Security holes... Who cares?

Eric Rescorla ekr at rtfm.com
Sun Nov 17 11:46:43 EST 2002


I thought this paper might be of interest to the cryptography folks.

                      Security holes... Who cares?

                              Eric Rescorla
                      RTFM, Inc.   <http://www.rtfm.com/>

We report on an observational study of user response following the
OpenSSL remote buffer overflows of July 2002 and the worm that exploited
it in September 2002.  Immediately after the publication of the bug and
its subsequent fix we identified a set of vulnerable servers. In the
weeks that followed we regularly probed each server to determine whether
it had applied one of the relevant fixes. We report two primary
results. First, we find that administrators are generally very slow to
apply the fixes. Two weeks after the bug announcement, more than two
thirds of servers were still vulnerable. Second, we identify several
weak predictors of user response and find that the pattern differs in
the period following the release of the bug and that following the
release of the worm.

The paper can be downloaded from:
http://www.rtfm.com/upgrade.pdf
http://www.rtfm.com/upgrade.ps

-Ekr

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo at wasabisystems.com



More information about the cryptography mailing list