RE: Releasing patches is bad for security

From: Ross M. W. Bennetts (rbennett_at_une.edu.au)
Date: 02/26/04

  • Next message: a55mnky_at_yahoo.com: "Nmap - 3.50 changes mstask.exe?"
    To: <incidents@securityfocus.com>
    Date: Fri, 27 Feb 2004 09:39:10 +1100
    
    

    > The vulnerability was discovered by Eeye Digital Security in July 2003 but
    > no exploits were produced until three days after Microsoft's patch became
    > available.

    [Ross M. W. Bennetts]
    But if a hacker did produce an exploit wouldn't he/she be more likely to use
    it surreptitiously for their own private purposes and then only release it
    to the kiddies on the net after the patch has been released?

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: a55mnky_at_yahoo.com: "Nmap - 3.50 changes mstask.exe?"

    Relevant Pages

    • RE: Microsoft Security Advisory MS 03-007 - Problems
      ... I think that one of the most important things to remember about this patch ... My first install on a freslhly built W2K ... How a Hacker Uses SQL Injection to Steal Your SQL Data! ...
      (Focus-Microsoft)
    • Re: rumours about new RPC DCOM vulnerability
      ... the hacker that got me used 3 or 4 programs and 2 ... that patch DID fix everything it was supposed to. ... >> RPC DCOM vulnerability that is not fixed with patch ...
      (microsoft.public.security)
    • RPC/NT Authority
      ... it is finding you through rpc files...read the the fix! ... it is a little criptic but, the patch ... We were able fight off our hacker by turning on our xp ...
      (microsoft.public.windowsxp.security_admin)
    • Re: [Full-disclosure] Unofficial Microsoft patches help hackers, not security
      ... [The consumer goes along to Windows Update on Tuesday and doesn't think they need a patch, because Microsoft tells them its not needed. ... Little does the consumer know their machine was patched by a hacker, who now has control over their ... It means the unofficial patch is as harmful as the vulnerability and exploit ... Hacker patches vulnerability ...
      (Full-Disclosure)
    • Re: IO-APIC on nforce2 [PATCH] + [PATCH] for nmi_debug=1 + [PATCH] for idle=C1halt, 2.6.5
      ... certain amount or NOT using AGP stabilizes it to an amount... ... I am using Ross' C1halt patch to make the system stable ...
      (Linux-Kernel)