: >> Click here <<
View: Microsoft BetaNews (requires valid BetaID)


FIC Radeon 9600 Pro at Gamer Depot
View: FIC Radeon 9600 Pro at GD

VajaCases-iPod Case @ Geekshelter.com
"With the iPod craze that has sweept the nation, many people are constantly trying to stylize their iPods look and feel. Recently, a company by the name of Vaja has released an elegent set of Cases to really beef up your pod. I was lucky enough to obtain their new case released for the 3rd Generation iPods."

View: VajaCases-iPod Case @ Geekshelter.com

Radeon 9800 & 9700 put head to head
Having the capability to produce as much as 1.8 million graphic cards per month, Sapphire Technologies happens to be one of ATI’s primary OEM partners.
Today we are examining their Radeon 9800 Atlantis Pro; with a board design that resembles ATI's reference a lot, the Atlantis offers 9800 Pro's outstanding performance packed with a great bundle, high quality parts (good for o/cing) & Sapphire's warranty to back it up, at an acceptable price point.

View: Radeon 9800 & 9700 put head to head @ Techspot

Vantec NXP-205 Fan Controller Review
Nexus Fan Controller connects up to 4 fans and allows you manually adjust the fan speed and noise level. The fan speed is determined by the variable speed potentiometer settings which vary the voltage of the fan from 7V-12V. Each channel will support 15-18W. Blue LED lights combine perfectly with the Black or Silver housing. Nexus Fan Controller is great for Large CFM fans and fits perfectly in your standard 5'25" drive bay.

View: Vantec NXP-205 Fan Controller Review @ Ascully.com



There are 71 additional comments
Advertisement
Quote this comment Reply to this comment #1 Posted by Quick Reply on 06 Aug 2003 - 10:31
awesome, the Longhorn newsgroups are gonna rock after they release a beta
(1 reply) Quote this comment Reply to this comment #2 Posted by kairon on 06 Aug 2003 - 10:58
Gee, won't even tell us. Why even bother posting this.
Quote this comment #2.1 Posted by cooldude7273 on 06 Aug 2003 - 15:10
its harsh.....
Quote this comment Reply to this comment #3 Posted by Trix on 06 Aug 2003 - 10:59
aww no sharing of the id and wont let other ppl post it grrrrr havto fin this exploit my self or lern howto make these Xploits
Quote this comment Reply to this comment #4 Posted by Voodoo on 06 Aug 2003 - 11:03
we gotta give ms the chance to plug it first
Quote this comment Reply to this comment #5 Posted by Sim31 on 06 Aug 2003 - 11:04
<<removed>>
Quote this comment Reply to this comment #6 Posted by Trix on 06 Aug 2003 - 11:07
what wwas removed ???? tell meeee!
Quote this comment Reply to this comment #7 Posted by Trix on 06 Aug 2003 - 11:08
grrr hwat mod is watching this commenty goto findout
(3 replies) Quote this comment Reply to this comment #8 Posted by Trix on 06 Aug 2003 - 11:09
just look at iexbeta they think this is all a fake grrr idiots well who know neowin mite be messin wiht our heads! <<iexbeta.com>>

Last edited by 32223 on 06 Aug 2003 - 11:26
Quote this comment #8.1 Posted by Neobond on 06 Aug 2003 - 11:15
its not fake because I coinfirmed the exploit myself and we arent showing people how to do it because that could create mayhem on the betanews groups. MS will surely love us for that.
Quote this comment #8.2 Posted by Sim31 on 06 Aug 2003 - 11:30
Guess your right, Have news post everywhere and ms wondering where the people got access to it
Quote this comment #8.3 Posted by J.A.X on 06 Aug 2003 - 11:38
wow...working exploit. I rtested it. but was not lucky enough to find any good interesting groups :p
(1 reply) Quote this comment Reply to this comment #9 Posted by Sim31 on 06 Aug 2003 - 11:13
Hmm guess its not allowed to say how to do it then
Quote this comment #9.1 Posted by kairon on 06 Aug 2003 - 11:14
Why, do you know?
Quote this comment Reply to this comment #10 Posted by Sim31 on 06 Aug 2003 - 11:16
Yes, Posted it and got removed, so I cant tell
Quote this comment Reply to this comment #11 Posted by nathanintu on 06 Aug 2003 - 11:20
(1 reply) Quote this comment Reply to this comment #12 Posted by air101 on 06 Aug 2003 - 11:26
The Screen shows LongHorn , can't it be fake or something ?
Quote this comment #12.1 Posted by neostyle on 06 Aug 2003 - 11:43
no its not
Quote this comment Reply to this comment #13 Posted by Sim31 on 06 Aug 2003 - 11:59
I dont think they will let you post in the groups tho since I tried, and nothing shows up hmmm

Last edited by 15825 on 06 Aug 2003 - 12:05
Quote this comment Reply to this comment #14 Posted by Trix on 06 Aug 2003 - 12:09
hey Sim31 i figured out how to do it but all i need now is a beta place ID and i lost my a loooooooooooooooooooooooooooooooooooooong time ago
Quote this comment Reply to this comment #15 Posted by Trix on 06 Aug 2003 - 12:14
sh|t theve said now!
(1 reply) Quote this comment Reply to this comment #16 Posted by on 01 Jan 1970 - 00:00
Quote this comment #16.1 Posted by Phoenix_25 on 06 Aug 2003 - 12:24
cool thx!
Quote this comment Reply to this comment #17 Posted by Voodoo on 06 Aug 2003 - 12:25
again to remind u - we will not allow links to sites that give details of the exploit
(4 replies) Quote this comment Reply to this comment #18 Posted by Quick Reply on 06 Aug 2003 - 12:29
I got in, pretty boring eh?

but I also found...
Cobra
Miata
Everest
SFU 3.5
SQL SLammer Defense
MRS Trial
Mira v1.5
MSTV Tools Suite 1.0 Preview Release 1
Project 11
mediacenter update
UNIX DB Library
VS6 Sp6 Beta
msklc
MidTownx
Baseball 2003
Exchange RDP
Storage Services
FS 9
Preview Beta SP4 (dont know if thats w2k sp4 or not)
Windows ADS Beta
CRM1.0 Intl
Ozone
Jupiter
Windows2000 JA SP4
HIS
SQL QFE
ObjectSpaces EAP
Highwire v1.0
MSIB 2.0
IB Training

and others that are heard of
Quote this comment #18.1 Posted by shift on 06 Aug 2003 - 13:15
QUOTE
Exchange RDP


Anyone got any information on what this is?

Some of the others sound interesting too, but this in perticular sounds very interesting to me!
Quote this comment #18.2 Posted by Sawyer12 on 06 Aug 2003 - 17:24
some of them sound very interesting although the names dont give much away about what they actually are. What are Cobra,Miata,msklc,Ozone,Jupiter.

Quote this comment #18.3 Posted by Jugalator on 06 Aug 2003 - 19:54
"Ozone":
http://www.microsoft-watch.com/article2/0,4248,1125771,00.asp

"Jupiter":
http://news.com.com/2009-1122-1009533.html

msklc:
http://www.microsoft.com/globaldev/tools/msklc.mspx
Quote this comment #18.4 Posted by NeonShark on 08 Aug 2003 - 17:57
What are the numbers for theose newsgroups? What is the number for FS9?
Quote this comment Reply to this comment #19 Posted by Trix on 06 Aug 2003 - 12:32
aww man i want a beta ID
(3 replies) Quote this comment Reply to this comment #20 Posted by SOHara on 06 Aug 2003 - 12:35
Found the Halo PC beta on there as well
Quote this comment #20.1 Posted by outofcoffee on 06 Aug 2003 - 12:36
freelancer beta also
Quote this comment #20.2 Posted by Trix on 06 Aug 2003 - 12:40
ooh is there any download for that yet?
Quote this comment #20.3 Posted by Quick Reply on 06 Aug 2003 - 12:44
yup i found that, directx and flight simulator 9 too

Last edited by 22902 on 06 Aug 2003 - 21:23
(1 reply) Quote this comment Reply to this comment #21 Posted by joa on 06 Aug 2003 - 12:41
I found Longhorn Dev => achthonderd vijftien
Quote this comment #21.1 Posted by Gophlin on 06 Aug 2003 - 12:51
Dank

Now we have to find some guestID's for Betaplace
Quote this comment Reply to this comment #22 Posted by Trix on 06 Aug 2003 - 12:44
we should start a separte topic for this
(2 replies) Quote this comment Reply to this comment #23 Posted by air101 on 06 Aug 2003 - 12:48
THE Screenshot is FAKE!
Quote this comment #23.1 Posted by outofcoffee on 06 Aug 2003 - 12:52
lol just cos you can't figure it out ;P
it's not fake. really :p

WinFS info is kinda interesting... what the hell's a "File Promoter"?
Quote this comment #23.2 Posted by outofcoffee on 06 Aug 2003 - 12:54
ah..

QUOTE
Hi,
though we call it "file promotion", it actually works
both ways. There's a promoter and demoter for each file
type and if the either the file or the winfs item is
modified, both will be written with the information. If
there's a new file type introduced to the computing world
after WinFS releases in Longhorn, ISVs and MS will be
able to add new file promoters/demoters as appropriate or
needed.


shh! i think i head neobond/voodoo coming! (run!)
Quote this comment Reply to this comment #24 Posted by Trix on 06 Aug 2003 - 12:49
no the screen shot isnt fake i got 3 other ppl to back that up
Quote this comment Reply to this comment #25 Posted by Trix on 06 Aug 2003 - 12:52
PLEASE does anybody have a Beta ID i can use just for 10 minutes please!
(1 reply) Quote this comment Reply to this comment #26 Posted by air101 on 06 Aug 2003 - 12:54
all n00bs
Quote this comment #26.1 Posted by OptiPlex on 06 Aug 2003 - 13:21
All right
Quote this comment Reply to this comment #27 Posted by Trix on 06 Aug 2003 - 12:56
so what the ucp or what ever it is call id 81 or 81_somthing?
(3 replies) Quote this comment Reply to this comment #28 Posted by ThunderRiver on 06 Aug 2003 - 13:03
Oh Almighty Voodoo, if you actually use your little brain, you might understand it is not wise to post when you don't belong to that specific newsgroup.

Oh well..
Quote this comment #28.1 Posted by Voodoo on 06 Aug 2003 - 13:06
i was given permission by a MS Security Programme Manager, just to see if u can post using the exploit.

BE aware tho - I wouldn't recommend anyone else try it
Quote this comment #28.2 Posted by Voodoo on 06 Aug 2003 - 13:21
QUOTE (#27.0)
Oh Almighty Voodoo, if you actually use your little brain

u can appologise for suggesting i have a small brain now...
Quote this comment #28.3 Posted by DJ^TuRKiYe on 06 Aug 2003 - 13:24
I'm not gonna bother trying to post since i don't fancy losing my beta id
(1 reply) Quote this comment Reply to this comment #29 Posted by Tom Servo on 06 Aug 2003 - 13:17
I spoiled. I'm reading their newsgroups...

On a second note... Why are there people called "Joe User" and BS like that in these newsgroup? Talk about seriousity.

--edit--
OMFG an OT topic about Matrix Reloaded! What the?

Last edited by 413 on 06 Aug 2003 - 13:24
Quote this comment #29.1 Posted by outofcoffee on 06 Aug 2003 - 13:28
lol i know!
the reply's a bit....urm... "boring"

<snipped>
bleh
Quote this comment Reply to this comment #30 Posted by whistlerxp on 06 Aug 2003 - 13:24
Cool nice trick,you made MS all exited.
(2 replies) Quote this comment Reply to this comment #31 Posted by ZiUL on 06 Aug 2003 - 13:52
Read the bible:
Genesis 5:10
Quote this comment #31.1 Posted by syscrash2k on 06 Aug 2003 - 15:45
QUOTE
Genesis 5
10 And after he became the father of Kenan, Enosh lived 815 years and had other sons and daughters.

Wha?
Quote this comment #31.2 Posted by ZiUL on 06 Aug 2003 - 17:11
Numbers...
(2 replies) Quote this comment Reply to this comment #32 Posted by Cool4 on 06 Aug 2003 - 14:16
i have a valid beta ID, but i don't know how to sign in, it should only ask for the beta ID, i think! but it ask for user and pass! what do i have to do?
Quote this comment #32.1 Posted by dougkinzinger on 06 Aug 2003 - 14:38
Sounds like you didn't read your Beta Packet Cool4..........
Quote this comment #32.2 Posted by Cool4 on 06 Aug 2003 - 15:34
no... seems not
Quote this comment Reply to this comment #33 Posted by dougkinzinger on 06 Aug 2003 - 14:32
I'm also in, since I actually USE the newsgroups....there is some interesting stuff out here, but remember folks--it's just NEWSGROUPS....that's all....
(1 reply) Quote this comment Reply to this comment #34 Posted by EnIgMa-PenGuIn on 06 Aug 2003 - 14:36
^_^ nice one guys lols. im sure ms was happy to know and fix that hole. good work ^_^ and at least it keeps unmentionables out of there
Quote this comment #34.1 Posted by dougkinzinger on 06 Aug 2003 - 14:37
No, not yet, it's still "open" Penguin......
Quote this comment Reply to this comment #35 Posted by gameguy on 06 Aug 2003 - 14:44
hehehe, widbey
Quote this comment Reply to this comment #36 Posted by Know Won on 06 Aug 2003 - 15:29
Good find.
Quote this comment Reply to this comment #37 Posted by gameguy on 06 Aug 2003 - 16:27
is it "fixed" now? i think it is
(2 replies) Quote this comment Reply to this comment #38 Posted by netizen on 06 Aug 2003 - 16:37
Sureley MS ought to reward the Neowin admins with an access-all-areas betaID for this
Quote this comment #38.1 Posted by Voodoo on 06 Aug 2003 - 16:47
i wish
Quote this comment #38.2 Posted by kairon on 06 Aug 2003 - 19:16
I'm sure Voodoo has enough exclusive information to keep him happy.
Quote this comment Reply to this comment #39 Posted by whoreman on 06 Aug 2003 - 19:07
i see the theory behind it and i belive this to true but possibly fixed now?

well half my legit links dont work
(1 reply) Quote this comment Reply to this comment #40 Posted by Michael Lerner on 06 Aug 2003 - 22:18
Great Job they did too, can't access one of my newsgroups
Quote this comment #40.1 Posted by RevJohn on 07 Aug 2003 - 15:44
Drop me an email and we'll see if we can't figure out what the problem is, Michael.

John Eddy johneddy@microsoft.com
Microsoft Windows XP - Shell, Tablet PC, IE/OE MVP Lead
Quote this comment Reply to this comment #41 Posted by filter04 on 16 Sep 2004 - 00:38
neowin alert microsoft to so much stuff that goes wrong, and do we ever here a thanks ?
Quote this comment Reply to this comment #42 Posted by 23305004937369 on 17 Sep 2004 - 01:33
ccooool thnx
[1]

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.


Scroll to the Top
....
My Preferences
....
Communicating with server
Loading
Please Wait...
....
Loading
 X 
....