Sunday, April 20, 2008

Microsoft admits it sent Office nag to all WSUS servers

Admins, furious, say their Office installs have been falsely fingered as fake

System administrators have ripped Microsoft Corp. for pushing a trial anti-piracy program meant for limited distribution to all enterprise update servers, a mistake that has triggered false warnings of Office counterfeits.

Earlier this month, Microsoft announced it would kick off a pilot program for software to display nagging notices on copies of Office that it deems fake. The program, part of the Office Genuine Advantage (OGA) initiative, which already requires users to validate their software as legitimate, was to run in only four countries: Chile, Italy, Spain and Turkey. The notices would appear on machines running phony copies of Office XP (called Office 2002 by some), Office 2003 and Office 2007.

Last Tuesday, however, Microsoft published the test update to all Windows Server Update Services (WSUS) servers, and did not limit its delivery to end users in Chile, Italy, Span and Turkey. WSUS is the primary update mechanism used by businesses to patch their Microsoft software. Later, Microsoft said the mistake had seeded the OGA update to WSUS servers for about 24 hours.

By early Wednesday, administrators in the U.S., U.K., New Zealand and elsewhere were posting messages on Microsoft support newsgroups, asking why their WSUS systems had received the Office nag. In some cases, administrators reported that the update had fingered large numbers of desktop PCs as running counterfeit copies of Office.

"Update KB949810 arrived via WSUS yesterday and now all my XP workstations running Word 2002 are telling me it needs activating," said a user identified as "morriswoodyman," who said he is in the U.K. "The only problem is that the software is genuine and was activated three years ago," the user added in a message to a Microsoft support newsgroup.

The support document morriswoodyman referenced -- KB949810 -- is the one associated with the OGA notification update, and was how WSUS labeled the update in its listings.

Another user, James, said he is with the U.S. Army, and that the systems he manages had also been falsely accused. "I have 100s of systems now giving me errors," he said on the same support thread. "These are US Government computers with legitimate licenses! MS needs to fix this FAST!!!"

Some users were blunt in their criticism. "I'm legal. My software is legal," said Susan Bradley on the same newsgroup. "There is nothing more frustrating as a Microsoft shareholder to constantly see Microsoft shoot themselves in the foot by treating legal customers in this manner."

Although Microsoft representatives acknowledged that there had been a glitch as early as Wednesday, it wasn't until Friday that Microsoft issued an official explanation in a post to its WSUS team blog.

"On April 15 the Office Genuine Advantage (OGA) notifications update (KB949810) was inadvertently published to WSUS servers for approximately twenty-four hours," the company said. "This update was intended for Microsoft Office users in the pilot countries of Italy, Spain, Turkey and Chile, but because of WSUS publication, it became available to WSUS managed clients inside and outside of these intended countries."

Microsoft also said that if administrators had configured their WSUS servers to automatically approve EULAs (end-user licensing agreements), the Office nag update went out to client systems without any action on the part of the IT staff. The update, Microsoft also admitted, had been tagged as "critical" for WSUS, which contradicted the company's assertion in early April that the pilot program would be voluntary. Updated pegged critical are, for instance, downloaded and installed automatically from Windows Update to most machines.

"OGA notifications are designed to alert customers who are using non-genuine software, and are thus more vulnerable to activation exploits and the risks of counterfeit," said Microsoft in the WSUS blog post. "As such, this update was marked critical for WSUS."

That raised the ire of at least one user on the support newsgroup. "This update was deployed as a CRITICAL Update? While this may be critical to Microsoft's bottom line, any clear thinking IT person would assume (silly me) that a critical update would be critical to IT in the sense of stability or security," said a user identified as Chris Edwards-Dawn yesterday.

"I would suggest a new classification of update titled 'Revenue Generation.' As a corporation, we have exerted much blood, time and money on compliance. As my corporation's WSUS Admin, I am considering suggesting using WSUS to block updates, not distribute them! There is nothing more frustrating than being a loyal customer, only to be treated poorly and incompetently."

As several users, including Edwards-Dawn, noted on the support newsgroup, the OGA error is not the first mistake Microsoft's made in its anti-piracy efforts. In August 2007, for example, a Windows Genuine Advantage server outage accused an unknown number of Windows XP and Vista users of running bogus copies of the OS; it then stripped machines of some features when it deemed them invalid.

Microsoft's also had trouble making sure WSUS was supplied with the proper updates. Last October, it apologized for pushing a Windows Desktop Search update to some PCs without getting administrator approval.

One user called on Microsoft to drop its anti-piracy technology, dubbing it a "farce."

"All it does is harass the paying customers while doing zero to stop people from using your software illegally," said "ioniancat21" on Thursday. "[Windows] Genuine Advantage is a failure, will always be a failure and has no chance of being successful in anyone's lifetime."

Microsoft representatives posting messages to the same newsgroup recommended that users whose systems had been updated with the OGA notification code download the "MGADiag.exe" diagnostic tool, run it and report its findings to the company's support desk.

According to information posted on Microsoft's Web site, however, the OGA notifications update cannot be uninstalled once it's made its way onto a PC.


Courtesy: www.computerworld.com, author: Gregg Keizer

12 comments:

Anonymous said...

Keep up the good work.

Anonymous said...

Run this command.
MsiExec.exe /uninstall {B148AB4B-C8FA-474B-B981-F2943C5B5BCD}

You will be prompted if you are sure you want to unistall. Click ‘Yes’

This will unistall the OGA notifier 1.7.0105.35.0 described on this blog. Works for vista and XP.

Anonymous said...

Good day !.
You re, I guess , probably curious to know how one can make real money .
There is no initial capital needed You may commense to receive yields with as small sum of money as 20-100 dollars.

AimTrust is what you haven`t ever dreamt of such a chance to become rich
AimTrust represents an offshore structure with advanced asset management technologies in production and delivery of pipes for oil and gas.

Its head office is in Panama with structures around the world.
Do you want to become really rich in short time?
That`s your choice That`s what you really need!

I`m happy and lucky, I began to get real money with the help of this company,
and I invite you to do the same. It`s all about how to select a correct partner who uses your savings in a right way - that`s it!.
I earn US$2,000 per day, and my first investment was 500 dollars only!
It`s easy to get involved , just click this link http://sumogalep.wtcsites.com/anocaw.html
and lucky you`re! Let`s take our chance together to become rich

Anonymous said...

Good day !.
might , perhaps very interested to know how one can make real money .
There is no initial capital needed You may commense earning with as small sum of money as 20-100 dollars.

AimTrust is what you thought of all the time
The company incorporates an offshore structure with advanced asset management technologies in production and delivery of pipes for oil and gas.

Its head office is in Panama with structures everywhere: In USA, Canada, Cyprus.
Do you want to become really rich in short time?
That`s your chance That`s what you really need!

I`m happy and lucky, I started to take up income with the help of this company,
and I invite you to do the same. It`s all about how to choose a correct companion utilizes your funds in a right way - that`s it!.
I take now up to 2G every day, and my first investment was 500 dollars only!
It`s easy to join , just click this link http://nifodomiw.1accesshost.com/ebefova.html
and go! Let`s take our chance together to feel the smell of real money

Anonymous said...

Good day, sun shines!
There have been times of hardship when I felt unhappy missing knowledge about opportunities of getting high yields on investments. I was a dump and downright pessimistic person.
I have never imagined that there weren't any need in big initial investment.
Nowadays, I'm happy and lucky , I begin to get real income.
It gets down to select a correct partner who uses your funds in a right way - that is incorporate it in real business, parts and divides the income with me.

You may ask, if there are such firms? I have to tell the truth, YES, there are. Please get to know about one of them:
[url=http://theblogmoney.com] Online investment blog[/url]

Anonymous said...

Hi!
You may probably be very curious to know how one can manage to receive high yields on investments.
There is no need to invest much at first.
You may commense earning with a sum that usually is spent
for daily food, that's 20-100 dollars.
I have been participating in one company's work for several years,
and I'll be glad to let you know my secrets at my blog.

Please visit my pages and send me private message to get the info.

P.S. I make 1000-2000 per daily now.

http://theinvestblog.com [url=http://theinvestblog.com]Online Investment Blog[/url]

Anonymous said...

Can I help you?
---------------------------------------------------------
Signature:buy levitra professional online gzv

Anonymous said...

singles dances massachusetts [url=http://loveepicentre.com/]herpes and dating[/url] totally free online dating http://loveepicentre.com/ speed dating north east

Anonymous said...

It isn't hard at all to start making money online in the hush-hush world of [URL=http://www.www.blackhatmoneymaker.com]blackhat scripts[/URL], Don’t feel silly if you don't know what blackhat is. Blackhat marketing uses little-known or not-so-known ways to generate an income online.

Anonymous said...

cigna pharmacy management [url=http://usadrugstoretoday.com/disclaimer.htm]Online Pharmacy - Safe, Secure, Prescriptions Guaranteed[/url] pro health ultra cookware http://usadrugstoretoday.com/categories/cholesterin.htm pictures of herpes women http://usadrugstoretoday.com/products/lariam.htm
home medical equipment supply [url=http://usadrugstoretoday.com/products/brahmi.htm]brahmi[/url] faith and stress [url=http://usadrugstoretoday.com/categories/antibiotici.htm]homeopathic gout medicine[/url]

Anonymous said...

syphilis the bacteria [url=http://usadrugstoretoday.com/products/minocycline.htm]minocycline[/url] drugs tests http://usadrugstoretoday.com/categories/arthrite.htm hippa regulations dental mn http://usadrugstoretoday.com/products/diclofenac.htm
health news articles [url=http://usadrugstoretoday.com/products/isoptin.htm]isoptin[/url] bisocodyl drug classification [url=http://usadrugstoretoday.com/products/cefixime.htm]chicken antibiotics[/url]

Anonymous said...

journal hypertension [url=http://usadrugstoretoday.com/products/brand-cialis.htm]brand cialis[/url] smoking dragons blood daemonorops draco http://usadrugstoretoday.com/products/urispas.htm medicare national drug code http://usadrugstoretoday.com/products/viagra-soft-flavoured.htm
apwu health plan [url=http://usadrugstoretoday.com/products/colchicine.htm]colchicine[/url] sexy anal orgasm videos [url=http://usadrugstoretoday.com/index.php?lng=es&cv=eu]diabetes mellitus risk factors[/url]