Re: I Just Head The Entire State Of New York Has A Power Outage

From: The Kung Fu Hippie From Gangsta City (spamspamspam_at_spam.spam)
Date: 08/15/03


Date: Fri, 15 Aug 2003 18:06:15 GMT


"Luca" <bobbito@balcab.ch> wrote in news:3f3d11bc$1@news.swissonline.ch:

>
> "Steve S. Jackson" <stevesjackson@earthlink.net> wrote
>> The wires are now saying it was a generator in Ohio. We may
>> never know.
>
> In a German online paper I've read an article on how the Lovsan worm
> could have had something to do with it. The central power station used
> unpatched software which had exactly that type of hole... Dunno if
> there's anything out like this in English and I can't be bothered to
> translate the whole thing right now. Maybe tomorrow if by then they
> haven't nailed a couple of Saudis for it.
>
> Luca
>

Windows Update flaw 'left PCs open' to MSBlast

Munir Kotadia
ZDNet UK
August 15, 2003, 14:40 BST

Tell us your opinion

A flaw in Windows Update caused some organisations - including the US
Army - to wrongly believe they were protected from MSBlast, according to
a researcher

 

A flaw in Windows Update -- Microsoft's online tool that lets customers
update their operating system with patches and fixes -- enabled the
MSBlast worm to infect computers that apeared to have already been
patched, according to a security expert.
The flaw led to a US Army server, among others, falling victim to
MSBlast, according to Russ Cooper, chief scientist at security company
TruSecure.
Windows Update works by adding an entry into the system registry every
time it installs a patch. When users log on to the update tool, it scans
their registry and offers them list of patches that have not yet been
installed. Cooper said that this mechanism was found to be flawed.
"We found that people had got the registry key for the patch, but not the
file," he said, explaining that the error could be triggered by a number
of reasons -- from an incomplete installation to a lack of system
resources.
"If you go to Microsoft's site and say, 'tell me if I am up to date', and
it says 'you are up to date', but you are not, what are you supposed to
do?" he said.
In order to fix the problem, Windows Update should be looking for the
actual fix rather than just a registry entry, Cooper argued. This feature
is already included in the tool, but is not "fully enabled", Cooper said.
He recommends that users should run the Microsoft Baseline Security
Analyzer (MBSA) as an alternative to Windows Update for checking to see
if patches have been correctly installed. MBSA is also designed to look
for security problems in the Windows registry and can be downloaded free
from Microsoft's Web site.
Microsoft did not respond to requests for comment on the Windows Update
issue.
Patching has been a thorn in Microsoft's side, with companies complaining
that it takes far too long to implement patches because of the
compatibility testing that is necessary before deploying them to
thousands of servers and desktops. Additionally, the sheer volume of
patches being generated by Microsoft means that companies are finding it
difficult to keep up.
Stuart Okin, chief security officer at Microsoft UK, admitted that
Microsoft customers spend too much time fixing their systems: "Our
customers don't necessarily have the programmes, processes and
environments in place to deal with dynamic changes," he said. He admitted
that companies have had problems deploying the patch to thousands of
workstations or servers "within the space of four weeks" -- approximately
the time between when the vulnerability was discovered and the worm was
released.
Last year, Microsoft launched its Trustworthy Computing Initiative, which
included retraining its programmers to ensure their code was written with
security in mind and involved an overhaul of its entire patching system.
Okin said that within two years, Microsoft will have made significant
changes to its Windows Update service. The company is planning on
introducing a single update source -- probably called Microsoft Update --
which will be capable of updating all of the Microsoft products installed
on a computer.
Do you have a horror story related to the spread of the MSBlast worm? If
so, add TalkBack below or write to the mailroom.

-- 
Can I borrow a feeling?
http://www.mp3.com/gortician
Bass for your anus:
http://www.mp3.com/manticore
http://www.mp3.com/meterversusyard
http://www.mp3.com/highc
http://www.mp3.com/measurerecords
"[The artwork of Andrew Penland] is REAL...what I mean by "real" is that 
it made NEW THOUGHTS occur in my head, which would have never otherwise 
occurred." --Full Force Frank


Relevant Pages

  • Re: KB943460 / Software Distribution Service 3.0 System Restore Pr
    ... Sorry if I seemed coy its simply I had it my head you were a Microsoft ... I suppose it might simply be a rebrand of Windows Update. ... McAfee Security Center or AVG Free. ... KB943460 is not causing your System Restore problems. ...
    (microsoft.public.windowsxp.general)
  • Re: How to Maintain an IIS Server?
    ... >>> I looked at the Microsoft Security Website. ... >> before a firewall and antivirus have been installed]. ... >> new patches that are missing, ...
    (microsoft.public.inetserver.iis.security)
  • Re: IE patches killed internet connection
    ... IE to download/install from Windows Update manually, so don't even try using Firefox. ... Later, Auto Update reoffered the security update, but I was ... Microsoft.com to try to download manually, but I have to use Firefox to ... install all patches offered except for SP2. ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: How to Maintain an IIS Server?
    ... > [for MS MBSA Baseline Security Analyzer] ... Get a firewall or two as well, ... >>> new patches that are missing, ... >>> software installed on your computer, especially Microsoft Windows, ...
    (microsoft.public.inetserver.iis.security)
  • Re: cant update XP, Yes I had the vundo
    ... I'd say you've got more work to do (and you should replace McAfee Security Center with a more-robust AV app/security suite). ... NB: If you had no anti-virus application installed or the subscription had expired *when the machine first got infected* and/or your subscription has since expired and/or the machine's not been kept fully-patched at Windows Update, don't waste your time with any of the below: Format & reinstall Windows. ... Support for Windows Update: ... no-charge support is available by calling 1-866-PCSAFETY in the United States and in Canada or by contacting your local Microsoft subsidiary. ...
    (microsoft.public.windowsupdate)