Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
The Buck Stops Where?
Tim Mullen, 2002-04-15

Don't blame Microsoft. They gave you the patch; it's your responsibility to use it.

Comments Mode:
The Buck Stops Where? 2002-04-15
Nighthawk (3 replies)
The Buck Stops Where? 2002-04-16
Anonymous (1 replies)
The Buck Stops Where? 2002-05-06
Anonymous
The Buck Stops Where? 2002-04-17
hmmm... (1 replies)
The Buck Stops Where? 2002-04-23
dave.williams@gte.net
The Buck Stops Where? 2002-04-30
Bruno Ferreira
The Buck Stops Where? 2002-04-15
MG (1 replies)
The Buck Stops Where? 2002-04-16
Anonymous (1 replies)
The Buck Stops Where? 2002-04-18
MG (2 replies)
The Buck Stops Where? 2002-04-20
Willie (1 replies)
The Buck Stops Where? 2002-04-23
Anonymous
The Buck Stops Where? 2002-04-22
Anonymous
The Buck Stops Where? 2002-04-15
Anonymous
The Buck Stops Where? 2002-04-16
Willie (2 replies)
The Buck Stops Where? 2002-04-17
Anonymous (1 replies)
The Buck Stops Where? 2002-04-20
Anonymous
The Buck Stops Where? 2002-04-23
Anonymous
The Buck Stops Where? 2002-04-16
Anonymous
Responsibility? 2002-04-16
Anonymous
The Buck Stops Where? 2002-04-16
Andy
The Buck Stops Where? 2002-04-16
Anonymous
The Buck Stops Where? 2002-04-16
Anonymous (1 replies)
The Buck Stops Where? 2002-04-17
Anonymous (1 replies)
The Buck Stops Where? 2002-04-18
Anonymous
The Buck Stops Where? 2002-04-16
Anon (3 replies)
The Buck Stops Where? 2002-04-17
Anonymous
The Buck Stops Where? 2002-04-18
Anonymous
Everyone's situation is different.

We have a webmaster and his incompetent staff who hardly know anything about Microsoft products .asp and other Ms stuff they push to do their development. So imagine the boat I am in trying to convince these bozos to switch platforms to Unix/Linux hardened systems running Apache!

All they know is that this other stuff outside of MS is buzzwords they are so lost. So convincing departments and managers they need to get off MS and .asp is not as easy as it sounds...to much political crap...plus they would have to actually learn .php, Java Unix/Linux shell/scripting etc...which they don't have the ability to do in our organization...just too much incompetence going around.

Also, you can't expect Microsoft to test everything out there with a patch...example...we had a 5 year old Compaq with old raid adapter and drivers...guess what?!?! Security patch somehow broke the driver...well reboot time and...whoops...no more booting...server down....

Is MS really responsible for testing all hardware compatibility as it pertains to scenarios like this? Not in my opinion...it's our bad for running on antiquated servers and technology...that is life in the business...I'm not letting them off the hook by these statements, just see this side of due diligence they are required is all I am asking...

A simple plan to harden OS/IIS and monitoring security updates...logs...and best practices is all that is needed to make these boxes 99.99 percent secure...nothing is 100 percent as we know. Better than the 10 percent when you take all the defaults...

There are plenty of docs out there on how to do this...While you have some extra time with a hardened windows install..help me convince our web team to get off these darn MS boxes...Please!!!



[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/74/11948#11948
The Buck Stops Where? 2002-05-05
Anonymous
The Buck Stops Where? 2002-04-16
Anonymous
The Buck Stops Where? 2002-04-16
Anonymous
The Buck Stops Where? 2002-04-17
Anonymous (1 replies)
The Buck Stops Where? 2002-04-17
Anonymous
The Buck Stops Where? 2002-04-17
Mel
The Buck Stops Where? 2002-04-17
blacklight
The Buck Stops Where? 2002-04-18
Anonymous
It all comes down to these things. 2002-04-19
Noseman (1 replies)
The Buck Stops Where? 2002-04-19
Owen Creger
The Buck Stops Where? 2002-04-19
Sculder
The Buck Stops Where? 2002-04-19
Anonymous
The Buck Stops Where? 2002-04-19
Anonymous
The Buck Stops Where? 2002-04-22
ali abolfathi (1 replies)
The Buck Stops Where? 2002-04-23
Anonymous
Blame the (Em)balmer? 2002-04-23
dave.williams@gte.net (1 replies)
Blame the (Em)balmer? 2002-04-29
Stefan
The Buck Stops Where? 2002-04-23
Jim
The Buck Stops Where? 2002-04-23
blacklight
The Buck Stops Where? 2002-04-26
Bakdosh
The Buck Stops Where? 2002-04-29
Anonymous (1 replies)
The Buck Stops Where? 2002-05-04
Anonymous
The Buck Stops Where? 2002-05-01
Anonymous
The Buck Stops Where? 2002-05-02
Anonymous
The Buck Stops Where? 2002-05-06
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus