Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
Applications /

Compendium /

How to respond to Slammer-like attacks

Related linksToday's breaking news
Send to a friendFeedback


Network World Fusion 01/28/03

Joshua, a Microsoft program manager, doesn't agree that we should be trying to get lazy sysadmins to patch six-month-old holes in their software:

Sysadmins don't keep up with patches; just as the sun rises in the east. Blaming sysadmins does nothing to solve the problem.
Instead, he says the reaction to this past weekend's attack shows the right way to handle it: Network providers working together to cut off traffic from such beasties; network managers putting into place plans for quickly isolating infected network segments.

Meanwhile, see what some Fusion users have to say about my calling sysadmins who didn't apply the SQL patch "dummies."

Back to Compendium

Comments

The Slammer worm was highly visible but also extremely benign. Much more troublesome would be a worm that's essentially invisible but gathers sensitive banking info from, say, Bank of America, whose vulnerability is now obvious.

As long as they continue to use Microsoft products, sysadmins have absolutely GOT to keep their systems patched. Closing the barn doors after the horses are loose is entirely inadequate.

Posted by: Art Smart on January 30, 2003 11:12 AM

I lay a lot of the blame at Microsoft's feet since once you install a service pack there is no easy way to deinstall it. Installing a service pack or even a patch is always a risky proposition on SQL server and other products.

And who wants to be the first to install a newly released patch? Not me.

Although it is difficult to wade through the shear volume of patches and service packs for all products and make good decisions on what should and should not be applied, we have to do it, or face the consequences.

It would be nice if company management understood the complexity of this problem and the potential risks. However, even when you explain it to them, they do not grasp the significance.

Posted by: Geg Brooks on January 31, 2003 11:59 AM

Do we hold the networking organizations responsible for preventing attacks like this or does this clearily fall on the shoulders of the clients who fail to keep current on patches?

Posted by: Doug on February 6, 2003 08:59 AM

Post a comment

Name:


E-mail address:


URL:


Comments:


Remember info?




NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.
* HOME    * RESEARCH CENTERS     * NEWS     * EVENTS

Contact us | Terms of Service/Privacy | How to Advertise
Reprints and links | Partnerships | Subscribe to NW
About Network World, Inc.

Copyright, 1994-2006 Network World, Inc. All rights reserved.