[PLUG] A moment of silence please
Steve Beattie
steve at wirex.net
Thu Aug 14 20:00:03 UTC 2003
On Thu, Aug 14, 2003 at 03:30:54PM -0700, Russ Johnson wrote:
> * Steve Beattie <steve at wirex.net> [2003-08-14 14:18]:
> > Just because a machine might not have local users does not mean local
> > root escalation vulnerabilities should be ignored.
>
> I agree, to a point. Each vulnerability needs to be evaluated and the
> system admin should determine if the systems they administer need
> something done.
Absolutely. However, IMHO, the bragging ability of the administrator in
having a large uptime should not be factored into that decision.
> However, to apply updates "because they exist" makes us no better than
> MS drones that update Windows because MS issued a patch.
Given the rpc worm going around, I'd rather more MS drones were actually
patching.
However, you will get no argument from me that whether to patch and
when to patch are complicated issues. We presented a paper at LISA 2002
that tried to come up with a simple model about making that decision,
and attempted to collect some data on patch quality to help make that a
rational decision ("Timing the Application of Security Patches for Optimal
Uptime" <http://www.nxnw.org/~steve/papers/lisa2002-time-to-patch.pdf>).
Funnily enough, it was apparently a controversial paper with the program
committee, because there were several members who believed there's no
other answer to "When to patch?" than immediately.
Ultimately, the patch and pray cycle is a failed approach to system
administration, but it's roughly the best we've got. Approaches like what
Immunix, OpenBSD, and others are doing I believe will mitigate issues
and help us get out of this mess in the long term, but we're all still
issuing security advisories.
> My point is that neither of us know if the machine in question had ssl
> installed, or in fact, if it had any vulnerabilities that mattered in
> the grand scheme. It may not have had any user accounts. The only person
> that knows (most likely) is the system admin.
Mostly there's two prongs to my rant:
(1) the absence or presence of user accounts is a red herring. I've
seen posts to plug and other lists where someone will say they
don't need to apply a particular patch because it's a locally
exploitable vulnerability and they're the only user. This is
mis-guided because all the exploit requires is a shell, not a
normally authenticated user shell.
(2) uptime dicksize wars. When I've played systems administrator (I'm
a bug producer^W^Wdeveloper now), I'd much rather have a system
where I had to have planned downtime once every three months that
lasted 5 minutes versus a system that had an uptime for a year,
but took me a week or more to recover from being 0wned. (Don't
believe it can take that long or longer? Look at all the work the
FSF people are having to do to recover ftp.gnu.org.)
Anwyay, thanks for the discussion and suffering through my rants. I hope
this has been enlightening for somebody.
--
Steve Beattie Don't trust programmers?
<steve at wirex.net> Complete StackGuard distro at
http://NxNW.org/~steve/ immunix.org
http://www.sardonix.org -- Audit code, earn respect.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: not available
URL: <http://lists.pdxlinux.org/pipermail/plug/attachments/20030814/8d06b8ac/attachment.asc>
More information about the PLUG
mailing list