<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.3.1" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: Attacks</title>
	<link>http://security-samizdat.com/attacks/</link>
	<description>Information Security, from a pragmatic point of view</description>
	<pubDate>Tue, 08 Jul 2008 21:32:55 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.1</generator>
		<item>
		<title>By: jacko</title>
		<link>http://security-samizdat.com/attacks/#comment-11</link>
		<dc:creator>jacko</dc:creator>
		<pubDate>Sat, 24 Feb 2007 13:22:21 +0000</pubDate>
		<guid>http://security-samizdat.com/attacks/#comment-11</guid>
		<description>Blind patching is a problem like you describe, Pete. However a good patch management process should take testing, regression bugs and proper risk assessment into account.

Proper controls? of course, a proper Change&#38;Configuration Management process and Risk Management process go a long way.

Jacko</description>
		<content:encoded><![CDATA[<p>Blind patching is a problem like you describe, Pete. However a good patch management process should take testing, regression bugs and proper risk assessment into account.</p>
<p>Proper controls? of course, a proper Change&amp;Configuration Management process and Risk Management process go a long way.</p>
<p>Jacko</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pete</title>
		<link>http://security-samizdat.com/attacks/#comment-9</link>
		<dc:creator>pete</dc:creator>
		<pubDate>Fri, 23 Feb 2007 17:13:17 +0000</pubDate>
		<guid>http://security-samizdat.com/attacks/#comment-9</guid>
		<description>Patching is often the wrong response.  It often only fixes one small part of a service without regard to further potential bugs and provides a false sense of security.  That is if it doesn't break more while it fixes.  The right response is to assure proper controls are in place and to only use hardened servers and services in hostile environments (like the Internet).</description>
		<content:encoded><![CDATA[<p>Patching is often the wrong response.  It often only fixes one small part of a service without regard to further potential bugs and provides a false sense of security.  That is if it doesn&#8217;t break more while it fixes.  The right response is to assure proper controls are in place and to only use hardened servers and services in hostile environments (like the Internet).</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.448 seconds -->
