Re: OT: Found this useful over the years.. Crossplatform. Keep your fingers in more than 1 pie

From: Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP] (sbradcpa_at_pacbell.net)
Date: 02/18/05


Date: Thu, 17 Feb 2005 18:45:13 -0800

The Linux kernel had several vulnerabilties even this week....and the
SuSe folks are working on a patch.

Blackhat a year ago had a presentation on the vulnerabilities of Novell
[non SuSe version]

Patching is a way of life..... and the sooner that everyone wakes up and
realizes that as alternative systems gain in market share they too will
have their issues [right now Firefox has about three unpatched items]
and the sooner we build in patch management processes and tools the
better we all are dude.

After we get the OS's all nice and safe then they will go after our
applications.

F-secure and Symantec both had buffer overflows this week.

Patching "is" normal and the sooner that everyone wakes us that we can
never have "perfect" software the better we will all be.

I have the knowledge and tools to protect myself and secure myself on
Microsoft products. I do not have the time to keep up to date on the
Novell/SuSe stuff.

It's once a month for patches folks... not "every few weeks" unless you
define "few" as four. Besides, I use it as monthly "inventory" time
anyway. The reality is that I left Novell because I saw support
dwindling.

Newby wrote:
> Patching as a way of life is ONLY made to sound normal here.
>
> on average we apply 1 service pack a year (even though Novell might issue
> more)
> with 230+ users to support - we can't afford downtime
> (if we really have a security issue we will evaluate)
>
> No issues in the last *** 5 years ***
> This is a rock solid system - no downtime except for annual patches.
>
> We also have several Windows Servers but these are becoming a nightmare for
> support (by comparison)
> with a need to install patchs every few weeks
>
> "Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP]" <sbradcpa@pacbell.net>
> wrote in message news:O4XCUWTFFHA.2540@TK2MSFTNGP09.phx.gbl...
>
>>And security patching more than one platform......
>>
>>
>>
>>Newby wrote:
>>
>>>The Novell Software Evaluation and Development Library combines
>>>full-featured evaluation copies of the Novell and SUSE software with the
>>>Novell development tool (NDK, Metrowerks Code Warrior etc.) It is the
>
> ideal
>
>>>offering for developers. It comes in 2 licenses: Standard -2 server, 5
>
> user
>
>>>($299) and Expanded 2 server, 100 user($495). Content:
>>>
>
> http://support.novell.com/subscriptions/subscriber_resources/breakdown/2005/nsedl_breakdown_jan05.html
>
>>>http://support.novell.com/subscriptions/buy_renew_upgrade/buy.html
>>>
>>>
>
>
>



Relevant Pages

  • Re: Russ Coopers AusCERT Presentation on MS Security Bulletins
    ... but this gal in SBSland thinks that non-patching is NOT the ... I'll take a Security hotfix anyday, thank you, ... feel that I get 100% in my lan of patching. ... there on XP sp2 RC, firewall in place AND the Sasser patch in place, I ...
    (NT-Bugtraq)
  • Re: Patch Management on Critical Servers (Healthcare)
    ... *nix servers patch management is handled at two levels. ... meeting and approved, especially patching. ... change meetings for the hospitals and dates set. ...
    (Focus-Microsoft)
  • Re: [Full-Disclosure] RE: Linux (in)security
    ... > There's a vast difference in having to backout patches in complex ... And I don't recall the last time that we had to back out a patch in an over ... There isn't a vast difference between patching ... Windows and patching *nix. ...
    (Full-Disclosure)
  • Re: [PATCH] [5/12] x86_64: Make patching more robust, fix paravirt issue
    ... The broken commit is Rusty's patch which, ... AFAICT patching is writing garbage into the insn stream. ... I suspect it's copying an uninitialized temp buffer. ... Can you send me the revert patch that is verified to work? ...
    (Linux-Kernel)
  • Re: change page protection, how to
    ... I have a very small stub of code ... not possible to circumwent it from user mode. ... patch an application. ... For patching dlls, ...
    (comp.lang.asm.x86)