Thoughts Media.com

 


Windows Phone Thoughts

Loading feed...

Digital Home Thoughts

Loading feed...

Apple Thoughts

Loading feed...




Go Back   Thoughts Media Forums > Thoughts Media Off Topic

Reply
 
Thread Tools Display Modes
  #1  
Old 09-11-2003, 09:00 PM
Janak Parekh
Editor Emeritus
Janak Parekh's Avatar
Join Date: Aug 2006
Posts: 15,171
Default Patch Your Windows Boxes -- Again

http://news.com.com/2100-1002-5074415.html?tag=nl

Another very serious vulnerability in Windows NT/2k/XP/2k3 RPC services was announced yesterday, and it could enable another Blaster to hit the Internet if people don't patch their boxes soon. Translated: we will see another worm, because there are just enough people out there that don't know how to patch or won't be able to roll it out to all of their systems in time. :?

What I'm truly worried about is a "cross-vector" worm -- one that spreads BOTH via vulnerabilities and email. This way, it can get past the firewall to the internal network as long as someone executes it. I expect it to exist one day, and that will truly will shake up people's consciousness about security. I hope. Anyway, make sure you hit Windows Update, use a virus scanner, and have a firewall and you should be all set.
 
Reply With Quote
  #2  
Old 09-11-2003, 09:18 PM
easylife
Theorist
Join Date: Jul 2003
Posts: 258
Default Re: Patch Your Windows Boxes -- Again

Quote:
Originally Posted by Janak Parekh
What I'm truly worried about is a "cross-vector" worm
What about cross-platform viruses? :lol: Oh yes, I believe everything I read on BBSpot. :wink:
 
Reply With Quote
  #3  
Old 09-11-2003, 09:25 PM
Ed Hansberry
Contributing Editor Emeritus
Ed Hansberry's Avatar
Join Date: Aug 2006
Posts: 8,228
Default Re: Patch Your Windows Boxes -- Again

Quote:
Originally Posted by Janak Parekh
boxes soon and/or use firewalls.
then
Quote:
What I'm truly worried about is a "cross-vector" worm -- one that spreads BOTH via vulnerabilities and email.
This is why anyone that thinks a firewall is protection is just fooling themselves. Patch your @$*(&@ system!!!

I can think of a dozen ways to get an infected machine/worm behind a VPN in a company with 5,000 employees. The firewall doesn't do diddly. Patch, patch and then patch. I personally just wish people would quit saying a firewall is valid. It is as asinine, IMHO, as walking into a community infected with small pox while wearing a protective suit. Chances are, the longer you stay in the community, the higher your chances are of getting infected. Get the vaccine. Patch.
__________________
text sig
 
Reply With Quote
  #4  
Old 09-11-2003, 09:37 PM
Janak Parekh
Editor Emeritus
Janak Parekh's Avatar
Join Date: Aug 2006
Posts: 15,171
Default Re: Patch Your Windows Boxes -- Again

Quote:
Originally Posted by Ed Hansberry
This is why anyone that thinks a firewall is protection is just fooling themselves. Patch your @$*(&@ system!!!
Sorry, I didn't mean it that way. I meant to say that because people won't patch AND because they won't use firewalls, they'll get hacked. Firewalls are an extra line of defense, but not a complete defense themselves. Post edited.

--janak
 
Reply With Quote
  #5  
Old 09-11-2003, 09:40 PM
Ed Hansberry
Contributing Editor Emeritus
Ed Hansberry's Avatar
Join Date: Aug 2006
Posts: 8,228
Default Re: Patch Your Windows Boxes -- Again

Quote:
Originally Posted by Janak Parekh
Quote:
Originally Posted by Ed Hansberry
This is why anyone that thinks a firewall is protection is just fooling themselves. Patch your @$*(&@ system!!!
Sorry, I didn't mean it that way. I meant to say that because people won't patch AND because they won't use firewalls, they'll get hacked. Firewalls are an extra line of defense, but not a complete defense themselves. Post edited.

--janak
Thanks. Just don't let it happen again. :wink: :rotfl:
__________________
text sig
 
Reply With Quote
  #6  
Old 09-11-2003, 09:59 PM
Sslixtis
Thinker
Join Date: Feb 2002
Posts: 400
Send a message via MSN to Sslixtis

Ahh, the Love! pclove:

Feels almost like home! :rotfl:
 
Reply With Quote
  #7  
Old 09-11-2003, 10:11 PM
qmrq
Thinker
Join Date: Jul 2003
Posts: 443
Default Re: Patch Your Windows Boxes -- Again

Quote:
Originally Posted by Ed Hansberry
The firewall doesn't do diddly.
Exagerating a bit, eh?

I suggest everyone install BeOS, or buy macs. 8)
 
Reply With Quote
  #8  
Old 09-11-2003, 10:27 PM
brianchris
Philosopher
brianchris's Avatar
Join Date: Sep 2006
Posts: 533

I am NOT arguing that people should not patch their systems, as they absolutely should, but immediately and blindy patching has its own issues, right? We are all aware of MS patches that have been pulled becuase they caused issues equal to or greater than those problems they were created to fix. As far as a client is concerned, it really isn't too important to them whether their server is down due to a virus or a patch.....their server is down. This is similar to the seatbelt argument in which there are a number of "what-if" scenarios where a seatbelt would do more harm than good, however those are few and far between. Chances are, you're safer with the seatbelt than without, and you're safer with the patch than without.

My only point is, just as firewall's aren't perfect, neither is patching.....its a jungle out there

-Brian
 
Reply With Quote
  #9  
Old 09-11-2003, 10:30 PM
icatar
Ponderer
Join Date: Mar 2004
Posts: 88
Send a message via MSN to icatar Send a message via Yahoo to icatar

I read an interesting bit that said that one of the problems is that Microsoft announces the vulnerability which then allows all the hackers to go ahead and exploit it, knowing full well that not everyone is going to have it patched.

As I sit here and plan a patch deployment to 2500 systems (again!), I wonder whether it would be better if Microsoft would just not announce the vulnerability and we can live blissfully in ignorance!
 
Reply With Quote
  #10  
Old 09-11-2003, 10:47 PM
Jeff Rutledge
Moderator Emeritus
Jeff Rutledge's Avatar
Join Date: Aug 2006
Posts: 1,998

Quote:
Originally Posted by icatar
I read an interesting bit that said that one of the problems is that Microsoft announces the vulnerability which then allows all the hackers to go ahead and exploit it, knowing full well that not everyone is going to have it patched.

As I sit here and plan a patch deployment to 2500 systems (again!), I wonder whether it would be better if Microsoft would just not announce the vulnerability and we can live blissfully in ignorance!
I somewhat agree with you there. I think the problem with that though is that it's usually Security firms that discover the vulnerability so that information is already "out there" so MS has to announce it.
 
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 09:27 PM.


Powered by vBulletin® Version 3.8.9
Copyright ©2000 - 2019, vBulletin Solutions, Inc.
Copyright Thoughts Media Inc. 2009