On TechRepublic: 10 cool USB flash drive tricks
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 15 of 73:
Next »
« Previous
The paper is serious
Just because a writer uses humor to express concepts does not mean the content is not serious or that the content is flawed. It simply ensures that the paper is likely to get read. This is an important paper and it should be read.

The paper was complete in terms of what it was dealing with and consistent with other reports of knowledgeable people in the computer security field. There was no need for it to be broader in scope. It was a report, not a thesis. You are trying to find flaws where they don't exist.

"I bet those servers weren't patched, or they were simply misconfigured (weak admin password), and the admins were lying to save face/their jobs."

MS loves to hear how it's really the fault of incompetents that so many of their systems get compromised. And how easy it is to suggest that. You get to pretend to a greater knowledge than you have and remain blind to the very real and serious problems affecting Windows systems, while MS gets to continue to sit on their hands and not fix the problems that are very well-known.

Closing off a few ports (as SP2 does) doesn't solve the basic problem. There are already many articles showing how ports get bypassed or accessed.

"Why do you think the two (IIS5 and IIS6) windows web servers I have the displeasure of running wern't hit by this?"

Are you in the financial services industry? Those were the servers primarily targeted. However, you could very well be infected and not know it, because it has nothing to do with competence. If you don't have outside agencies monitoring your systems, it's quite possible you have no idea what all is happening to the servers. You just think you know what's happening with them.

"If you have a link to some information on these 'patched servers' that were exploited, please share. As an IIS admin it would be of great interest to me."

I didn't bother to save the links because the details were widely reported at the time by the agencies who monitor these things in the journals and magazines that deal with computer security. But it was clear to the monitoring agencies that the servers had been correctly patched or upgraded.

Please note that although I run Linux systems, I am reading about these things and staying on top of them while you appear to be complacent and not aware of the information that is commonly distributed.

One of the sources of protection which Aitel notes in his white paper is the fact that there is better information in the Linux community about what's happening with it than is true of the Windows community. It is much easier to discover the problems in a Linux system and the solutions are much quicker in coming.

All systems have flaws -- Linux is much better at finding and correcting them, that's all (I'm not going to get into the "white hats" and "black hats" on which a lot of this is based -- if you're in the computer security business you will know what I'm talking about). You must be plugged into the information sources if you wish to be aware of what's going on -- even with Linux.

While there is a problem with incompetency, the fact is that if you bother to read things like the Cert advisories, you'd discover that many MS patches are incomplete or placebos and do not solve the problem they are touted to address.

The security problem is not primarily one of incompetency of users and admins. The primary problem is that the OS is not well-protected against attack -- it is too easy for a hacker to 0wn.
Posted by: dhk   Posted on: 08/15/04 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

this is nice and all....but where's the link?  Monkey_MCSE | 08/13/04
This is a white paper  dhk | 08/14/04
Talk about your misleading titles...  Michael Kelly | 08/13/04
Well, it's a staple for ZDNet..  Jeff Spicoli | 08/13/04
SP2  georgep_z | 08/13/04
Nope, you missed the point  AbsolutelyNot | 08/13/04
Don't any of you understand what constitutes data?  dhk | 08/14/04
Without data the whitepaper is opinion, not fact  balsover | 08/15/04
Linux is not for everyone -- so why are you worried about this paper?  dhk | 08/15/04
Here is the a link to the paper.  toadlife | 08/13/04
I think you missed the point  dhk | 08/14/04
Allow me to break it down for you  toadlife | 08/14/04
You just don't get it  dhk | 08/14/04
You take the paper too seriously  toadlife | 08/14/04
The paper is serious  dhk | 08/15/04
You might have a few misconceptions about me  toadlife | 08/15/04
My conceptions can only be based on what you say  dhk | 08/15/04
The servers weren't patched  toadlife | 08/15/04
I've just rechecked CERT & others -- you're incorrect  dhk | 08/15/04
I'm completely and utterly dumbfounded.  toadlife | 08/15/04
I believe you are dumbfounded  dhk | 08/16/04
Disagree re OS X  Fred Fredrickson | 08/15/04
You misunderstood the data in the table  dhk | 08/15/04
Thanks  Fred Fredrickson | 08/16/04
Still makes no sense  ITGuy04 | 08/16/04
Re: Thanks  dhk | 08/16/04
Re: Still makes no sense  dhk | 08/16/04
Thanks... again  Fred Fredrickson | 08/16/04
I agree...this paper was not for the lay reader  dhk | 08/16/04
I have to admit...lol..that was AWESOME..  DigitalKid | 08/13/04
The paper wasn't written to be serious...  el1jones | 08/13/04
Because...  toadlife | 08/13/04
Oh, but it was...  AbsolutelyNot | 08/13/04
And it sounds like he's unprofessional to me...  TimeBomb | 08/14/04
It doesn't matter  NonZealot | 08/14/04
You're not a zealot????  Mack DaNife | 08/15/04
Finally, some quality stuff on ZDNet..!  Xunil_Sierutuf | 08/13/04
So do you only accept articles that match your point of view?  Linux_Developer | 08/13/04
We see the light  NonZealot | 08/13/04
Please stop joking...  TimeBomb | 08/14/04
Dude  nomorems | 08/16/04
Ummm, monoculture,  FilledOut | 08/15/04
MSZealot  nomorems | 08/16/04
Far too slanted to be taken seriously  Cerowyn | 08/13/04
i think he's basing it towards MS papers on TCO  Monkey_MCSE | 08/13/04
TCO to implement???  voska | 08/13/04
implement is just one of those grey words  hipparchus2000 | 08/13/04
Why not  seosamh_z | 08/13/04
Longhorn  nomorems | 08/16/04
TC0 not TCO  dhk | 08/14/04
Hmmm...  ITGuy04 | 08/16/04
Wow, productive  FilledOut | 08/14/04
ms needs to go back to making great OSs  V Sanders | 08/14/04
Odd way of putting it...  AmusedAtItAll | 08/14/04
Hey!  toadlife | 08/15/04
re: ms needs to go back to making great OSs  TtfnJohn | 08/14/04
SP2 INCLUDE Media player 9  balsover | 08/15/04
Scary  tripolitan | 08/15/04
Re:ms needs to go back to making great OSs  tripolitan | 08/15/04
"go back to"?!? It'd be good if they start.  hayesk | 08/15/04
Mac point of view  frabjous | 08/22/04
Article based on opinion not fact  EnterPrise_Analyst | 08/15/04
Do Windows users have a sense of humour?  hayesk | 08/15/04
Some 'anti-microsoft' people are taking it way too seriously  toadlife | 08/15/04
If the show were on the other foot  FilledOut | 08/16/04
Lower cost of total ownership? (nt)  Fred Fredrickson | 08/15/04
Watch those Microsofties squirm  whisperycat | 08/16/04
Your job will be in INDIA  Hamburger Chef | 08/16/04
TAKE THAT NO_AX!!!  itanalyst | 08/16/04
you are anti-American join Abul  Hamburger Chef | 08/16/04
What The Title Of The Article Was Supposed To Be Was This:  itanalyst | 08/16/04
INDIA will own you and YOUR JOB  Hamburger Chef | 08/16/04
Degreed India Hamburger Chef  Hamburger Chef | 08/16/04

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
advertisement