[Discuss] OT: Microsoft Secure Channel (Schannel) Vulnerability

2014-11-14 Thread Stephen Ronan
November 14: "This flaw allows a remote attacker to execute arbitrary code and fully compromise vulnerable systems" https://www.us-cert.gov/ncas/alerts/TA14-318A This is what my ISP has to say about it. = "Extremely serious Windows security vulnerability

Re: [Discuss] OT: Microsoft Secure Channel (Schannel) Vulnerability

2014-11-14 Thread Bill Ricker
This was discussed pretty much all week on SANS Internet Storm Center "Daily Stormcast" podcast. Handler Diaries - https://isc.sans.edu/diary/How+bad+is+the+SCHANNEL+vulnerability+%28CVE-2014-6321%29+patched+in+MS14-066%3F/18947 & https://isc.sans.edu/diary/SChannel+Update+and+Experimental+Vuln

Re: [Discuss] OT: Microsoft Secure Channel (Schannel) Vulnerability

2014-11-14 Thread Stephen Ronan
Thanks, for less technically adept folks like myself, what is involved in successfully patching these machines? Is it just a matter of going straight to Windows Update when they're turned on? - Stephen On Sat, 15 Nov 2014, Bill Ricker wrote: This was discussed pretty much all week on SANS

Re: [Discuss] OT: Microsoft Secure Channel (Schannel) Vulnerability

2014-11-14 Thread Bill Ricker
On Sat, Nov 15, 2014 at 12:49 AM, Stephen Ronan wrote: > Thanks, for less technically adept folks like myself, what is involved in > successfully patching these machines? Is it just a matter of going straight > to Windows Update when they're turned on? - Stephen As far as i know [AFAIK], yes. [

Re: [Discuss] OT: Microsoft Secure Channel (Schannel) Vulnerability

2014-11-14 Thread Ryan Pugatch
On Sat, Nov 15, 2014, at 12:32 AM, Stephen Ronan wrote: > > November 14: > "This flaw allows a remote attacker to execute arbitrary code and > fully compromise vulnerable systems" > https://www.us-cert.gov/ncas/alerts/TA14-318A > Interesting how the US-CERT alert links to a reddit thread as a re

Re: [Discuss] OT: Microsoft Secure Channel (Schannel) Vulnerability

2014-11-15 Thread Jerry Feldman
I received notices yesterday and updated all the Windows systems I am responsible for. On 11/15/2014 12:59 AM, Bill Ricker wrote: > On Sat, Nov 15, 2014 at 12:49 AM, Stephen Ronan wrote: >> Thanks, for less technically adept folks like myself, what is involved in >> successfully patching these ma