[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
RE: [Full-Disclosure] Learn from history?
- To: "Full-Disclosure" <full-disclosure@xxxxxxxxxxxxxxxx>
- Subject: RE: [Full-Disclosure] Learn from history?
- From: "Alerta Redsegura" <alerta@xxxxxxxxxxxxx>
- Date: Wed, 5 May 2004 18:09:17 -0500
> > > > 2. If a patch cannot be installed, find workarounds
> > >
> > > That does not work with the workarounds customer need to facilitate
> > > life (security <> easy of use, remember)
> >
> > In the particular case of Sasser, workarounds indicated in KB
> > 835732 and/or making sure TCP 445 is closed to the outside
> > world was enough and not difficult to achieve.
> >
> Not it wasn't enough. It would be until someone dialled to the
> Internet, or even to some other third party network that had the virus.
> The only thing that was enough was to patch. The only people who
> have the luxury of not patching are those who have no connectivity
> from their LAN to any other network.
If the "Internet" and a "third party network" are not part of the "outside
world", what are they?
Iñigo Koch
Red Segura
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html