Security holes... Who cares?

From: Eric Rescorla (ekrat_private)
Date: Fri Nov 15 2002 - 10:30:53 PST

  • Next message: OpenPKG: "[OpenPKG-SA-2002.011] OpenPKG Security Advisory (bind, bind8)"

    I'd like to announce the availability for downlaod of the following
    paper.
    
                          Security holes... Who cares?
    
                                  Eric Rescorla
                          RTFM, Inc.   <http://www.rtfm.com/>
    
    We report on an observational study of user response following the
    OpenSSL remote buffer overflows of July 2002 and the worm that exploited
    it in September 2002.  Immediately after the publication of the bug and
    its subsequent fix we identified a set of vulnerable servers. In the
    weeks that followed we regularly probed each server to determine whether
    it had applied one of the relevant fixes. We report two primary
    results. First, we find that administrators are generally very slow to
    apply the fixes. Two weeks after the bug announcement, more than two
    thirds of servers were still vulnerable. Second, we identify several
    weak predictors of user response and find that the pattern differs in
    the period following the release of the bug and that following the
    release of the worm.
    
    The paper can be downloaded from:
    http://www.rtfm.com/upgrade.pdf
    http://www.rtfm.com/upgrade.ps
    



    This archive was generated by hypermail 2b30 : Sun Nov 17 2002 - 13:14:56 PST