Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
The Buck Stops Where?
Tim Mullen, 2002-04-15

Don't blame Microsoft. They gave you the patch; it's your responsibility to use it.

Comments Mode:
The Buck Stops Where? 2002-04-15
Nighthawk (3 replies)
The Buck Stops Where? 2002-04-16
Anonymous (1 replies)
The Buck Stops Where? 2002-05-06
Anonymous
The Buck Stops Where? 2002-04-17
hmmm... (1 replies)
The Buck Stops Where? 2002-04-23
dave.williams@gte.net
The Buck Stops Where? 2002-04-30
Bruno Ferreira
The Buck Stops Where? 2002-04-15
MG (1 replies)
The Buck Stops Where? 2002-04-16
Anonymous (1 replies)
Sounds like you're running quite a large scale environment there with your "web portal".

How do you justify the risks associated with deploying these patches? What kind of testing, lab environment, staffing, etc do you use to mitigate the risks? How many SYSTEMS do you use with unique applications? How do you suggest a company with, say, 10,000 web servers running different applications test these patches?

Tim's article holds water for only the smallest companies that have simplistic configurations. Microsoft's patches DO break servers, and unless we're dealing with a Nimda or Code Red, the cure is worse than the disease most of the time. The best thing is to isolate these systems on a DMZ, monitor the hell out of them, and wait until FORMAL testing can be done for all crucial systems before deploying them.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/74/11893#11893
The Buck Stops Where? 2002-04-18
MG (2 replies)
The Buck Stops Where? 2002-04-20
Willie (1 replies)
The Buck Stops Where? 2002-04-23
Anonymous
The Buck Stops Where? 2002-04-22
Anonymous
The Buck Stops Where? 2002-04-15
Anonymous
The Buck Stops Where? 2002-04-16
Willie (2 replies)
The Buck Stops Where? 2002-04-17
Anonymous (1 replies)
The Buck Stops Where? 2002-04-20
Anonymous
The Buck Stops Where? 2002-04-23
Anonymous
The Buck Stops Where? 2002-04-16
Anonymous
Responsibility? 2002-04-16
Anonymous
The Buck Stops Where? 2002-04-16
Andy
The Buck Stops Where? 2002-04-16
Anonymous
The Buck Stops Where? 2002-04-16
Anonymous (1 replies)
The Buck Stops Where? 2002-04-17
Anonymous (1 replies)
The Buck Stops Where? 2002-04-18
Anonymous
The Buck Stops Where? 2002-04-16
Anon (3 replies)
The Buck Stops Where? 2002-04-17
Anonymous
The Buck Stops Where? 2002-04-18
Anonymous
The Buck Stops Where? 2002-05-05
Anonymous
The Buck Stops Where? 2002-04-16
Anonymous
The Buck Stops Where? 2002-04-16
Anonymous
The Buck Stops Where? 2002-04-17
Anonymous (1 replies)
The Buck Stops Where? 2002-04-17
Anonymous
The Buck Stops Where? 2002-04-17
Mel
The Buck Stops Where? 2002-04-17
blacklight
The Buck Stops Where? 2002-04-18
Anonymous
It all comes down to these things. 2002-04-19
Noseman (1 replies)
The Buck Stops Where? 2002-04-19
Owen Creger
The Buck Stops Where? 2002-04-19
Sculder
The Buck Stops Where? 2002-04-19
Anonymous
The Buck Stops Where? 2002-04-19
Anonymous
The Buck Stops Where? 2002-04-22
ali abolfathi (1 replies)
The Buck Stops Where? 2002-04-23
Anonymous
Blame the (Em)balmer? 2002-04-23
dave.williams@gte.net (1 replies)
Blame the (Em)balmer? 2002-04-29
Stefan
The Buck Stops Where? 2002-04-23
Jim
The Buck Stops Where? 2002-04-23
blacklight
The Buck Stops Where? 2002-04-26
Bakdosh
The Buck Stops Where? 2002-04-29
Anonymous (1 replies)
The Buck Stops Where? 2002-05-04
Anonymous
The Buck Stops Where? 2002-05-01
Anonymous
The Buck Stops Where? 2002-05-02
Anonymous
The Buck Stops Where? 2002-05-06
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus