Re: [Full-Disclosure] No Subject (re: openssh exploit code?)

From: Kenneth R. van Wyk (ken_at_vanwyk.org)
Date: 10/21/03

  • Next message: Marc Schoenefeld: "[Full-Disclosure] IE6 & Java 1.4.2_02 applet: Hardware stress on floppy drive"
    To: <full-disclosure@lists.netsys.com>
    Date: Tue, 21 Oct 2003 17:26:18 -0400
    
    

    On Tuesday 21 October 2003 17:07, Robert Ahnemann wrote:
    > I flip to the local radar and get some sort of proof that there might be
    > a thunderstorm coming. Talk is cheap (as was said), so its up to the
    > admin to verify if A) there is a real threat B) the threat applies to
    > your systems C) the threat damage is worth the damage of 'unscheduled
    > downtime'

    FWIW, I agree that these are all reasonable steps to take in order to help
    prioritize whether (exiting the analogy...) you should apply the patch to
    YOUR systems. There's a couple other complicating factors that I haven't
    seen mentioned in this thread, though -- apologies if I've overlooked them:

    1) I've seen patches break applications. When applying a patch to a
    production app server, it's a good career-stabilizing move to test the patch
    to ensure that, if NOTHING else, the app still works once the patch is in
    place.

    2) Change management in some tightly controlled production data centers can be
    extreme. This is particularly true for environments in which change
    management has regulatory oversight -- such as in the pharmaceutical
    industry, where servers have to be FDA certified (in the USA, at least).

    That is, in some cases, even if you KNOW that the storm is coming and it is
    highly likely to hit you, you cannot take the corrective action that you
    think is called for. In cases like this, it may be prudent to look for other
    workarounds to protect those production systems...

    There's a lot of variables and complexity to the patch-and-chase process. If
    were only so simple to run {windows update|apt-get upgrade|up2date|...} on
    all of our systems, we would have figured it out by now. IMHO.

    Cheers,

    Ken van Wyk
    http://www.krvw.com

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Marc Schoenefeld: "[Full-Disclosure] IE6 & Java 1.4.2_02 applet: Hardware stress on floppy drive"

    Relevant Pages

    • Re: Patch Management on Critical Servers (Healthcare)
      ... Some key items to remember is that testing of the patch must be done in a separate environment from production. ... Patch Management on Critical Servers (Healthcare) ...
      (Focus-Microsoft)
    • Re: Forth as an operating system
      ... A patch to the operating system itself is very different in terms of risk than using the same machine for both end-users and software development concurrently. ... But what can be said is that on a system like you describe, it is perfectly normal for the same system to be used both for running end-user tasks and software development. ... I wouldn't think of attaching a new piece of hardware to a running production system unless it and its driver had been thoroughly tested elsewhere, whereas a lot of application tweaks can be done perfectly safely. ...
      (comp.lang.forth)
    • Re: FYI - Windows users be afraid. Be very afraid.
      ... and say a 98SE patch will be developed as well. ... If it is a threat. ... Conservatives are not necessarily stupid, ...
      (alt.guitar.bass)
    • Re: Healing threat messed up since patch
      ... Say someome had salvation plus some 25% agro ... before this patch that would be 30+25=55% ... possible to get over 100% threat reduction. ... Take a shadow priest with all of Silent Resolve (20% less threat), ...
      (alt.games.warcraft)
    • Re: Security Announcements & Incremental Patches
      ... >> Production systems administration has to be conservative. ... > But below you seem to have an inordinate fondness for the Solaris patch ... What isn't incremental about Solaris patches? ... Another difference between Solaris and FreeBSD patches is the level ...
      (FreeBSD-Security)