Skip to content
Silicon Shecky

Silicon Shecky

Infosec Practitioner

  • Security is Reactionary, No Matter What Security
  • New Year, New Post, from the start General
  • First Defcon – The results Reviews
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General

Random Thoughts On Security

Posted on November 13, 2009 By Michael Kavka No Comments on Random Thoughts On Security

Who thinks its funny that the day after Patch Tuesday, Windows 7 and Server 2008 R2 get hit with a zero day exploit that causes them to crash? Its one of those things that the timing seems suspect on. Obviously they knew about the exploit before hand, and had to confirm it before they would allow the world to know about it.

Well if you think about it, waiting till Wednesday, Microsoft basically about itself a full month to get the patch out there. Its a stall tactic. Now considering the flaw does not allow access to data, allow rooting of the OS, or anything worse than a crash, it isn’t as bad as it could be.

The whole thing that people don’t understand about an exploit like this, and say Malware that gets on your system is where the real hole is. The ultimate hole in any OS is the end user. They don’t want to hear that going to their favorite adult site is what is causing them to get infected with malicious software. They patch their system, they only go to sites they trust.

Now I do agree that holes in the OS such as the recently patched kernel flaw can cause a ton of problems. Still once that gets patched, you have less of a chance of a drive by infection. When your users go to unsavory sites, sites that do a ton of redirecting, or just sites that really are not maintained, they cause a much bigger problem.

Then there is the problem of pirated software. The funny thing about pirated software is it usually isn’t the software itself that has the malware in it, its the crack that does. Whether it is a key generator or a small file you change out, that little piece of code is what opens you up. Mind you I’m not saying that file sharing is bad. I’m not bashing bittorrent at all. In fact Bittorrent is very useful for getting legitimate Open Source software, such as Linux ISOs.

I’m also well aware of how expensive software is. The amount of profit Microsoft makes off of Office is insane, and it wouldn’t be pirated nearly as much of the price came down to a more manageable level. The thing is that there is reputable legal free software that can do most of what the expensive software does, without cracks or malicious software hiding inside of a crack. Open Office, Gimp, Linux, VLC, Audacity, and many more Open Source projects are really coming into their own.

The bottom line is no matter what we do, unless we are willing to take the time to properly educate our end users, I don’t care how much you harden your system, something will happen to it. Best to be prepared, and have a slew of tools ready. Oh, and some of the best of those tools, are Open Source and free.

Computers, Rants, Security, Software

Post navigation

Previous Post: Shecky Tweets for 2009-11-12
Next Post: Shecky Tweets for 2009-11-13

Related Posts

  • Security is Reactionary, No Matter What Security
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General

More Related Articles

Security is Reactionary, No Matter What Security
Defender, KQL and Lockbit Microsoft
Do well, not be “popular” Ramblings
Defense Layers: A Case Study Microsoft
Device vs. User Microsoft
Ransomware, Are You Ready? General

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

  • About
  • Links
    • Burbsec
    • BSides312
    • Infosec Exchange Mastodon
    • BSidesRoc
    • Hacks4Pancakes Blog
    • Krebs On Security
    • Bleeping Computer
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Archives
  • Social Media

Browse by tags

2008 Active Directory Android Antivirus Apple Beta CarbonBlack Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches SBS SBS 2008 Security Server SMB Software Support Surface TechEd Thotcon Tweets Ubuntu Verizon Virus Vista Windows Windows 7 Windows 8 XP
  • About
  • Links
    • Burbsec
    • BSides312
    • Infosec Exchange Mastodon
    • BSidesRoc
    • Hacks4Pancakes Blog
    • Krebs On Security
    • Bleeping Computer
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Archives
  • Social Media

Connect

  • Bluesky
  • LinkedIn
  • Mastodon
  • RSS
  • Twitter

RSS feed: iFin Intel Feed iFin Intel Feed

  • Google Doc Sidebar Sends Mac and Windows Users Down Different Paths to Malware September 15, 2026
  • Revolut confirms customer data breach through fake government requests September 12, 2026 Jagmeet Singh
  • Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent September 12, 2026 Bill Toulas
  • Researchers say OpenAI agents were behind May hacking campaign targeting RubyGems September 12, 2026 djohnson
  • Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal September 11, 2026 Tim Starks
  • Hackers abused Claude to extract secrets from 1.8M Android apps September 11, 2026 Bill Toulas
  • Florida says motor vehicle data breach tied to credentials stolen from officer’s personal device September 11, 2026
  • CVE-2026-89332 - Kiro IDE Sensitive Workspace Data Exfiltration via Agent-Written Workspace Configuration September 11, 2026 aws@amazon.com
  • Florida confirms DMV database breached via stolen police account September 11, 2026 Lawrence Abrams
  • GitLab’s critical flaw is already drawing internet-wide probes September 11, 2026 Greg Otto
  • Microsoft sees some new wrinkles in invoice-scam emails September 11, 2026
  • More JFrog Artifactory bugs under attack, and all 3 have patches September 11, 2026

Browse by tags

2008 Active Directory Android Antivirus Apple Beta CarbonBlack Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches SBS SBS 2008 Security Server SMB Software Support Surface TechEd Thotcon Tweets Ubuntu Verizon Virus Vista Windows Windows 7 Windows 8 XP

RSS feed: iFin Intel Feed iFin Intel Feed

  • Google Doc Sidebar Sends Mac and Windows Users Down Different Paths to Malware September 15, 2026
  • Revolut confirms customer data breach through fake government requests September 12, 2026 Jagmeet Singh
  • Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent September 12, 2026 Bill Toulas
  • Researchers say OpenAI agents were behind May hacking campaign targeting RubyGems September 12, 2026 djohnson
  • Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal September 11, 2026 Tim Starks
  • Hackers abused Claude to extract secrets from 1.8M Android apps September 11, 2026 Bill Toulas
  • Florida says motor vehicle data breach tied to credentials stolen from officer’s personal device September 11, 2026
  • CVE-2026-89332 - Kiro IDE Sensitive Workspace Data Exfiltration via Agent-Written Workspace Configuration September 11, 2026 aws@amazon.com
  • Florida confirms DMV database breached via stolen police account September 11, 2026 Lawrence Abrams
  • GitLab’s critical flaw is already drawing internet-wide probes September 11, 2026 Greg Otto
  • Microsoft sees some new wrinkles in invoice-scam emails September 11, 2026
  • More JFrog Artifactory bugs under attack, and all 3 have patches September 11, 2026
  • Security is Reactionary, No Matter What Security
  • New Year, New Post, from the start General
  • First Defcon – The results Reviews
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General

Social Media

  • Bluesky
  • Mastodon
  • Twitter

Copyright © 2026 Silicon Shecky.