quote: Originally posted by jusunlee
yes, the vulnerability was discovered more than six months ago, on may 15, 2002, with a public announcement on july 25, 2002. microsoft issued a hotfix for mssql2000 service pack 2, followed by service pack 3 which resolved the issue. go here for more information.
its amazing how lazy some sysadmins are, especially those in korea. korea was hit hardest from 'code red' not less than two years ago. yet that didnt stop the admins there from being prompt to patch for future security issues. had all sysadmins been diligent, 'sapphire' wouldnt have caused much havoc.
ofcourse, this, like 'code red', only affected microsoft servers. maybe its time the world switched to linux servers, paired with more competent admins.
werd.
__________________
"Love is like a friendship caught on fire. In the beginning a flame, very pretty, often hot and fierce, but still only light and flickering. As love grows older, our hearts mature and our love becomes as coals, deep-burning and unquenchable. " - Bruce Lee
|