[12062] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Security holes... Who cares?

daemon@ATHENA.MIT.EDU (Eric Rescorla)
Tue Nov 19 16:39:35 2002

To: cryptography@wasabisystems.com
Date: Sun, 17 Nov 2002 08:46:43 -0800
From: Eric Rescorla <ekr@rtfm.com>

I thought this paper might be of interest to the cryptography folks.

                      Security holes... Who cares?

                              Eric Rescorla
                      RTFM, Inc.   <http://www.rtfm.com/>

We report on an observational study of user response following the
OpenSSL remote buffer overflows of July 2002 and the worm that exploited
it in September 2002.  Immediately after the publication of the bug and
its subsequent fix we identified a set of vulnerable servers. In the
weeks that followed we regularly probed each server to determine whether
it had applied one of the relevant fixes. We report two primary
results. First, we find that administrators are generally very slow to
apply the fixes. Two weeks after the bug announcement, more than two
thirds of servers were still vulnerable. Second, we identify several
weak predictors of user response and find that the pattern differs in
the period following the release of the bug and that following the
release of the worm.

The paper can be downloaded from:
http://www.rtfm.com/upgrade.pdf
http://www.rtfm.com/upgrade.ps

-Ekr

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@wasabisystems.com

home help back first fref pref prev next nref lref last post