[Tfug] oh joy...

A.Chris Hilton tfug@tfug.org
Sun Sep 15 16:08:02 2002


On Sun, 15 Sep 2002 11:16:33 -0700 (MST)
Jon <bigj@flatwan.net> wrote:

> http://msn-cnet.com.com/2100-1001-957988.html?type=pt&part=msn&tag=cdf&form=base&subj=cn_fd
> 
> Jon

Well.  Looking through SecFocus's solution page for the bug this worm
exploits 
(http://online.securityfocus.com/bid/5363/solution/) it looks every OS
maintainer affected had released fixes by mid August at the latest. 
Most within 5 days of the bug's announcement.  How long did it take M$
to admit, fix, and make available the vulnerability that lead to code
red?  And to add to Adrian's bash: as a percentage of the whole, how
many 'nix machines are/will be exploited?  How does that compare to
(pick your iis exploit du jour)?

-C-