<RANT>

I just have to chime in with my two cents here.  Jochem makes an
excellent point about being late with patching servers to fix a
well-publicized security hole.  I own and manage a small hardware store
in a New York suburb.  We have two small web servers, do some ecommerce
and a bit of web hosting.  Out ecommerce and web hosting make up about
.5% of our annual revenues, so it's a TINY portion of our business.

I subscribe to NTBugtraq, all the MS security lists, MS-Info, SANS
newsletter, Website Talk (no .ida problems with Website Pro!), CF-Talk
and CF-Community, and several others related to web servers.  I install
every patch, update, service pack, virus update, etc.  Honestly, our
Internet stuff is almost a hobby...so I'm constantly amazed when people
who maintain servers and GET PAID FOR IT neglect to keep up with the
latest security patches and updates.

</RANT>

OK, back to cutting some keys and selling some grass seed.

John
www.cornells.com 

> -----Original Message-----
> From: Jochem van Dieten [mailto:[EMAIL PROTECTED]] 
> Sent: Thursday, July 19, 2001 6:18 PM
> To: CF-Talk
> Subject: Re: Service pack 6a?
> 
> 
> Jeff Green wrote:
> 
> > Hi all,
> > 
> > Im running NT 4.0 with cf 4.5.2 we just had problems with the ida 
> > hack, and we just patched.
> 
> 
> You ought to be prosecuted for criminal negligence because you didn't 
> patch this earlier. If you are a hosting service and had any service 
> disruption because of this you are lucky I am not your customer.
> 
> This is not a troll/flame or anything, it is just my professional 
> 
> opinion on being one month late with patching a server with a 
> well published 
> 
> bug.
> 
> > I was wondering if it was a good idea to upgrade to sevice 
> pack 6a?  
> > We currently have 5.
> 
> 
> Depends on the reasons for upgrading. AFAIK this is not a problem 
> specific to SP6a. Some problems can only be fixed by using 
> SP6a, so then it is a good idea ;)
> 
> Jochem
> 
> 


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Structure your ColdFusion code with Fusebox. Get the official book at 
http://www.fusionauthority.com/bkinfo.cfm

Archives: http://www.mail-archive.com/[email protected]/
Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists

Reply via email to