Much ado about patch management

Opinion
Sep 8, 20037 mins

* Patches from SuSE, Debian, Conectiva * Beware 9/11 viruses * CSI: Lost e-mails, and other interesting reading

The issue of patch management seems to have hit a nerve with a few readers. Last week I published a letter from Chuck Krueger who thinks there has to be a better way of getting the job done. You can read his thoughts here: http://www.nwfusion.com/newsletters/bug/2003/0901bug1.html

The issue of patch management seems to have hit a nerve with a few readers. Last week I published a letter from Chuck Krueger who thinks there has to be a better way of getting the job done. You can read his thoughts here:

https://www.nwfusion.com/newsletters/bug/2003/0901bug1.html

Krueger’s plea brought in these responses:

From Michelle Black:

Chuck is only partly right on the patch management nightmare.

We expect that software writers will write perfect software that no one can ever compromise.  Ever.  In the meantime, we expect that software companies will come up with some kind of perfect solution for administering all of the patches.

How about something called e-d-u-c-a-t-i-o-n.  How about the software manufacturers AND retailers be required to actually teach someone buying or operating a computer to know how to properly maintain it?  We do it for cars (it’s called driver’s ed), they do it for forklift operators and people who operate other *potentially* dangerous equipment, the doctor and pharmacist is supposed to do it when prescribing or dispensing drugs that could interact with other possibilities.

How about a license to own/operate a home computer – pass a test to determine if you actually know how to operate and maintain the thing.  You have a license for your car, and your car can only damage a small set of nearby objects, not the millions of computers and billions of dollars in damage caused by a virus on the loose, and on the loose mainly because people don’t patch.  But you know to put gas in the car, check the oil and the air pressure in the tires.  Maintaining a computer is not all that more difficult, if all you have to do is go to a Web site and download a patch on a regular basis, install a decent firewall, and have an anti-virus program and update it.

How about those infected suing those who infected them – individuals and corporations?  That usually gets the attention of people.

It is probably impossible to write 10 million lines of code that will be flawless and seamless, interacting with other tens of millions of lines of code in other operating systems, networks, etc.

But then again, if everyone did what they were supposed to do and acted in a responsible manner, what would we then have to complain about?

From Ronald Edge:

I called our Purchasing dept and got permission that it would not violate any licensing to bundle the Win2K and XP SPs 4 and 1, plus the blaster search and patch, and burn them to CDs. We then handed these out to our staff to take home and patch their machines to make them safe and functional enough to get on the net.

Staff are NOT keeping their home machines up to date because of the impossibility of doing the long, massive downloads over modem connections. And staff machines are for us a MAJOR vector of infection/re-infection, as most dial up directly to university modem pools to do all their Internet connectivity, only a small percentage have private accounts as I do at home with a commercial ISP.

This is simple self-defense in action.

Jeremy Hines thinks PC manufacturers need to help:

I think that PC manufacturers should be tasked with making sure that all of the latest updates are applied to a PC when it ships.  Then, downloading any additional security patches over a modem isn’t that big a deal.  Most security patches are less than 1M byte.  If the user wants to have a patch that adds functionality (usually several MBs) then it is their issue to get the update (either wait with the modem download or find a friend with a faster connection and burn the update to a CD-ROM).  Red Hat and many other Linux vendors offer an update service.  I can’t really speak for Apple as I don’t have any experience with current Apple technology.

Thomas Smith says, “just do it!”:

This is as annoying and like listening to someone complain about proper maintenance on a car, proper exercise and diet for the body, the need for continuing education…  Just do it.

Use the proper tools, and stop bellyaching because the maker couldn’t produce a machine with the software to do it all for you. Install with the proper service packs, look up slipstream under Help, and Stop Whining.

Finally, reader Brandon Fouts believes using Novell NetWare is one way to keep things secure. And, “Not using Outlook and IE may also be part of the lack of excitement on our network.”

Today’s bug patches and security alerts:

Debian releases new wu-ftpd packages

A flaw in the popular wu-ftpd FTP server package could be exploited to run arbitrary code on the affected machine with the privileges of the server process. For more, go to:

https://www.debian.org/security/2003/dsa-377

**********

SuSE, Conectiva patch pam_smb flaw

A vulnerability in the pam-smb module used by SuSE and Conectiva could be exploited by a malicious user to execute arbitrary code with the privileges of the application requesting PAM authentication. For more, go to:

SuSE:

https://www.suse.com/de/security/2003_036_pam_smb.html

Conectiva:

https://www.nwfusion.com/go2/0908bug1a.html

**********

Debian, Conectiva release exim patch

A buffer overflow has been found in exim, a mail transport agent used by Debian and Conectiva. The flaw could cause a heap overflow. However, no exploit has been discovered that would allow for arbitrary code execution. For more, go to:

Debian:

https://www.debian.org/security/2003/dsa-376

Conectiva:

https://www.nwfusion.com/go2/0908bug1b.html

**********

Conectiva issues new stunnel package

Two vulnerabilities have been found in Conectiva’s stunnel, a wrapper for network connections. One flaw could be used to take down an existing stunnel connection and another could be exploited to hijack the stunnel server. For more, go to:

https://www.nwfusion.com/go2/0908bug1c.html

**********

Today’s roundup of virus alerts:

First of perhaps many 9/11 viruses emerges

Antivirus researchers late Wednesday discovered what is being described as the first of potentially many “9/11” anniversary viruses spreading on the Internet. Computerworld, 09/04/03.

https://www.nwfusion.com/news/2003/0904firstofpe.html

OF97/ExeDrop-B – An Office 97 virus that drops a Trojan horse on the infected machine. The virus spreads via an Access database called “SEP 2003 POM.mdb”. (Sophos)

W32/SobigF-Dam – A damaged version of the Sobig worm that does not properly replicate, making it harmless. (Sophos)

W32/Neroma-A – An e-mail virus that spreads in an infected message entitled “It’s Near 911!” with an attachment called “NEROSYS.EXE”. On certain days of the month, the virus attempts to delete files on the infected machine. (Sophos)

Mapson.D – This worm spreads via e-mail, IRC and file-swapping services. It opens a Telnet session on the infected machine to give a remote user unauthorized access. It also terminates a number of security-related applications. (Panda Software)

Darby.A – A macro virus that infects the normal.dot template used by Microsoft Word. It disables the macro editing tools in Word and Excel. (Panda Software)

Apdoor.B – A backdoor Trojan horse that provides access to the infected machine via a predefined IRC channel. An attacker can use the infected machine to launch denial-of-service attacks. (Panda Software)

Daol.A – This virus exploits previously discuss Windows vulnerabilities to infect a number of file types. No word on the damage caused by the virus. (Panda Software)

Surfbar – Another virus that exploits an older Internet Explorer vulnerability. It redirects most Web page requests to pornographic Web sites. (Panda Software)

**********

From the interesting reading department:

CSI: Lost e-mails

Forensic experts sift through electronic data looking for key bits of evidence. Network World, 09/08/03.

https://www.nwfusion.com/research/2003/0908csi.html

XKMS does the heavy work of PKI

An upcoming standard from the World Wide Web Consortium aims to reduce the costs of PKI without sacrificing its benefits. Network World, 09/08/03.

https://www.nwfusion.com/news/tech/2003/0908techupdate.html