Re: Russ Cooper's AusCERT Presentation on MS Security Bulletins

From: Craig Shaw (CraigS_at_CAAMANITOBA.COM)
Date: 06/03/04

  • Next message: http-equiv_at_excite.com: "TREND MICRO: The Protector Becomes The Vector [technical exercise: cross-application-scripting]"
    Date:         Thu, 3 Jun 2004 10:44:45 -0500
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    Susan,

    WOOOT! I'm with you all the way!

    We use SMS Server for patch management, and like you said, it's not MS
    products that scare me. It's all those other LOB apps that keep me up at
    night worrying. I can get a 98% deployment success rate with MS patches
    in about an hour. I might have to visit 2 or 3 machines manually to get
    the update to take because some luser didn't log off at night, but
    that's it.

    I know Russ likes to slam Microsoft whenever he can, but this time I
    think he's WAY off the mark. Better off not patching? Is he serious?

    Software is buggy. ALL software is buggy. The more complex the software,
    the more bugs it gets. Period. Patching is a fact of life, pretty much
    since programs grew beyond a few hundred lines of code. This isn't a
    Microsoft problem. It is an industry problem. At least Microsoft is
    taking proactive steps to make it easier to get patches in place and
    keep users notified when new patches are available. Most of the LOB apps
    I'm forced to support are nowhere near as easy to update, and the
    vendors sure don't tell me when updates are even available.

    Maybe it's time to set aside the "I Hate Microsoft" rhetoric and start
    thinking about reality.

    Craig Shaw
    Systems Administrator

    -----Original Message-----
    From: Windows NTBugtraq Mailing List
    [mailto:NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM] On Behalf Of Susan Bradley,
    CPA aka Ebitz - SBS Rocks [MVP]
    Subject: Re: Russ Cooper's AusCERT Presentation on MS Security Bulletins

    Sorry Russ, but this gal in SBSland thinks that non-patching is NOT the
    way to go.

    -----
    Patch Automation v6.0 by Mobile Automation, Inc. allows you to quickly
    identify and fix all PC's that are exposed to the Sasser worm! Our
    solution provides quick and seamless discovery and deployment of all your
    PC computer's Microsoft security patching needs. Regardless of where
    you're PC's reside (inside the LAN, at home or on the road), Patch
    Automation gets the job done. Contact us to learn about our free 30-day
    trial version at 800-344-1150 or visit our website at
    <http://www.patchautomation.com>
    -----


  • Next message: http-equiv_at_excite.com: "TREND MICRO: The Protector Becomes The Vector [technical exercise: cross-application-scripting]"

    Relevant Pages

    • Re: My MS04-028 FAQ
      ... It's a confusing bulletin, but mainly because the underlying technologies ... Microsoft released a tool to help users find vulnerable files to try to ease ... >effect patch management on more than 3 PC's. ... scanning and patching. ...
      (microsoft.public.security)
    • RE: [Full-Disclosure] Support the Sasser-author fund started
      ... > the worm come out AFTER the patch? ... > patched it sooner so that the worm could have come out sooner. ... > The biggest question I have is why all the hostility at Microsoft ... ms is patching a hole but manages to break other things in the process quite frequently. ...
      (Full-Disclosure)
    • [Full-disclosure] [Fwd: The New World of Work]
      ... Microsoft has evolved to build bridges between ... information workers spend up to 30 percent of their working day just ... agile and productive in the global economy is to stop automation and the ... attend useless business meetings. ...
      (Full-Disclosure)
    • Re: [Full-disclosure] Security Alert: Unofficial IE patches appear on internet
      ... created by a vulnerability is as serious as this case and the available ... Microsoft will be inclined strongly against holding on to this patch. ... Microsoft often have patches ready but wait for the corporate known ...
      (Full-Disclosure)
    • Re: Worm in Patch
      ... a naive and trusting nature in your personality believing that you would ... "receive a patch" instead of getting it from a trusted source..? ... Essentially - Microsoft never emails you a patch. ... using Windows XP "prettifications". ...
      (microsoft.public.windowsxp.security_admin)