RE: Releasing patches is bad for security

From: Curt Purdy (purdy_at_tecman.com)
Date: 02/26/04

  • Next message: mgotts_at_2roads.com: "Re: Releasing patches is bad for security"
    To: "'Chris Brenton'" <cbrenton@chrisbrenton.org>, <incidents@securityfocus.com>
    Date: Thu, 26 Feb 2004 14:05:05 -0600
    
    

    Chris Brenton wrote:

    > This is just such a hoot I had to share:
    > http://news.bbc.co.uk/1/hi/technology/3485972.stm
    > The story quotes David Aucsmith, who is in charge of technology at
    > Microsoft's security business and technology unit as stating:
    >
    > "We have never had vulnerabilities exploited before the patch was
    > known,"

    Then how did I get a copy of dcom.exe 2 days before they released the DCom
    RPC patch. And it was surely in the deep underground longer than that. A
    very effective exploit too, giving you a command line in 5 seconds on an
    unpatched box.

    I would call it less of a hoot and more like a baldface lie.

    Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA
    Information Security Engineer
    DP Solutions

    ----------------------------------------

    If you spend more on coffee than on IT security, you will be hacked.
    What's more, you deserve to be hacked.
    -- White House cybersecurity adviser Richard Clarke

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: mgotts_at_2roads.com: "Re: Releasing patches is bad for security"

    Relevant Pages

    • Re: OT - Worth a read ... then cry.
      ... think of what is best for America. ... the most to their campaigns to keep them in office. ... I wanna say, "DUH", for your stating the obvious, but I guess I shouldn't ... Not the security, which was trivial, but the insane ...
      (rec.woodworking)
    • Windows security updates notice
      ... As soon as I got online today, a Windows Messenger ... enclosed link to download a security fix--something about ... it's stating I need to get a lot of updates (which I do ...
      (microsoft.public.security)
    • Re: Settings
      ... >language settings for both mail & NGs in Outlook Express (as opposed to ... >HTML) stating that this is a security issue. ...
      (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
    • Re: FullTilt Support too busy to care about collusion
      ... what I'm saying is it's SOP for FullTilt to reply to the message ... stating that they are sending it to their security team for further ... Very few companies do that when they're treating the situation as a security ...
      (rec.gambling.poker)
    • chkdsk /f replacing security ids with default ones (lots of them)
      ... array.. ... it was stating the drive may contain errors.. ... "replacing invalid security id with default security id for file xxxx" ... Chkdsk discovered free space marked as allocated in the master file ...
      (microsoft.public.windows.server.general)