Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Does Microsoft Give a Damn?
George Smith, 2003-09-15

The software-maker's dismal security record seems to have left it immune to criticism and shame.

Comments Mode:
Does Microsoft Give a Damn? 2003-09-15
Anonymous (6 replies)
Does Microsoft Give a Damn? 2003-09-15
Anonymous (1 replies)
Does Microsoft Give a Damn? 2003-09-18
Anonymous (1 replies)
Does Microsoft Give a Damn? 2003-09-23
Anonymous
One problem w/ SUS: 2003-09-16
Penguinisto (1 replies)
One problem w/ SUS: 2003-09-18
Anonymous (1 replies)
One problem w/ SUS: 2003-09-19
penguinisto
Does Microsoft Give a Damn? 2003-09-16
Anonymous
Does Microsoft Give a Damn? 2003-09-17
Anonymous
Does Microsoft Give a Damn? 2003-09-17
Anonymous
Make that Two problems with SUS 2003-09-23
Anonymous
We Must Do Our Job 2003-09-15
Sean M. Lynch (2 replies)
Patch, reboot, patch, reboot.... 2003-09-16
Anonymous (1 replies)
Patch, reboot, patch, reboot.... 2003-09-17
Anonymous (2 replies)
Patch, reboot, patch, reboot.... 2003-09-18
Anonymous
Patch, reboot, patch, reboot.... 2003-09-18
Anonymous
We Must Do Our Job 2003-09-16
Anonymous (2 replies)
We Must Do Our Job 2003-09-17
Mark Kovacic
We Must Do Our Job 2003-09-17
Anonymous (1 replies)
Yes and no... 2003-09-18
Penguinisto
Useless rhetoric 2003-09-15
Anonymous (2 replies)
Useless rhetoric 2003-09-16
Anonymous (2 replies)
Useless rhetoric 2003-09-16
Anonymous
Useless rhetoric 2003-09-17
Anonymous
Useless rhetoric 2003-09-17
Anonymous (1 replies)
Useless rhetoric 2003-09-17
Anonymous (2 replies)
Useless rhetoric 2003-09-20
Anonymous
Useless rhetoric 2003-09-21
Anonymous
Does Microsoft Give a Damn? 2003-09-16
Anonymous
Does Microsoft Give a Damn? 2003-09-16
Gary K (1 replies)
Does Microsoft Give a Damn? 2003-09-16
Anonymous
Gary wrote:
I'm saying that Microsoft has more patches out for their OS's than any other software provider, bar none.

This isn't true, at least when it comes to security specific patches - but - when it comes to most Windows admins it doesn't really matter who got the most/least patches out. Problem is they don't get installed period. Please read on and I'll explain.

Gary writes further:
The problem comes when people try to use Microsoft in "real companies" - IE, not a 20 PC shop run by someone who "knows computers" and got their favorite certification.

I'd like to think of my company as a "real company", with our 15'000+ clients and a few hundred servers. And yes, I do have a whole alphabet of certifications. (I'm the guy who wrote the first post).

Gary then makes a very valid statement:
I guess people can say "oh, you didn't run out and install the fix when daddy said so!" Well, unfortunately we can't afford unscheduled downtime, and I refuse to down servers every other week

I agree one hundred percent. But not all Microsoft patches are important. Why patch IE on a server that can't reach the internet (or other web servers)? However, when a patch like this RPC-DCOM comes along one really should drop everything and test, re-test and then deploy.

But this isn't what happens in most Windows shops (including the very large ones). One of my customers came crying that they've been torn apart by blaster. I went over to help them out and what do you know. Most of their servers (Win2K) where runing SP1, yes, that's correct Service Pack 1, released years ago. They thought they where safe cause their firewalls where running on linux (their quoute, not mine).

They where quite mad of course and wowed to port all their servers to linux as soon as possible.

Now think about that for a moment.

How often do you think people like that are going to patch their linux (or any other non-MS) servers?

This is what I fear is the worst problem with Windows based admins. The lack of interest in patching up (and locking down). Moving to another platform will not solve this. And if enough of these people move to then soon you will see not new blasters comming over the horizon, but a specific worm.

and Gary, all MS patches can be installed, scripted and run from the commandline ;)





[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/185/22337#22337
Does Microsoft Give a Damn? It doesn't matter 2003-09-16
Anonymous - Jerk (1 replies)
Does Microsoft Give a Damn? 2003-09-17
Anonymous (1 replies)
Does Microsoft Give a Damn? 2003-09-17
Anonymous
We Must Do Our Job 2003-09-17
Sean M. Lynch
Does Microsoft Give a Damn? 2003-09-17
Anonymous
Does Microsoft Give a Damn? 2003-09-17
Anonymous
Does Microsoft Give a Damn? 2003-09-17
E(Ces)
Does Microsoft Give a Damn? 2003-09-18
Anonymous
Does Microsoft Give a Damn? 2003-09-18
Anonymous (1 replies)
Does Microsoft Give a Damn? 2003-09-20
Anonymous
Does Microsoft Give a Damn? 2003-09-18
Anonymoose
Does Microsoft Give a Damn? 2003-09-18
Anonymous (1 replies)
Does Microsoft Give a Damn? 2003-09-19
Anonymous
Of Course They Dont::Does Microsoft Give a Damn? 2003-09-18
Linux, Torvald. Mr. Linux Torvald to you. (1 replies)
Stop the whining, George! 2003-09-18
Anonymous (1 replies)
Stop the whining, George! 2003-09-20
Anonymous
Shut Up !!! 2003-09-18
Anonymous (1 replies)
Does Microsoft Give a Damn? 2003-09-19
Anonymous (1 replies)
Only two Suse patches?!? 2003-09-19
Anonymous (1 replies)
Only two Suse patches?!? 2003-09-21
Anonymous (1 replies)
Only two Suse patches?!? 2003-09-23
Anonymous
Does Microsoft Give a Damn? 2003-09-19
Anonymous
How Interesting 2003-09-20
Sigmund Einstein
Does Microsoft Give a Damn? 2003-09-20
haloflightleader at yahoo dot com
Does Microsoft Give a Damn? 2003-09-21
Anonymous
Does Microsoft Give a Damn? 2003-09-26
penfold
Shrill 2003-09-26
Anonymous
Should Microsoft Give a Damn? 2003-09-26
mr_jinx







 

Privacy Statement
Copyright 2008, SecurityFocus