[PLUG] A moment of silence please
Russ Johnson
russj at dimstar.net
Thu Aug 14 15:31:02 UTC 2003
* Steve Beattie <steve at wirex.net> [2003-08-14 14:18]:
> Just because a machine might not have local users does not mean local
> root escalation vulnerabilities should be ignored.
I agree, to a point. Each vulnerability needs to be evaluated and the
system admin should determine if the systems they administer need
something done.
> It's hard enough to get users/admins to apply security
> patches -- Eric Rescorla's study of the openssl vulnerability
> <http://www.rtfm.com/upgrade.pdf> showed that 30 days *after* the slapper
> worm was announced, roughly 35% of hosts he monitored still had not
> patched openssl. Do we really need to encourage people to brag about
> not applying security updates in the name of a big uptime?
However, to apply updates "because they exist" makes us no better than
MS drones that update Windows because MS issued a patch.
My point is that neither of us know if the machine in question had ssl
installed, or in fact, if it had any vulnerabilities that mattered in
the grand scheme. It may not have had any user accounts. The only person
that knows (most likely) is the system admin.
--
Russ Johnson
Dimension 7/Stargate Online
http://www.dimstar.net
Top post? http://www.caliburn.nl/topposting.html
Random thought #3 (Collect all 19)
"Education is what remains after one has forgotten everything he learned in school." - Albert Einstein
More information about the PLUG
mailing list