HZGN.COM
welcome to my space
X
Feng Shui | Graphic Design | Cosmetics | Causes and Organizations | Regulatory Compliance | Gadgets and Gizmos | Computer Forensics | Tools and Equipment | Related articles
Search:  
Welcome to:hzgn.com
NAVIGATION - HOME
When Patches Aren't Applied
Published by: jane 2008-12-01

Enterprise IT administrators, bombarded by daily software vulnerability warnings on a daily basis, have not been serious about applying security patches despite the clear danger of worms, viruses and intruder attacks.

Applying BK produced patches with new files using patch | Ramblings::
into this problem (which I do every few weeks/months): new files arent created. patch that includes new files, allows you to apply it using patch (or,
http://www.flamingspork.com/blog/2007/08/13/applying-bk-produced-ith-new-files-using-patch
HOME
That's the word from online security experts who estimate that up to 50 percent of all enterprises could be sitting ducks for hacker attacks because of unpatched, vulnerable computer systems.

While it is impossible to figure exact percentages of critical or important patches that have been downloaded and installed, experts believe the application of fixes are delayed for months, even with the increased awareness after the recent Code Red and Slammer incidents.

Last year alone, network administrators had to deal with more than 80 percent more vulnerabilities than in 2001, according to a report from Symantec, which provides anti-virus software. Microsoft , the world's leading software vendor, issued 72 security alerts in 2002 and 10 already this year.

A Microsoft spokesman told internetnews.com there are no exact percentages available for issued patches and downloaded because there is not a 1:1 ratio of patch downloads to patch applications.

"While technologies such as Windows Update, Auto Update and SUS have increased patch uptake, we cannot provide detailed download statistics. Large enterprises often download a patch to a local server, then deploy it across thousands of computers, therefore; patch downloads are not indicative of the numbers of computers protected," the spokesman explained.

Marty Lindner, team leader for incident handling at the CERT Coordination Center, agreed it was nearly impossible to figure out actual percentages. In large enterprises, for instance, Lindner said the term 'patch download' doesn't apply because those systems are typically protected through an outsourced software maintenance contract.

"In a major organization, if they have 100,000 machines, they aren't downloading and installing 100,000 patches. It really is hard to measure because, even for smaller business, you have no way of knowing what happens once a patch is downloaded. You don't know how many machines it is applied to and who is sharing a patch with who," Lindner explained.

Coding Hints:Patches - Wine-Wiki::
1.1.3.4 How Long to Wait before the patch might be applied you cant get stuff in if you arent trusted, but it means it will require extra
http://wiki.jswindle.com/index.php/Coding_Hints:Patches
HOME
Patches | Hishams Blog::
Unfortunately, the results arent showing the same level of success as following I successfully applied it to my laptop and it has worked repeatedly.
http://blog.hishamrana.com/tag/patches
HOME

Lindner's CERT/CC, the federally funded clearinghouse for warnings from all major vendors, reported 4,129 vulnerabilities in 2002, almost double the number issued the previous year. The Center's statistics show an alarming trend upwards but Lindner said the lack of information is still a major setback in the Center's quest to secure susceptible systems.

Sheer Volume

Lindner blamed the administrators' indifference to patch applications on the large amounts of security information being shuttled to enterprises on a daily basis. "The sheer volume of security information that's seen by a network administrator is mind-boggling. In many cases, it's a huge task just figuring out which patch applies to you," he explained.

Even after the sysadmin is made aware of the problem, it's not a straightforward care of applying a patch, Lindner explained. "People believe you solve the problem by applying a patch but, typically, you can do a configurating change or turn off the offending software and secure your system," he added.

"The first challenge is to decide which patches apply to your system. After you have weeded through that, then you have to apply the patch and test it outside of production. When you apply the patch, you have to make the blind assumption that it's fixing whatever needs to be fixed. Even then, you take the risk that you will break something that used to work," Lindner said in an interview, arguing that faulty patches have been just as destructive as the vulnerable software it was meant to fix.

Thomas Kristensen, chief technology officer as security research firm Secunia, believes network admins are more likely to patch holes in mail servers and Web servers in a timely manner.

"Generally, in a medium-sized business, they'll use Windows update and get patches relevant to their systems and, even then, they'll apply the patches based on whether it is important or not," Kristensen said.

He said bug warnings around Web browsers or other client systems are routinely ignored because they are deemed unimportant. "Sometimes, they will hesitate and delay fixing a faulty browser for several months and assume they aren't vulnerable because they're using a firewall but that is a dangerous assumption. The intruders are sophisticated and are using attack scenarios that penetrate the firewall," Kristensen told internetnews.com.

In many small- and medium-sized enterprises, Kristensen said it boiled down to a matter of available resources to deal with patch applications. "They just don't have the tools or software to distribute patches in the network. They'll have to do it individually and it is a tremendous task for a one-man staff to be running from machine to machine to plug a hole," he said.

CERT/CC's Lindner agreed that the urgency to apply fixes was determined by the cost factor. "Many corporations choose to measure the risk associated with the cost of patching a system. Sometimes, it is a conscious decision that patching computer systems is not a high enough priority to spend big dollars to do it," Lindner asserted.

So what to do when all of those patches are critical? Read more on Page 2.


Management Tools 'Priority One' for Open Source
Wind River Embraces OSDL, Linux

You are looking at:hzgn.com's When Patches Aren't Applied, click hzgn.com to home
  • problem with ftp connection
  • strange problem with spysubtract and outlook
  • multiple open ports
  • internet is blocked by op 2 x with big data traffic lan msn and internet e mule
  • dreamweaver cuteftp will not work
  • bsods are back in v2 5 375 4822 374
  • connection trouble after update
  • ie and localhost access problem
  • how to modify rules by jscript or wsh
  • configuration help
  • protect lst entry ignored
  • what does this mean please
  • outpost not showing in system tray
  •  
  • urgent is this normal
  • problem with outlook
  • 2 different ip addresses
  • attachments filtered even if the respective plugin is disabled
  • log rules
  • dhcp ip lease renewal issues
  • malformed dns request from emule with the kad support on
  • irc bnc users getting disconnected
  • outpost freezes
  • constant registry file access hdd torture
  • switching user in xp can t access internet
  • outpost bundled with routers
  • reason learning mode
  • all e mail blocked
  • #If you have any other info about this subject , Please add it free.#
    Your name:
    E-mail:
    Telphone:

    Your comments:


    If you have any other info about When Patches Aren't Applied , Please add it free.

    About us -Site map -Advertisement -Jion us -Contact usExchange linksSponsor us
    Copyright© 2008 hzgn.com All Rights Reserved
    Site made&Support support@hzgn.com    E-mail: web@hzgn.com