doc_strange: (Default)
doc_strange ([personal profile] doc_strange) wrote2003-08-18 08:53 pm

Where the hell is the microphone?

Well? Where is it? I make a joke about the hole being so blatantly unpatched still despite all the noise, that someone ought to write a worm to patch it, and within 48 hours this happens.

Add to it that, when MS0-026 came out, it was obviously a problem calling for a worm. Loudly. When I wrote up the advisory for a client's internal service delivery (ops) staff, we said the patch timeline should be: ASAP for critical infra and border hosts, Aug 1 for all servers and as many laptops as you can get, and Aug 8 to wrap up desktops and everything else. On Aug 11, the worm showed up.

Now I wonder when the prediction about an MS03-030/MS03-026 combo hole worm will come out. If it does, it will be veri nasti.

[identity profile] cheesetruck.livejournal.com 2003-08-18 11:17 pm (UTC)(link)
Friend in Japan is having fun explaining to guys who don't know English or tcpdump or unix how he can tell which machines are infected.

[identity profile] docstrange.livejournal.com 2003-08-19 07:01 pm (UTC)(link)
Hai! Hai! Porto 707/TCP.
Bad randomnumgenerator.
135 scans. Ping ping ping!
I listen.

If I had the will, I could probably make a haiku out of that.