Iain Thomson
Iain Thomson

Did Sasser leave you shamefaced?

Many IT managers are being caught out by the speed at which hackers are reverse-engineering patches

Iain Thomson

Anyone working in technology knows that they are permanently on call to friends and family for technical support.

So even while on holiday last week I disinfected a couple of PCs that had fallen victim to Sasser variants for good friends who were just a few weeks late in deploying patches.

Advertisement

This speed in reverse-engineering patches is an issue that affects us all. And judging from the infection rate of the Sasser worm, many corporate IT managers should be looking a little shamefaced.

If Sasser was built by reverse-engineering a Microsoft patch in record time it only confirms what many security professionals have been saying for years: patch management is becoming ever more crucial.

Back in simpler times reverse-engineering patches was a long process and IT managers could expect to have months before an exploit was found. But now it seems that hackers are banding together to crack patches faster.

This is perfectly understandable from their perspective. Why do all the tedious work of finding an unknown vulnerability when the manufacturer has told you what to look for?

By reverse-engineering patches the hackers are relying on the overworked IT manager or under-informed consumer not patching their systems as soon as possible.

From an IT manager's perspective it's a case of damned if you do and damned if you don't.

Patching is a notoriously labour intensive task, and there is always the risk that a patch might do something unexpected to your carefully tweaked systems.

But if anything good can come of Sasser it will be to provide a potent example for the board next time they complain about network downtime.

Patching must be done immediately; the hackers won't wait and neither should you.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

Madeline Bennett

Could prison cure viruses?

Will the sentences imposed by courts really serve as a deterrent against virus writers?

Sasser F blames it on Bill

Unpatched computers at risk

Sasser strikes back despite arrest

German law enforcement picks up alleged virus writer, but new variant emerges

Patch now or suffer Sasser

'Dark forecast' as Windows users warned of new family of viruses

Related whitepapers

Related jobs

Most watched

Summit video: Intel discusses processors designed for data overload (part one of two)

Intel explains how its Xeon processors can handle data-intensive apps

Summit: Intel discusses processors for data overload (part 2 of 2)

More thoughts on how servers can help manage overload

Analysis and Reports

Remote access - Three steps to getting connected

3.4 million UK professionals now work from home – is your company equipped?

Cost benefits of a global collaboration network

This white paper is a must read for organisations looking for evidence of the bottom-line benefits of high-definition video and voice communications

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

White paper library

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Spotlight

deloitte

Summit interview: Deloitte discusses security implications of the data deluge

We chat to Mike Maddison, UK head of Security, Privacy...

ibm logo

IBM boosts mobile shopping with WebSphere Commerce

Update designed to give mobile users a richer, more personalised...

Summit: Intel discusses processors for data overload (part 2 of 2)

More thoughts on how servers can help manage overload

chrome logo

Google plans a Mac version of Chrome

A Mac-friendly version of the browser is in the pipeline

Primary Navigation