Free Republic
Browse · Search
General/Chat
Topics · Post Article

I am merely the messenger. Discuss.
1 posted on 01/09/2006 3:50:14 PM PST by cabojoe
[ Post Reply | Private Reply | View Replies ]


To: cabojoe

Link to CERT report: http://www.us-cert.gov/cas/bulletins/SB2005.html#UnixLinux


2 posted on 01/09/2006 3:50:45 PM PST by cabojoe
[ Post Reply | Private Reply | To 1 | View Replies ]

To: cabojoe

Linux is less popular and thus less targeted by hackers, etc. Take your pick.


3 posted on 01/09/2006 3:57:58 PM PST by RedBeaconNY (Vous parlez trop, mais vous ne dites rien.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: cabojoe

I am a Windows/Capitalism fan as much as the next guy, but I don't know if it's entirely fair to lump Linux with Apple. Of course, as someone else said, it's hard not to have scrutiny when you're installed on about 97% of the world's personal computers. The most recent Windows flaw, dealing with images, affected every Windows OS since 1990! It took that long to discover.


4 posted on 01/09/2006 4:10:54 PM PST by Dan Nunn (http://marklevinfan.com/Audio/WhyAreWeAtWar.wma)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: backhoe

ping.


9 posted on 01/09/2006 6:42:54 PM PST by Jet Jaguar
[ Post Reply | Private Reply | To 1 | View Replies ]

To: rdb3; chance33_98; Calvinist_Dark_Lord; Bush2000; PenguinWry; GodGunsandGuts; CyberCowboy777; ...
From NewsForge::
After all this time, you'd think that the mainstream tech press could get it right when reporting on security. The sheer number of vulnerabilities means little when compared with other factors, such as the severity of the vulnerability, how easy it is to exploit the vulnerability, and how long it takes a vendor to respond to the vulnerability.

So you want to talk about vulnerabilities?

While some outlets are saying that "Windows beats Linux/Unix on vulnerabilities," Windows admins are sweating the WMF vulnerability without any patch available from Microsoft. Microsoft disclosed the WMF vulnerability on December 27. This was a zero-day exploit, meaning that exploits were found in the wild before the vulnerability was known.

Here we are, more than a week later, and Windows admins are having to use unofficial patches to try to protect themselves. Microsoft says it expects to have a patch next week, if it passes quality testing, meaning the window of opportunity for this nasty little vulnerability will be at least two weeks. One source cites at least 70 malicious WMF files in the wild so far.

It's worth noting that this vulnerability is a design issue, not a buffer overflow or some other exotic exploit -- WMFs are supposed to be able to call external procedures and execute code. Microsoft is vulnerable because the company included a feature to run arbitrary code from an image file.

This is not to say that the data from US-CERT is a meaningless aggregation. You can easily spot the most vulnerable operating system in wide use today by taking a look at the Technical Cyber Security Alerts issued by US-CERT last year. Here's the bottom line:

That's quite a different picture than the one the Microsoft press machine wants you to see. Here's more of the same. US-CERT's list of current vulnerabilities contains a total of 11 vulnerabilities, six of which mention Windows by name, and none of which mentions Linux.

10 posted on 01/10/2006 6:32:13 AM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: cabojoe

:Cert included under the Linux umbrella Mac OS X, as well as the various Linux distributions and flavours of Unix. It claimed that the Unix camp had more than twice as many vulnerabilities as Windows.

The Cyber Security Bulletin 2005, said that out of 5,198 reported flaws, 812 were Windows operating system vulnerabilities, while 2,328 were Unix/Linux operating bugs. "


So they took a dozen or more duifferent versions and added together the flaws and got a larger number than one operating system by itself so they declared that one operating system "safer."


Somebody is either stupid or paid off.


Let's apply that reasoning to homeland security: There are more security threats in the other 49 states put together than in New York by itself. Therefore New York is the safest state for terrorist attacks.


11 posted on 01/10/2006 6:42:21 AM PST by gondramB (Democracy: two wolves and a lamb voting on lunch. Liberty: a well-armed lamb contesting the vote.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: cabojoe

As far as the argument about flaws taking Microsoft longer to discover/fix goes, common sense would tell you that Open Source flaws are easier to discover since everyone can analyze the source code directly and immediately.

I have to agree that lumping the MAC OS in with out UNIX variants is mixing apples and oranges (pardon the pun).


12 posted on 01/10/2006 7:32:11 AM PST by contemplator (Capitalism gets no Rock Concerts)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: cabojoe
Wow what a poor technical writer this person is! lets start with this:

Computer Emergency Readiness Team (CERT) has prepared a report for the government that claims that fewer vulnerabilities were found in Windows than in Linux/Unix operating systems in 2005

Looking at the cert list he based this off of I seem many thigs which are not Linux such as Apache, BZIP, Ethereal, and other *applications*. A bug in the windows version of Apache is not a windows bug, its an apache bug but apparently a bug in the Linux version of apache is a Linux bug.

Cert included under the Linux umbrella Mac OS X, as well as the various Linux distributions and flavours of Unix. It claimed that the Unix camp had more than twice as many vulnerabilities as Windows.

So Linux, OSX, and about a dozen UNIX operating systems are double that of windows? Why not count just Linux, or OSX, or Solaris? What this means is that vulnerabilities in the kernel are not only counted in every Linux distro but also problems which affect multiple UNIX distros are counted.

The remaining 2,058 were multiple operating system vulnerabilities. It is possible to hear the sounds of the provisional wing of the Linux and Apple glee clubs strapping cyber explosives to their belts at the announcement.

Ahh yes, this explains it its a hit piece.

It seems that the figures prove the impression of many in the security industry that the only reason Windows boxes get turned over the most is because there are more of them.

If one completely ignores the weakness of the study which include:

*couning Solairs, HP-UX, AIX, Linux, RedHat, Suse, Applications that run on any of these platforms

*Ignoring time to patch by the vendor

*Ignoring the severty of the bug

Then this statement might have merit.

13 posted on 01/10/2006 7:54:36 AM PST by N3WBI3 (If SCO wants to go fishing they should buy a permit and find a lake like the rest of us..)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: cabojoe
THE UNITED STATES Computer Emergency Readiness Team (CERT) has prepared a report for the government that claims that fewer vulnerabilities were found in Windows than in Linux/Unix operating systems in 2005.

"What is found" and "What exist" are two VERY different things.

48 posted on 01/10/2006 9:55:49 PM PST by Petronski (I love Cyborg!)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: cabojoe

I think so few own them that the hackers have gone after the 95% windows units for the most vast results.


73 posted on 01/12/2006 2:06:14 PM PST by A CA Guy (God Bless America, God bless and keep safe our fighting men and women.)
[ Post Reply | Private Reply | To 1 | View Replies ]

Free Republic
Browse · Search
General/Chat
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson