Security Basics mailing list archives
Re: Firewall configuration statistics
From: Brian Eckman <eckman () umn edu>
Date: Mon, 23 Jun 2003 11:37:38 -0500
security () rexwire com wrote: (snip)
25% of exploits had patch readily available -SKP
Do you mean that you read that 25% of compromises were due to exploiting flaws that had a patch readily available?
If so, there is no way that number is correct. Everything that I have read and experienced lead me to believe that a *vast* majority of compromises are due to flaws that have already been patched. I can't tell you the exact number, and I don't know who with any "authority" can. But I would bet dollars to doughnuts that it is definitely nowhere close to 25%, and more like 95-99% depending on your definition of "compromise".
If that isn't what you meant, perhaps you can elaborate on that statement? Brian -- Brian Eckman Security Analyst OIT Security and Assurance University of Minnesota 612-626-7737 "There are 10 types of people in this world. Those who understand binary and those who don't." --------------------------------------------------------------------------- Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts! The Gartner Group just put Neoteris in the top of its Magic Quadrant, while InStat has confirmed Neoteris as the leader in marketshare.Find out why, and see how you can get plug-n-play secure remote access in
about an hour, with no client, server changes, or ongoing maintenance.Visit us at: http://www.neoteris.com/promos/sf-6-9.htm
----------------------------------------------------------------------------
Current thread:
- Re: Firewall configuration statistics, (continued)
- Re: Firewall configuration statistics Devdas Bhagat (Jun 10)
- RE: Firewall configuration statistics Des Ward (Jun 10)
- RE: Firewall configuration statistics security (Jun 09)
- RE: Firewall configuration statistics John Floyd (Jun 09)
- RE: Firewall configuration statistics Gregory Kane (Jun 09)
- Re: Firewall configuration statistics Brian Eckman (Jun 09)
- Re: Firewall configuration statistics Brad Mills (Jun 09)
- RE: Firewall configuration statistics security (Jun 20)
- Re: Firewall configuration statistics Justin Pryzby (Jun 20)
- RE: Firewall configuration statistics security (Jun 23)
- Re: Firewall configuration statistics Brian Eckman (Jun 24)
- RE: Firewall configuration statistics Des Ward (Jun 24)
- RE: Firewall configuration statistics security (Jun 24)
- RE: Firewall configuration statistics ATD (Jun 25)
- RE: Firewall configuration statistics security (Jun 23)
- RE: Firewall configuration statistics ATD (Jun 26)
- RE: Firewall configuration statistics security (Jun 26)
- RE: Firewall configuration statistics Kelly Martin (Jun 26)
