The Exploits are running wild - Sasser
If you have not installed the latest updates for Windows XP yet, you just might be too late. If nothing else, switch on the Internet Connection Firewall asap if you can.
For more information refer to the Security Report on the Microsoft site.
The new virus on the block is called Sasser (W32.Sasser.Worm). It's already running wild; I just read some reports about it taking Autralian Railways down.
So personally, I'm a happy man, I get to do my Windows XP SP2 talk tomorrow on the Security Summit, and can you have a better point to explain why Microsoft is doing SP2 than a virus running wild as I speak? It is not enough for Microsoft to be pushing out updates, if people will not update their machines, or if there is no basic protection. Sasser for example will have no effect if you have enabled the Internet Connection Firewall. And yes, there are reasons why not to have it turned on the way it is at the moment. That is why SP2 is such an important piece of security equipment. It will fix a lot of these problems.
Comments
- Anonymous
May 03, 2004
You're a HAPPY man? Sorry? You should be a happy man if those security patches were available 3 months ago. This sounds as if the security holes are left in there, just to be able to have those nice security speeches... - Anonymous
May 03, 2004
The comment has been removed - Anonymous
May 03, 2004
The comparison to locking the door of your house doesn't hold water. If companies that built houses designed the walls so that sections of it would fall away periodically, leaving man-sized openings for criminals to creep in, then you'd have a valid comparison.
I'm not of the belief that Microsoft intentionally designs security flaws, however. The negative PR that's generated by these problems is too much for a company to take. Rather, it should be too much for a company to take. ;) - Anonymous
May 03, 2004
Rudi,
Thanks for blog'ging about this stuff. I'd love to see some more information re: SP2; we got given those discs while in Redmond recently but I still haven't installed it as yet.