Re: [Full-Disclosure] When do exploits get used?

From: Luke Scharf (lscharf_at_aoe.vt.edu)
Date: 03/22/04

  • Next message: Will Image: "Re: [Full-Disclosure] commerical rainbow crack?"
    To: Jay Beale <jay@bastille-linux.org>
    Date: Mon, 22 Mar 2004 17:31:44 -0500
    
    

    On Mon, 2004-03-22 at 17:13, Jay Beale wrote:
    > You may find this discussion academic. But the exploit writers and the
    > worm writers are getting faster. And that's what should scare us into
    > moving beyond patches. That's what should get us moving to better
    > network and host configurations. That's what should get us to evaluate
    > patching as, at most, the easy, but most critical, 50%.

    I would say that we could all agree that not patching is a recipe for
    disaster -- and that it's very easy to keep up to date.

    But, my 90% figure comes from the accidental plugging of unpatched
    Windows machines into the open network. Every time I do that, the
    machine is running msblast in a few minutes. And as near as I tell,
    it's not my machines that are doing it (except for that one unpatched
    machine that I spend an hour rebuilding)...

    -Luke

    -- 
    Luke Scharf, Systems Administrator
    Virginia Tech Aerospace and Ocean Engineering
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    

  • Next message: Will Image: "Re: [Full-Disclosure] commerical rainbow crack?"

    Relevant Pages

    • Re: Internet Radio
      ... If you can run to it look at the Centrino machines. ... Near enough cutting edge processors (battery life, performance) and most have built in wireless - look for 'g' spec to be sure of a decent stream, although frankly the older wireless should be just fine. ... As for the rsik of having an open network, ...
      (uk.rec.audio)
    • Re: Just uninstalled Delphi 2005 Enterprise
      ... > FWIW Delphi 2005 Personal is usable here on machines ... even after patching and "bareboning" ... sacred as the laws of God and there is not a force of law and public ...
      (borland.public.delphi.non-technical)
    • ms03-039
      ... How to patching my LAN workstation, ... machines. ... How do that in enterprises more biggers... ...
      (microsoft.public.win2000.security)
    • Windows Installer 3.0
      ... Is there any benefit to upgrading our machines to Windows Installer 3.0 if ... we're using SMS SUS for patching? ...
      (microsoft.public.sms.misc)

  • Quantcast