Lessons Not Learned
Computerworld - What have we learned from the current stampede of Windows-infecting worms with names like Zotob, Esbot, Bobax and Spybot (see story)? First lesson: If you want to raise public awareness about a tired old subject like computer worms, just gore the oxes of reporters and editors at CNN, The New York Times, The Associated Press and ABC News. There's nothing like personal pain to freshen up a story. In CNN's case, there's nothing like having it happen on live TV.
Second lesson: Uh, is there a second lesson?
Probably not. After all, we already knew that the most common security hole is a buffer that can overflow if the code filling it doesn't check for input length. That's the programming flaw that these worms exploit -- a flaw that's been around since 1988, when the notorious "Morris worm" brought a much smaller Internet to its knees with a buffer overflow attack.
We already knew that it's a good idea for vendors to release patches as soon as vulnerabilities are made public. To Microsoft's credit, it shipped a patch the day it announced the security hole. (But no points to Microsoft for shipping products with the hole in the first place.)
We already knew that stretched-thin IT staffs have a tough time applying those patches quickly, because it takes time to test and then roll them out to servers and desktop PCs.
We already knew that publishing exploit code that can easily be pasted into worm programs is not helpful. Well, it's helpful to worm writers, but not to the rest of us. Such code was reportedly published on a security Web site the day after Microsoft got its patch out the door. Three days later, the Zotob worm was in the wild, infecting Windows machines.
We already knew that worm writers both share information and compete with one another. It's no great surprise that within hours, Zotob was joined by other worms exploiting the same hole -- and hammering away at Windows users.
So maybe there just isn't a lot to learn from this round of being overrun by worms.
But isn't it time we stopped treating worm outbreaks as learning experiences?
Isn't it time for Microsoft to stop selling operating systems with buffer overflow security holes? That wouldn't require bug-free programming -- just looking for and eradicating one particular kind of bug.
Yes, Microsoft is trumpeting that Vista (nee Longhorn) will be safe from buffer overflows when it ships next year. Then again, that promise was originally based on



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Reducing the Cost and Complexity of Web Vulnerability Management
- Hackers and cybercriminals are constantly refining their attacks and targets; which means you need agile tools to stay ahead of them.
Download this... - Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- Streamline Compliance and Increase ROI
- Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will... All Malware and Vulnerabilities White Papers
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
- Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
- Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
- Virtualize Business-Critical Applications with Confidence
- Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®... All Malware and Vulnerabilities Webcasts