Re: [Full-Disclosure] The worm author finally revealed!

From: HggdH (hggdh@attbi.com)
Date: 01/31/03

  • Next message: Thor Larholm: "Re: [Full-Disclosure] Origin of the term "driveby download""
    From: "HggdH" <hggdh@attbi.com>
    To: <full-disclosure@lists.netsys.com>
    Date: Fri, 31 Jan 2003 09:05:05 -0600
    

    From: <futureshoks@hushmail.com>
    (...)
    |
    | Just imagine you pulled the plug on your company's webserver because they
    were running an un-patched IIS (and you're running IIS because some
    development manager decided it was The Right Thing). Your CEO comes storming
    down saying they are loosing business and the reputation of the company is
    being damaged. What do you do? Retort with "well a hacked webserver would be
    more damaging". What do you think (s)he'll say? "Oh OK then, I see your
    point. Keep the servers down until its patched and thankyou for your
    proactive stance". Or more likely "get the servers back on-line or you are
    fired".
    |
    (...)

    Thank the Almight someone here actually works in a company like all
    companies I worked for. No, immediate patching does not happen all the
    times, and immediate response (i.e. fixing the code) does not happen all the
    time.

    You, or your manager, or your manager's manager (or, who knows, your intern)
    will always be making a call. Just like what you do when you are getting
    near to a crossing, and the traffic lights start to change. Most of the
    times you do not need to be a prophet to make the right call, but not
    always. Some times (in fact, a whole lot of them) making the wrong call does
    not hurt you.

    ..hggdh..

    "I completely hate extremists"

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html



    Relevant Pages

    • IUSR_PCNAME unable to access Server
      ... I am setting up a WebServer on a Windows 2000 Pro Machine ... running IIS. ... I need to access a database on my SBS2000 Server ... IUSR_WEBSERVER as a user on the SBS system. ...
      (microsoft.public.inetserver.iis.security)
    • Re: firewall ?
      ... >I'm looking for good free software to protect my webserver ... >I'm running iis ... Try the Linux Security group. ... Jeff ...
      (microsoft.public.inetserver.iis.security)
    • firewall ?
      ... I'm looking for good free (opensource) software to protect my webserver ... I'm running iis ...
      (microsoft.public.inetserver.iis.security)