Estimating the Time-To-Own of an Unpatched Windows PC
An anonymous reader notes a recent post on the SANS Institute's Internet Storm Center site estimating the time to infection of an unpatched Windows machine on the Internet — currently about 4 minutes. The researcher stipulated that the sub-5-minute estimate was valid for an unpatched machine in an ISP netblock with no NAT or firewall. The researcher, Lorna Hutcheson, called for others to post data on time-to-infection, and honeypot researchers in Germany did so the same day. They found longer times to infection, an average of 16 hours. Concludes the ISC's Hutchinson: "While the survival time varies quite a bit across methods used, pretty much all agree that placing an unpatched Windows computer directly onto the Internet in the hope that it downloads the patches faster than it gets exploited are odds that you wouldn't bet on in Vegas."
I am posting this message from a completely unpatched windows box on the Internet and I am not seeing any side eff....
Buy Viagra Cheap at http://myipaddres/viaga
Would be interesting to compare with Vista.
They tried. They ran into some obscure bug with Vista that prevents it from accessing the internet while the machine is powered on.
I keep hearing on /. about how slow Windows is. Now it turns out that Windows is very fast.
I never patch my windows unless its a service pack and I run just fine... Always have my Antivirus running and Windows defender with a router with built-in firewall... No complaints for the 7 years since I built my pc....
Indeed, your computer is a valued member of our botnet.
How is this statistic measured?
How long is a piece of string?
Pretty short in this case...
Why does my IT guy always say PwN3D? he actually pronounces the "3" in klingon. Does this somehow relate?
Luck.
hell people have managed to survive jumping from airplanes without a parachute.
I'd mod you funny if I had modpoints. I think he probably meant no router/firewall, Microsoft's toy firewall enabled by default in SP2 is about as effective protection as a wet paper bag would be against a rocket propelled grenade. Or for the Slashdot crowd who only understand car analogies, as good a protection as a Ford Pinto crashed into by an express train.
it's = it is
its = belonging to it
http://xkcd.com/350/
Slashdot the spammers!
Lock the wife and the dog in the boot of the car.
Return one hour later.
Who's happy to see you?
FUD much? I think if one gave you a default install XP SP2 to play with remotely, you'd get frustrated oh in about 30 minutes, shrug and go back to WoW.
If this is Windows XP, why isn't there an article on the time-to-own for an unpatched RedHat 8 install?
Can you still buy Redhat 8?
Can you still buy Windows XP?
Lock the wife and the dog in the boot of the car.
Return one hour later.
Who's happy to see you?
As the OP said, just don't browse the web while you're doing a server install.
Yeah, let's see YOU install Gentoo without browsing the web.
Lock the wife and the dog in the boot of the car.
Return one hour later.
Who's happy to see you?
Everybody who would be reading this article?
You are welcome on my lawn.
if everyone was computer savvy like most of us here then there would be hardly any need for The Geek Squad, and others.
Are you sure there is a need for geek squad? People can steal porn off of computers without professional help....
A positive attitude may not solve all your problems, but it will annoy enough people to make it worth the effort.
How hard would it be for Microsoft to add a patch CD to the box, or when patches are released to ship patch CDs..... to people that ask nicely for them?
It seems that it's not that hard, seeing that they already do.
Your homework for today is to find the link at Microsoft's site that lets you get a copy of the SP3 security update CD mailed to you, and post it below. Extra points if you can write a script that goes through your local phone book and orders a CD for each person.
You are in a twisty maze of processor lines, all alike.
There is a lot of hype here.
Exactly.
Everybody's long since upgraded to the Storm worm.
"I've got more toys than Teruhisa Kitahara."