Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Focus-Microsoft
[Top] [All Lists]

RE: exploit to vulnerability

Subject: RE: exploit to vulnerability
Date: Fri, 19 Aug 2005 13:41:05 -0400
Murad,

IMHO you should still test the patches.  However, you need to speed up
the testing process.  This probably means you may not test as thoroughly
as you would like.  

Dennis

-----Original Message-----
From: Murad Talukdar [mailto:talukdar_m@subway.com] 
Sent: Friday, August 19, 2005 2:11 AM
To: focus-ms@securityfocus.com
Subject: exploit to vulnerability

With all the issues highlighting the speed that exploits are now being
written (eg http://www.securityfocus.com/news/11285 ) The window between
exploit/vuln, appears on average, to be getting tighter.

We have an SME network and I used to have a week or so to test patches
before rolling them out. 
This all begs the question now, with limited resources, do I just patch
and not worry about testing? I definitely have fewer resources than some
of the companies that were hit (CNN et al) and less time to dedicate to
patching. 

Should I just use auto updates/GP to patch everything regardless?
What do other SME admins do?

Kind Regards
Murad Talukdar




------------------------------------------------------------------------
---
------------------------------------------------------------------------
---


---------------------------------------------------------------------------
---------------------------------------------------------------------------


<Prev in Thread] Current Thread [Next in Thread>