3 ms·
How history repeats itself. Years ago I struggled to convince a group of sysadmins that server hardening, firewalls and patching were essential for any Interne
by rm-rf 17y ago
How history repeats itself.
Years ago I struggled to convince a group of sysadmins that server hardening, firewalls and patching were essential for any Internet connected system. I heard things like "there's a million computers on the Internet, why would anyone bother mine" [unless they wanted to use your server to hack someone else or store their porn|warez]" and "nobody can port scan the entire Internet, they'll never find my server" [unless they control an army of scanners].
I made significant progress by having my group perform live IIS5 directory traversal & telnet MTIM attacks at a conference of local sysadmins. (yep, this was a long time ago)
Similarly, today we have a significant number of web developers who don't think it can happen to them, until it does.
- deleted 17y ago[deleted]
- tptacek 17y agoUnfortunately, server hardening, firewalls, and patching wouldn't have prevented this problem; it's buried in the actual application code.
- rm-rf 17y agoI fully understand that. It was intended to be an analogy. Let me try again. A decade ago, clueless sysadmins put unpatched servers directly on the Internet with no firewall protecting ports that didn't need to be exposed, with no hardening, no patching, etc. An hour later, after their shiny new server got rooted, the clueless sysadmins stood there with the classic deer-headlights look, wondering what just happened. Today, with OS's that have reasonable default configs on as-shipped, and with firewalls the norm, it's the application developers that are clueless id10t's standing around with the deer-headlights look.