Re: Windows vulnerability vs Linux vulnerability [Re: Would a firewall

From: Lars M. Hansen (badnews_at_hansenonline.net)
Date: 05/06/04


Date: Thu, 06 May 2004 20:35:24 GMT

On Thu, 06 May 2004 12:10:53 -0400, Rowland spoketh

>1. So security patches are a bad thing? In that case, don't install any!

No, the patches are not bad, but there's a correlation between
vulnerabilities and patches that you're missing. Usually, there's a
patch for a vulnerability, thus by counting patches one can approximate
the number of vulnerabilities.

Lars M. Hansen
www.hansenonline.net
Remove "bad" from my e-mail address to contact me.
"If you try to fail, and succeed, which have you done?"



Relevant Pages

  • Re: [Full-disclosure] Getting Off the Patch
    ... patch a piece of software. ... patching is just a small part of the solution. ... One of the things with patches is, that people have an urge to apply them. ... who want audit verification of how vulnerabilities are being mitigated. ...
    (Full-Disclosure)
  • Re: [Full-Disclosure] Gates: You dont need perfect code for good security
    ... > the blaster worm preceded the patch so this argument is DOA ... vulnerabilities that were unknown, ... the security community can *hope* to stay up to date is with good patching / ... you should regularly install patches to protect systems ...
    (Full-Disclosure)
  • [Full-Disclosure] RE: Internet explorer 6 execution of arbitrary code (An analysis of the 180 Soluti
    ... And again each and every one of the method caching vulnerabilities liu and ... individuals, there I many many reasons why I dislike pivx, but I don't think ... registry patches nothing more, nothing less.. ... But ask yourself how seriously can you take a company that names 5 registry ...
    (Full-Disclosure)
  • RE: Patching
    ... There seems to be at least 5 or 6 new vulnerabilities released on ... As information security people, ... at those patches you need for what you do have running. ... network analyzers. ...
    (Security-Basics)
  • Re: Which Router for VPN and Webhosting
    ... > hats find the vulnerabilities before the white hats do. ... > seem to get most of their holes patched before the exploits hit the net. ... patches. ... who took a one-year "web programming" course, ...
    (alt.computer.security)