I'm going to pick one small nit with you. There is another possible guilty party. In some cases, at least in edu and medical centers (that's what I'm familiar with) the *vendor* is at fault. Some vendors will not certify their scientific instruments with the latest Service Packs and patches, leaving the admins no other choice but to find some other way to protect the machine. (Hell, we sometimes have trouble getting vendors of *security* devices to support their products with the latest SPs and patches. (Which is another reason that I dislike putting security-related software on Windows boxes, but sometimes you simply have no choice.)
As some may recall, my original statement was an answer to someone that was points that Unix is more secure then Windows (I agree up to this point), and gave and example telling that there are still several codered vulnerable machine around. This is the point I was commenting about. And you do have to agree that is a machine, today, is still vulnerable to Codered, it is mostly due to a fault of the administrator.
Paul Schmehl (pauls@xxxxxxxxxxxx) Adjunct Information Security Officer The University of Texas at Dallas AVIEN Founding Member http://www.utdallas.edu
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html