THE RISKS OF ‘NOT’ PATCHING… WWW.SBSDIVA.COM The risks of Patching… THE RISKS OF ‘NOT’ PATCHING… WWW.SBSDIVA.COM
Who am I? Patchaholic SBS MVP Security MVP Been ‘patchin’ SBS’s since SBS 4.0 Used to squint when rebooting
So… what’s the first questions to ask? What tool? What patch engine? What will break what? Tool isn’t important Process
What is a patch? Bug Flaw Something that needs fixing Patch = Security patch
Why ‘should’ we patch? Worst case scenario Fixing an issue where attacker from remote can hurt Code Execution Take control of system
Understanding the risks of patching Worst case – Line of business stuff breaks Best case – everything works Typical patch month for your networks What’s broken in the past for you?
What if you don’t patch? What’s the worst thing that happens? Well…..
Risks in a SBS network Server? Ports open? WORKSTATIONS Local administrator Download anything? Free stuff?
History of risks in SBSland Code Red Nimda Nail the server Today? Keep the system working Borrow the bandwidth
Greatest risks? Review your networks Desktops If you nail the server? If you nail a workstation? How expendable?
How to determine what/when? Read the bulletin What’s the riskiest? Read the criticality From remote? Mere surfing?
Win2k3 /XP sp2 Typical threats come from authenticated connections Lesser risks to these platforms A/V Spyware Safe surfing IE 7 coming out soon
Windows 2000 Risks from anonymous connections From remote Coded up exploits typically work
Window to patch Patch comes out at 10:00 a.m – 11:00 a.m Pacific Reverse engineer the patch to see what it’s fixing Determine issue Code vulnerability Typically within 20 minutes or so vulnerability is identified
Zero Days Vulnerability is out Used to exploit/to harm No patch But does that mean we are unprotected?
Window to patch Can it be automated? Can it be “wormable” What’s “Metasploit”?
Recent issues Focusing more on workstations Focusing more on applications Less on servers
When to patch? Do we have to do servers as soon as possible? Where’s our biggest risk of patching? What’s hurt in the past? Build an “ouch” database for your clients’ applications
When to patch? If we’ve mitigated already? Why do we need to patch now? Mitigate, patch later?
Now that we will patch Will it hurt? Check the caveat section Review the community Google on the KB number Review the Windows update newsgroup www.patchmanagement.org “Are you seeing?”
How/what to test? Microsoft performs patch testing Don’t test the “basics” Identify the clients’ key applications Identify a “patch canary”
Patch gets approved Tested on one workstation Done your research? NOW deploy
Deploy with? WSUS SBS 2003 r2 Shavlik Patchlink Other?
..but what about non MS? Adobe Flash Firefox Sun Java Even your antivirus
Tuesday’s patches …. To come…