ryan> I have yet to see a CERT advisory on these... Don't they
ryan> usually warn about attacks that are being actively pursued?
CERT only sends out advisories once the manufacturer or the developer puts out
a fix for
the problem. So if you see a CERT advisory it means that the 'crackers' known
about
the bug for weeks or even months. As always System Admins / Security is always
fighting
a catch up battle with no way of winning.
One way to actually know what is going on is to get on the 'cracker' web
sights, bbs's, IRC's
and fix the problems before they are released in CERT.
Follow-Ups:
|
|