RE: [Full-Disclosure] Re: Microsoft Security, baby steps ?

From: Schmehl, Paul L (pauls_at_utdallas.edu)
Date: 03/18/04

  • Next message: Schmehl, Paul L: "RE: Re[2]: [Full-Disclosure] New Virus under way ..."
    To: <full-disclosure@lists.netsys.com>
    Date: Thu, 18 Mar 2004 10:18:06 -0600
    
    

    > -----Original Message-----
    > From: full-disclosure-admin@lists.netsys.com
    > [mailto:full-disclosure-admin@lists.netsys.com] On Behalf Of
    > Full-Disclosure
    > Sent: Thursday, March 18, 2004 2:17 AM
    > To: full-disclosure@lists.netsys.com
    > Subject: RE: [Full-Disclosure] Re: Microsoft Security, baby steps ?
    >
    > In an corporate environment, you will have SUS or SMS
    > running. If so, no need for internet access.
    >
    I'm seeing statements like this more and more, on this list and others,
    and it's really starting to bug me. (Not picking on you personally.)
    Most of the attacks on corporate boxes come from the inside. Blocking
    internet access does very little to protect you. Don't believe it?
    Then explain how Slammer and Sobig and Mydoom and Nachi and Blaster
    managed to spread in corporate environments that have very good
    firewalling.

    Putting up a firewall is one small step in a very large process that
    gets you some semblance of security. You are not "safe" simply because
    the firewall is up and running. All it take is *one* improperly
    maintained box on the inside to be compromised/infected, and the hacker
    is off to the races. What will SUS/SMS do for you then?

    By all means, automate patching. But for god's sake, don't think that
    once you've done that you're done! You've only just begun.
     
    Paul Schmehl (pauls@utdallas.edu)
    Adjunct Information Security Officer
    The University of Texas at Dallas
    AVIEN Founding Member
    http://www.utdallas.edu/~pauls/

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Schmehl, Paul L: "RE: Re[2]: [Full-Disclosure] New Virus under way ..."

    Relevant Pages

    • Re: [fw-wiz] httport 3snf
      ... This isn't all that uncommon in the corporate environment either- and add ... the same firewall as the other campus networks is probably not the best ... nor is enforcing the same policies. ... > The SSL proxy sounds like an excellent idea but not all these firewalls ...
      (Firewall-Wizards)
    • Re: D-Link 604 Router
      ... > corporate environment of hundreds of employees. ... NAT/SPI makes their product a firewall when it really is just a router ... point to try and explain the difference between a firewall and a router. ... protection that a REAL firewall affords them), ...
      (comp.security.firewalls)
    • Re: Personal firewall for Business users
      ... I'd recommend Sophos Client Firewall (or Sophos Endpoint Security if you want firewall and anti-virus protection). ... Sophos Client Firewall is designed exclusively for the corporate environment and offer excellent central management and administration features and a high degree of flexibility, and top notch technical support too - a rarity in the IT industry. ...
      (alt.computer.security)
    • Re: What Firewall do you recommend?
      ... of course firewall software can have a place in corporate environment ... such as on roaming laptops that may ... introduce security issues through VPN or RAS when off the premises, ...
      (microsoft.public.win2000.security)

    Loading