Re: controversial paper

From: George Ou (533george_ou234_at_netzero234.com)
Date: 09/30/03


Date: Tue, 30 Sep 2003 05:34:11 GMT

On Tue, 30 Sep 2003 01:59:43 GMT, "Rickey Braddam"
<sharedsecrets@earthlink.net> wrote:

>Please don't interpret this as a personal attack. I'll do my
>best to never engage in a personal attack, and rely on the
>others here to point it out to me if I do. As one who makes
>my share of mistakes, and maybe more, I have no standing to
>critisize anyone for making a mistake. I'd just like to see
>(figuratively) you and Doug Gwyn, and maybe a couple others
>whose names don't pop off the top of my head right now,
>shake hands, pat each other on the back, and rejoin the
>group in friendly exchange of ideas.
>
>Rick

Fair enough.

But to be clear, I admitted that I should have said "known" in my
sentences. I just think it is cheap to take advantage of that minor
error in lack of clarity and try to twist some whole new meaning out
of it. I'll be more careful and use "known" in the future.

To sum up my position:
Microsoft, Sun, Oracle, Linux, SAMBA, BIND, Sendmail, IBM, Cisco, and
every other piece of software ALL have vulnerabilities known and
unknown. The current situation is that Microsoft software and OS is
so common that any vulnerability is felt through out the entire world.
The upside to that is that all these WORMs have had a tremendous
vaccine affect and now Windows systems are the most patched systems in
the world because they will die if they don't. Every other admin and
my own shop have gotten all critical updates installed through out
their network.

Microsoft in the past put way too much emphasis on ease of
configuration and tried to enable everything but the kitchen sink, and
they've learned a hard lesson for it and have reversed their "default
install" philosophy. Just look at Windows 2003 and how it's locked
down out of the box to the point that it's frustrating to people use
to the old Microsoft.

When I do an audit of most networks, the most blatant vulnerabilities
I see now are the Unix systems running Oracle, Sendmail, Solaris, and
Apache. It is the most difficult to patch are the Oracle systems
because they're so critical and difficult to schedule an outage, not
to mention that you're afraid you might break something or that
something isn't supported. Some of the other major holes on corporate
networks are Cisco IOS switches. Most companies have patched their
outward facing routers, but they have not done their internal IOS
switches. The fact that the average Joe Smith is not running Solaris,
Sendmail, or some of the other things I mentioned above might seem
like you're safe, but there is no reason Windows WORMS (or what ever
dominant OS of the future) can't be built to jump platforms and attack
everything else. The day that happens, the "unbreakable" crowd is
going to see the face of hell and the illusion of safety in diversity
will be shattered.

George Ou
http://www.LANArchitect.net



Relevant Pages

  • Re: 802.1X Setup using Server 03 and Aironet 1200 Series WAP help
    ... Office/Home Office or Small Organization Networks" ... communication between the wireless client and IAS just was not ... most of the 170 pg Microsoft pdf located at the link below. ... Windows" documentation http://technet.microsoft.com/en-us/library/bb457068.aspx ...
    (microsoft.public.internet.radius)
  • Networking Issues between WinXP client and Win2000 Svr
    ... My company is a Microsoft OEM and since the introduction of Windows XP ... we have been converting our networks over from Win95/98/NT to Windows ... We have been forced to bring documentation to our network customers ...
    (microsoft.public.windowsxp.general)
  • Re: Userenv EventId:1000 Access is denied
    ... If you get a warning that other installs may stop working if you ... on a network where you have configured your Windows 2000 ... This update only affects networks running Windows 2000 or Windows ... If you still want to have Q329170 installed, here is the latest from Microsoft: ...
    (microsoft.public.win2000.security)
  • Re: Uninstall Network Sign on.
    ... Networks, File and Printer Sharing for Microsoft Networks and Internet ... Protocol TC/IP with the addition of the AEGIS item on my wireless connection ... of this window in a blue border area, it says Windows Security. ...
    (microsoft.public.windowsxp.network_web)
  • Re: WMP 9 Requires Admin Rights Addendum
    ... I'm not making a personal attack unless you feel ... Windows and it's subsystems I guess. ... See http://zachd.com/pss/pss.html for some helpful WMP info. ... only "driver" incompatibility or improper installation lies with the ...
    (microsoft.public.multimedia.windows.mediaplayer)