Re: Releasing patches is bad for security

From: Pall Thayer (pall_at_fa.is)
Date: 02/26/04

  • Next message: james: "Re: Releasing patches is bad for security"
    To: "Curt Purdy" <purdy@tecman.com>, "'Chris Brenton'" <cbrenton@chrisbrenton.org>, <incidents@securityfocus.com>
    Date: Thu, 26 Feb 2004 21:43:35 -0000
    
    

    According to slashdot he also said "I can only think of one time that a
    vulnerability was exploited before a patch was issued." Apparently he said
    this shortly after saying "We have never had vulnerabilities exploited
    before the patch was known."

    Pall Thayer
    artist/teacher
    Fjolbrautaskolinn vid Armula
    http://www.this.is/pallit
    http://www.this.is/pallit/isjs
    http://www.this.is/pallit/harmony
    http://130.208.220.190/panse

    ----- Original Message -----
    From: "Curt Purdy" <purdy@tecman.com>
    To: "'Chris Brenton'" <cbrenton@chrisbrenton.org>;
    <incidents@securityfocus.com>
    Sent: Thursday, February 26, 2004 8:05 PM
    Subject: RE: Releasing patches is bad for security

    > Chris Brenton wrote:
    >
    > > This is just such a hoot I had to share:
    > > http://news.bbc.co.uk/1/hi/technology/3485972.stm
    > > The story quotes David Aucsmith, who is in charge of technology at
    > > Microsoft's security business and technology unit as stating:
    > >
    > > "We have never had vulnerabilities exploited before the patch was
    > > known,"
    >
    > Then how did I get a copy of dcom.exe 2 days before they released the DCom
    > RPC patch. And it was surely in the deep underground longer than that. A
    > very effective exploit too, giving you a command line in 5 seconds on an
    > unpatched box.
    >
    > I would call it less of a hoot and more like a baldface lie.
    >
    > Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA
    > Information Security Engineer
    > DP Solutions
    >
    > ----------------------------------------
    >
    > If you spend more on coffee than on IT security, you will be hacked.
    > What's more, you deserve to be hacked.
    > -- White House cybersecurity adviser Richard Clarke
    >
    >
    >
    > --------------------------------------------------------------------------
    -
    > --------------------------------------------------------------------------

    --
    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------
    

  • Next message: james: "Re: Releasing patches is bad for security"

    Relevant Pages

    • Re: Its not that simple... [Was: Re: [Full-disclosure] Disney Down?]
      ... PnP is not a show stopper when it comes to patch compatibility testing ... "Successful exploitation of this vulnerability could be leveraged to ... "If it had been International Paper or some company like ... > to take security matters more seriously. ...
      (Full-Disclosure)
    • Re: NT4 patch for MS00-084??
      ... there is no such patch to be found on the technet security ... > "Microsoft has released a patch that eliminates a security ... > vulnerability in Microsoft® Indexing Services for Windows 2000. ...
      (microsoft.public.security)
    • Download.ject - commentary - LONG
      ... vulnerability in question, but instead is just a partial workaround. ... ADDITION to applying the 870669 patch. ... Granted these are known security best practices related to Internet ... a new default browser to users and hope that it will be safe enough. ...
      (microsoft.public.win2000.security)
    • Re: Download.ject - commentary - LONG
      ... > patch recently released by Microsoft. ... > vulnerability in question, but instead is just a partial workaround. ... > Granted these are known security best practices related to Internet ... > a new default browser to users and hope that it will be safe enough. ...
      (microsoft.public.win2000.security)
    • Vulnerability Details for MS02-012
      ... Microsoft released a patch for a denial of service ... vulnerability in the Windows 2000 SMTP component. ... This bug affects all Windows 2000 systems running the SMTP service that have ...
      (Bugtraq)