Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Study: Unpatched PCs compromised in 20 minutes
News.com ^ | August 17, 2004, 12:22 PM PDT | Matt Loney and Robert Lemos

Posted on 08/18/2004 10:04:30 AM PDT by glorgau

Don't connect that new PC to the Internet before taking security precautions, researchers at the Internet Storm Center warned Tuesday.

According to the researchers, an unpatched Windows PC connected to the Internet will last for only about 20 minutes before it's compromised by malware, on average. That figure is down from around 40 minutes, the group's estimate in 2003.

The Internet Storm Center, which is part of the SANS Institute, calculated the 20-minute "survival time" by listening on vacant Internet Protocol addresses and timing the frequency of reports received there.

"If you are assuming that most of these reports are generated by worms that attempt to propagate, an unpatched system would be infected by such a probe," the center, which provides research and education on security issues, said in a statement.

The drop from 40 minutes to 20 minutes is worrisome because it means the average "survival time" is not long enough for a user to download the very patches that would protect a PC from Internet threats.

Scott Conti, network operations manager for the University of Massachusetts at Amherst, said he finds the center's data believeable.

"It's a tough problem, and it's getting tougher," Conti said.

One of Conti's administrators tested the center's data recently by placing two unpatched computers on the network. Both were compromised within 20 minutes, he said.

The school is now checking the status of computers before letting them connect to the Internet. If a machine doesn't have the latest patches, it gets quarantined with limited network access until the PC is back up to date.

"We are giving the people the ability to remediate before connecting to the network," Conti said.

The center also said in its analysis that the time it takes for a computer to be compromised will vary widely from network to network.

If the Internet service provider blocks the data channels commonly used by worms to spread, then a PC user will have more time to patch.

"On the other hand, university networks and users of high-speed Internet services are frequently targeted with additional scans from malware like bots," the group stated. "If you are connected to such a network, your 'survival time' will be much smaller."

In a guide to patching a new Windows system, the Internet Storm Center recommends that users turn off Windows file sharing and enable the Internet Connection Firewall. Microsoft's latest security update, Windows XP Service Pack 2, will set such a configuration, but users will have to go online to get the update, opening themselves up to attack.

One problem, experts say, is network administrators' reliance on patching and their assumption that users will quickly patch systems.

Speaking recently at the Microsoft TechEd developer conference in Amsterdam, Microsoft security consultant Fred Baumhardt said the day is likely to come when a virus or worm brings down everything.

"Nobody will have time to detect it," he said. "Nobody will have time to issue patches or virus definitions and get them out there. This shows that patch management is not the be-all and end-all."

Baumhardt stressed the importance of adaptability, using the human immune system as an example: "Imagine if your body said, 'Hmm, I have the flu. I've never had this before, so I'll die.' But that doesn't happen: Your body raises its temperature and so on, to buy time while other mechanisms kick in."

"If the human body did patch management the way (companies do), we'd all be dead."

Matt Loney of ZDNet UK reported from London.


TOPICS: Business/Economy; Culture/Society; Technical
KEYWORDS: exploit; getamac; internetexploiter; lowqualitycrap; microsoft; microsoftwindows; patch; securityflaw; trojan; virus; windows; worm
Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-8081-87 next last
To: 4ConservativeJustices

In ingles, por favor????? :> Mac's easier/shrugging... check on it anoche


41 posted on 08/18/2004 11:10:24 AM PDT by Ff--150 (The masses have no habit of self reliance or original action. -- Anon.)
[ Post Reply | Private Reply | To 35 | View Replies]

To: steplock
If everyone had a mac, then MAC's would be getting destroyed...

You are assuming that the security models for Windows and Mac (and Linux) are identical. They aren't. It's like saying that the damage would be identical if a tornado went through a brick home community rather than through a trialer park.

I prefer the security of my brick home (linux) over trailers (Windows).

42 posted on 08/18/2004 11:10:30 AM PDT by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 9 | View Replies]

To: glorgau

Okay, so how do you do this if you have to have the patch to get on the internet safely and you can't get the patch without getting on the internet?


43 posted on 08/18/2004 11:11:41 AM PDT by sweetliberty ("A wise man's heart inclines him to the right, but a fool's heart to the left." (Eccl. 10:2))
[ Post Reply | Private Reply | To 1 | View Replies]

To: aft_lizard
RegRun Gold,

That's one I haven't heard of .

44 posted on 08/18/2004 11:11:59 AM PDT by Ernest_at_the_Beach (A Proud member of Free Republic ~~The New Face of the Fourth Estate since 1996.)
[ Post Reply | Private Reply | To 20 | View Replies]

To: sweetliberty
Okay, so how do you do this if you have to have the patch to get on the internet safely and you can't get the patch without getting on the internet?

That would be the Question Of The Day (TM), wouldn't it?

Is 'whistle past the graveyard' a valid answer?

45 posted on 08/18/2004 11:16:03 AM PDT by LTCJ (God Save the Constitution.)
[ Post Reply | Private Reply | To 43 | View Replies]

To: glorgau

I'm not surprised. Whenever I have to disconnect my NAT firewall for even a short period of time and later look at the ZoneAlarm log I see dozens of incoming attempts to get into my system.


46 posted on 08/18/2004 11:18:24 AM PDT by octobersky
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ff--150
In ingles, por favor????? :> Mac's easier/shrugging... check on it anoche

Mac is far easier to defend, but not invulnerable. Windows is targeted bacuse the vulnerabilities exist on more desktops. Assume that you knew a secret combination to aparticular brand of safe - would you waste time attacking others when such easy pickings existed?

All these various programs (the ones I listed are all free) do is defend computer from attacks. Some are browser hijackers designed to generate income for a site, other are designed to record your keystrokes, credit card numbers etc.

Without protection, the only secure PC is one not attached to another, and no means of doing so.

Add Mailwasher to the list - preview email before downloading, prevent malware from loading when reading mail. Trask junk before it gets into 'puter.

47 posted on 08/18/2004 11:21:22 AM PDT by 4CJ (||) Men die by the calendar, but nations die by their character. - John Armor, 5 Jun 2004 (||)
[ Post Reply | Private Reply | To 41 | View Replies]

To: All
In addition to a software firewall like Norton or Zone Alarm, one should also have a hardware firewall. Usually most routers have one built in and hardware firewalls provide a much higher level of protection than software ones do.
48 posted on 08/18/2004 11:22:16 AM PDT by COEXERJ145 (I Annoy Buchananites)
[ Post Reply | Private Reply | To 1 | View Replies]

To: sweetliberty
Okay, so how do you do this if you have to have the patch to get on the internet safely and you can't get the patch without getting on the internet?


49 posted on 08/18/2004 11:22:44 AM PDT by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 43 | View Replies]

To: nyconse

The problem is Bell South, like other ISP's are in a catch 22. The real issue here is that hackers are getting more vicious in their attacks and there are not enough security people to weed them out, prosecute them and feed them to the sharks.

If you do not want your computer to catch a virus, worm, adware, get hacked, whatever there is only one solution.

Do not turn it on.


50 posted on 08/18/2004 11:23:09 AM PDT by Leatherneck_MT (Goodnight Chesty, wherever you may be.)
[ Post Reply | Private Reply | To 8 | View Replies]

To: steplock
I have a virus and I'm just about ready to sacrifice a goat to get rid of it. From what I've been able to ascertain the virus attached to McAfee's mghtml.dll and perhaps other dlls and now I can't get ANY virus protection software to work. It first presented itself through Outlook. When I try to "send and receive" I get a message that tells me I don't have permission to perform the operation. The virus apparently locks the outlook file.

McAfee support is ZERO help. When I try to re-install I get JavaScript errors, "Access Denied". Same thing happens when I try to access their online support. I called McAfee and they told me I couldn't access their site because I have a virus. What!?? Then they tell me to pay 2.95 a minute to get the problem resolved. So, my McAfee software was the conduit for the virus and McAfee wants me to PAY THEM to fix it? I think I might explode any minute now.

I ran hijackthis and deleted everything that looks suspicious. I was able to run the online virus check at TrendMicro but it didn't find anything. I don't know what else to do. **wimper** Does anyone have any ideas?
51 posted on 08/18/2004 11:28:26 AM PDT by hobson
[ Post Reply | Private Reply | To 19 | View Replies]

To: 4ConservativeJustices

LOL the you-know-what here is goin' go look at e-machines in a few hours--gettin' nervous, ya know :-)


52 posted on 08/18/2004 11:30:28 AM PDT by Ff--150 (The masses have no habit of self reliance or original action. -- Anon.)
[ Post Reply | Private Reply | To 47 | View Replies]

To: Leatherneck_MT

Unfortunately, you are absolutely correct about this.


53 posted on 08/18/2004 11:34:59 AM PDT by nyconse
[ Post Reply | Private Reply | To 50 | View Replies]

To: steplock
Why does anyone continue to use Internet Explorer as a web browser? It's so slow and it allows popup ads.

Instead, try out Mozilla and configure to block popups.

Also, set your cache to zero. There is no reason to save 50 MB of ads and old pictures on your HD. Besides, if the browser sees zero cache, it will not spend time looking there and will load images faster.

54 posted on 08/18/2004 11:37:26 AM PDT by zeebee
[ Post Reply | Private Reply | To 19 | View Replies]

To: hobson

Try this link-you can try it for free. It's called e-scan it found stuff that no other AV found.

http://www.mwti.net/antivirus/escan/escan.asp


55 posted on 08/18/2004 11:37:44 AM PDT by nyconse
[ Post Reply | Private Reply | To 51 | View Replies]

To: nyconse

Thanks! I'll try it.


56 posted on 08/18/2004 11:42:54 AM PDT by hobson
[ Post Reply | Private Reply | To 55 | View Replies]

To: nyconse

Ok just wondering


57 posted on 08/18/2004 11:43:53 AM PDT by Leatherneck_MT (Goodnight Chesty, wherever you may be.)
[ Post Reply | Private Reply | To 53 | View Replies]

To: hobson

Also, do you know how to check your permissions on the registry. Some of this stuff can actually deny you access to your own computer. You can fix this by going on as an administrator, but be careful. Someone I know goofed and no one could get in. I eventually found a way around it, but it took much work. If you know the name of your virus, type it into google. Lots of white knights out there who will help you. I learned plenty by lurking on those sites. If you are running xp-run e-scan first to see if it is in your restore files. If it is in these files. You need to disable system restore and run it again.


58 posted on 08/18/2004 11:44:55 AM PDT by nyconse
[ Post Reply | Private Reply | To 51 | View Replies]

To: nyconse

Ooops, wrong reply lol.

I've been working in computers and networking since 1987. The change I have seen in this industry in that amount of time is staggering.

We have come a long way in being able to defeat hackers and script kiddies, but we are still playing catchup.

Unfortunately anything that man can build, man can defeat.


59 posted on 08/18/2004 11:45:57 AM PDT by Leatherneck_MT (Goodnight Chesty, wherever you may be.)
[ Post Reply | Private Reply | To 53 | View Replies]

To: Leatherneck_MT

I agree with all your posts. We are never going to get rid of this problem, but we can reduce it. I help people with their computers sometimes, and I am appalled at the fact they do not protect their computers. Viruses would not spread so fast if people would just update and run anti-trojan programs. many of these programs are free. You are still going to have problems, but you will have less trouble


60 posted on 08/18/2004 11:49:18 AM PDT by nyconse
[ Post Reply | Private Reply | To 59 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-8081-87 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson