|
BugTraq
Preventing exploitation with rebasing Feb 04 2003 05:08AM David Litchfield (david ngssoftware com) (7 replies) Re: Preventing exploitation with rebasing Feb 05 2003 01:41PM dullien gmx de (1 replies) Re: Preventing exploitation with rebasing Feb 04 2003 10:52PM David Litchfield (david ngssoftware com) (2 replies) Re: Preventing exploitation with rebasing Feb 04 2003 02:00PM sd hysteria sk (1 replies) Re: Preventing exploitation with rebasing Feb 04 2003 11:20PM David Litchfield (david ngssoftware com) Re: Preventing exploitation with rebasing Feb 04 2003 02:00PM Torbjörn Hovmark (torbjorn hovmark abtrusion com) Re: Preventing exploitation with rebasing Feb 04 2003 11:38AM Charlie Root (weedpower home ro) (4 replies) Re: Preventing exploitation with rebasing Feb 06 2003 01:00AM Deus, Attonbitus (Thor HammerofGod com) Re: Preventing exploitation with rebasing Feb 04 2003 08:08PM Brian Hatch (bugtraq ifokr org) (2 replies) Re: Preventing exploitation with rebasing Feb 04 2003 05:26PM Alan DeKok (aland freeradius org) (2 replies) Re: Can't Preventing exploitation with rebasing Feb 05 2003 10:06AM bugtraq gaza halo nu (2 replies) Observation on randomization/rebiasing... Feb 05 2003 09:10PM Nicholas Weaver (nweaver CS berkeley edu) (1 replies) Re: Preventing exploitation with rebasing Feb 04 2003 06:38PM David Litchfield (david ngssoftware com) (1 replies) Re: [VulnDiscuss] Re: Preventing exploitation with rebasing Feb 05 2003 05:32PM Halvar Flake (halvar gmx net) Re: Preventing exploitation with rebasing Feb 04 2003 11:34AM Eugene Tsyrklevich (eugene securityarchitects com) Re: [VulnDiscuss] Preventing exploitation with rebasing Feb 03 2003 09:49PM Michal Zalewski (lcamtuf coredump cx) |
|
Privacy Statement |
> I fail to see how adding security that doesn't have a performance
> or stability cost is ever a bad thing.
Agreed. I'm not sure, however, that David's idea doesn't have an
affect on stability. Not the stability of a single server but on an
environment consisting of many servers. I'm not Windows wizard, but
I'll accept from everything I've already read in this thread that
rebasing on a single system will not have a negative impact on it.
However I question how will it scale to several tens of servers, which
is my problem? Is there an easy way to automate it such that it is
done after patch application? Considering how difficult and/or
expensive, take your pick, it is to apply patches in an automated
fashion on Windows systems I suspect not. Moreover, I gather that for
the solution to be effective, each system should be rebased
differently requiring even more planning to get it right even if
automation were easy. This should not be taken as an indictment of
the idea, just asking that when implementing security solutions on
individual machines, the keepers of security should consider the
issues of scale that we sysadmins have to deal with.
Thanks,
--
Dave Goldberg
Associate Department Head, G06A: Advanced Technical Computing Center
The Mitre Corporation \ MS K331 \ 202 Burlington Rd. \ Bedford, MA 01730
dsg (at) mitre (dot) org [email concealed] \ 781-271-3887
[ reply ]