Slashdot Mirror


Estimating the Time-To-Own of an Unpatched Windows PC

An anonymous reader notes a recent post on the SANS Institute's Internet Storm Center site estimating the time to infection of an unpatched Windows machine on the Internet — currently about 4 minutes. The researcher stipulated that the sub-5-minute estimate was valid for an unpatched machine in an ISP netblock with no NAT or firewall. The researcher, Lorna Hutcheson, called for others to post data on time-to-infection, and honeypot researchers in Germany did so the same day. They found longer times to infection, an average of 16 hours. Concludes the ISC's Hutchinson: "While the survival time varies quite a bit across methods used, pretty much all agree that placing an unpatched Windows computer directly onto the Internet in the hope that it downloads the patches faster than it gets exploited are odds that you wouldn't bet on in Vegas."

24 of 424 comments (clear)

  1. Baloney by Anonymous Coward · · Score: 1, Funny

    I am posting this message from a completely unpatched windows box on the Internet and I am not seeing any side eff....

    Buy Viagra Cheap at http://myipaddres/viaga

    1. Re:Baloney by Anonymous Coward · · Score: 1, Funny

      Pft. Newb. If you were smart, like me, you would have patched your Windows bo

      Buy Viagra Cheap at http://myipaddres/viaga

    2. Re:Baloney by SurturZ · · Score: 4, Funny

      Fools, don't you know that all you have to do is make sure you scan any flopp

      Buy Viagra Cheap at http://myipaddres/viaga

    3. Re:Baloney by Exitar · · Score: 5, Funny

      Haha, no problem for me with my Linux dis

      Buy Viagra Cheap at http://myipaddres/viaga

    4. Re:Baloney by Anonymous Coward · · Score: 2, Funny

      Well, once again, me and my Mac have been proven to be superi

      Buy Viagra Cheap at http://myipaddres/viaga

    5. Re:Baloney by Anonymous Coward · · Score: 1, Funny

      This reminds me, can your OS be shut off remotely? Because I just got a new dell, and I'm wondering if I install linux can dell jack my computer and turn it off remo

    6. Re:Baloney by Exitar · · Score: 2, Funny

      Hey, are you hitting on me?!?

  2. Re:Um, what version? by Anonymous Coward · · Score: 4, Funny

    Would be interesting to compare with Vista.

    They tried. They ran into some obscure bug with Vista that prevents it from accessing the internet while the machine is powered on.

  3. Typical /. Hypocrisy! by Anonymous Coward · · Score: 5, Funny

    I keep hearing on /. about how slow Windows is. Now it turns out that Windows is very fast.

    1. Re:Typical /. Hypocrisy! by pbhj · · Score: 4, Funny

      Now it turns out that Windows is very fast.

      Kinda like a high priced callgirl...and just as expensive to purchase.

      But you only get to use windows for a couple of hours before you get a virus ... oh, wait ...

  4. Re:I have to call BS by Anonymous Coward · · Score: 5, Funny

    I never patch my windows unless its a service pack and I run just fine... Always have my Antivirus running and Windows defender with a router with built-in firewall... No complaints for the 7 years since I built my pc....

    Indeed, your computer is a valued member of our botnet.

  5. Re:How is this measured by BazilBBrush · · Score: 2, Funny

    How is this statistic measured?

    How long is a piece of string?

    Pretty short in this case...

  6. Anonymous Coward by Anonymous Coward · · Score: 1, Funny

    Why does my IT guy always say PwN3D? he actually pronounces the "3" in klingon. Does this somehow relate?

  7. Re:What? by Anonymous Coward · · Score: 1, Funny

    Luck.
    hell people have managed to survive jumping from airplanes without a parachute.

  8. Re:How is this measured by Alpha+Whisky · · Score: 4, Funny

    I'd mod you funny if I had modpoints. I think he probably meant no router/firewall, Microsoft's toy firewall enabled by default in SP2 is about as effective protection as a wet paper bag would be against a rocket propelled grenade. Or for the Slashdot crowd who only understand car analogies, as good a protection as a Ford Pinto crashed into by an express train.

    --
    it's = it is

    its = belonging to it

  9. It just means your aquarium populates faster now.. by vittal · · Score: 2, Funny
  10. Re:wholesale jewelry by bloodninja · · Score: 3, Funny

    Slashdot the spammers!

    --
    Lock the wife and the dog in the boot of the car.
    Return one hour later.
    Who's happy to see you?
  11. Re:How is this measured by BillyGee · · Score: 2, Funny

    FUD much? I think if one gave you a default install XP SP2 to play with remotely, you'd get frustrated oh in about 30 minutes, shrug and go back to WoW.

  12. Re:Honeynet by bloodninja · · Score: 5, Funny

    If this is Windows XP, why isn't there an article on the time-to-own for an unpatched RedHat 8 install?

    Can you still buy Redhat 8?

    Can you still buy Windows XP?

    --
    Lock the wife and the dog in the boot of the car.
    Return one hour later.
    Who's happy to see you?
  13. Re:Doesn't make sense by bloodninja · · Score: 2, Funny

    As the OP said, just don't browse the web while you're doing a server install.

    Yeah, let's see YOU install Gentoo without browsing the web.

    --
    Lock the wife and the dog in the boot of the car.
    Return one hour later.
    Who's happy to see you?
  14. Re:How is this measured by PopeRatzo · · Score: 4, Funny

    but who has access to two computers at home?

    Everybody who would be reading this article?

    --
    You are welcome on my lawn.
  15. Re:How is this measured by phoenixwade · · Score: 2, Funny

    if everyone was computer savvy like most of us here then there would be hardly any need for The Geek Squad, and others.

    Are you sure there is a need for geek squad? People can steal porn off of computers without professional help....

    --
    A positive attitude may not solve all your problems, but it will annoy enough people to make it worth the effort.
  16. Re:Funny thing is that Zone Alarm has had vulns by ColaMan · · Score: 3, Funny

    How hard would it be for Microsoft to add a patch CD to the box, or when patches are released to ship patch CDs..... to people that ask nicely for them?

    It seems that it's not that hard, seeing that they already do.

    Your homework for today is to find the link at Microsoft's site that lets you get a copy of the SP3 security update CD mailed to you, and post it below. Extra points if you can write a script that goes through your local phone book and orders a CD for each person.

    --

    You are in a twisty maze of processor lines, all alike.
    There is a lot of hype here.
  17. Re:How is this measured by ozmanjusri · · Score: 4, Funny
    those who ignore MS's progress from the Blaster days are just spewing FUD.

    Exactly.

    Everybody's long since upgraded to the Storm worm.

    --
    "I've got more toys than Teruhisa Kitahara."