Advertisement
Promo

Security threats Toolkit

Story: Downadup worm infects 3.5m PCs

  • Previous comment

Posted by: lumension (Friday 16 January 2009, 11:58 PM)

  • Reply

Challenge your IT team - ask about their patch management strategy

The continued growth of the MS08-67 RPC issue really drives home the point that while firewalls and antivirus have evolved to become mainstays in network defense, all too many fail to realise that vulnerability management and patching is in fact a critical component of the very foundation of network security. Firewalls and AV are only one level of defence and really are insufficient if they are deployed on top of a weak foundation – lacking underlying vulnerability and patch management.

Take note:
SANS recently reported a clever social engineering trick by the malware – when the autorun.inf triggers the pop up autoplay dialog it changes the executable icon to that of a folder. The user is then tricked into clicking on the folder thinking they are simply going to view the files, NOT knowing that they were actually causing the execution of the malicious program when they click on the folder icon.

Ask about your own organisations patch management approach - the tools we have today are easy to deploy and automate the whole patch management process across a corporate network to really take control by identifying and remediating known vulnerabilities.

Beyond that, ask about Application Control - it can be used effectively to stop this type of infection in it's tracks by preventing the malware from executing in the first place.

Private message disabled

lumension

lumension
LONDON, UK
Member since: October 2008

Site Activity Rating:

3

 


  • Previous comment

  • Reply to this comment
  • Return to story
  • Report this as offensive


Full Talkback thread


Video icon

Video

Sentry Posts Blog

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Beware of keeping your head in the clo...

Information security professionals can look forward to a deepening appreciation for their skills as security continues to be recognised as an essential element for doing business in... More

1 comment

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment

Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters