On TV.com: 11 Things U Don't Know About JOSS WHEDON
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 8 of 10:
Next »
« Previous
Loverock, you are an idiot...
A *remote, unauthenticated root compromise* on a domain name server is "nothing to worry about"?

The workarounds, simply put... sucked. They required that you cripple remote management entirely to be protected. Sure, you can block RPC at the perimeter, but that only protects you from the internet -- not your own employees in an enterprise scenario.

Bearing in mind that many DNS servers are domain controllers as well, that's an unacceptable threat condition. Being forced to choose between "break access to DNS management" and "allow remote root access to your entire domain by anyone who can access your internal LAN" is not good threat posturing for Microsoft customers.

There's nothing ceremonial about this patch. They cost about a million dollars each to make and release, and enterprises spend a good sum deploying them... for a reason. They make their networks safer with less functional breakage than Microsoft's notoriously bad workarounds.
Posted by: SecurityGeek_z   Posted on: 05/07/07 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

Microsoft to patch zero-day DNS flaw  Loverock Davidson | 05/03/07
Agreed  ITguy5678 | 05/07/07
Any given home user  epcraig | 05/07/07
Right, but home users aren't affected  SecurityGeek_z | 05/07/07
Firewalling DNS  gotitright | 05/07/07
'gotitright' doesn't... have it right...  SecurityGeek_z | 05/07/07
Not so fast...  SecurityGeek_z | 05/07/07
Loverock, you are an idiot...  SecurityGeek_z | 05/07/07
Agree w/ Everything Except  rkuhn040172@... | 05/07/07
Drat, They Did It Again  astro_z | 05/08/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
advertisement

SmartPlanet

Click Here