There’s been a TON of talk about the latest vulnerability affecting Windows. Message boards have been lighting up with talk about it, vendors are offering webcasts, it’s the talk of the security town. In fact, it’s so bad that Microsoft is releasing an “out-of-band” patch to fix the problem.
So, is it worth the trouble to patch – especially on seemingly critical servers that you can’t afford a patch to take down? I think so…Why? Because exploit code is out there, right now, today. Sure, there are the CANVAS and CORE IMPACT commercial pen testing tools, but malicious users on your network don’t need to spend money on them. Oh no, no…the free and easy Metasploit tool has the MS08-067 exploit built in as well. All it takes is a simple download, plugging in a couple of variables, and boom – any given system on your network is at the attacker’s disposal. Internal breach anyone…?
“A business associate referred our company to Principle Logic when we were seeking a resource to perform vulnerability /penetration testing for our external and internal networks. We found Kevin Beaver to be professional, well informed, and easy to work with. His testing did not disrupt our networks, and his progress updates were timely.
His final report was very thorough and included security recommendations for our network environment. The executive leadership was so impressed with Kevin’s security expertise, they have extended their agreement to continue to perform periodic testing. We highly recommend Kevin Beaver and Principle Logic as a resource for network security testing.”