The #1 source of frustration and anger with ExchangeDefender is directly related to the way it handles executable content – with a shotgun. Through the years, we’ve seen executable email content damage so many computers and networks that we outright ban that content at the gate, nothing executable comes in or goes out. We go a few steps further too – You can’t zip it, you can’t rename it, you can’t rename it and zip it. We eval the file not just for the filename pattern but for the filetype MIME match as well. Then we check if it has multiple extensions trying to hide the .exe at the end. Then we check the length of the filename, then… Well, let’s just say we’re thorough.
Yet every Monday morning there are the unfortunate few customers that will have an urgent, critical business need to receive an executable file. The reason? You’ve guessed it:
My vendor distributes the software updates through email.
While ordinary ExchangeDefender users have a right and even an excuse to be ignorant of this, software vendors do not. Let me explain the ginormity (new word of the day) of this stupidity in somewhat plainer terms. Your software vendor is trying to behave like 98.3% of all worms and viruses out there. And after years and years of “Here is your Microsoft update, attached.” exploits there are still people under the rock about this. Here is how we like to translate your business need to patch applications that only receive updates through email:
My pharmaceutical distributor only sells this drug in a dark alley between 2 and 6 am.
My butcher will only sell that piece of meat after hours, and always locks the door after I come in.
My electronics dealer has the cheapest and newest stuff around, but only seems to have one piece of each model. He also only takes cash payments and asks me if I’ve seen any cops around on my way in.
Please, end this stupidity. There is no circumstance, whatsoever, under which we will ever allow executable content that we cannot validate through our network. Even if you’ve spent last 260 years in network security, have written books on it, have a pending Nobel prize in World Peace category for helping save starving African villages through your ability to keep orphanages running with software that only distributes patches via executable email attachments… even then we will block your ability to receive refuse to hand you a loaded gun to play Russian roulette with.
In closing, if this software vendor absolutely cannot deliver their software through anything but email…. Go get a gmail, yahoo, hotmail, etc account and have your patches sent there. Then download those directly onto the box running the said software, but ask yourself this:
If this software vendor has put so little thought into the distribution of their patch management and cannot even figure out how to put up an authenticated web page for their file distribution, which is a job of a jr system administrator…. what other holes have they left in their application if they can’t grasp these simple concepts?
The preceeding Monday morning rant is brought to you curtesy of Own Web Now Corp support.
Both comments and pings are currently closed.
1 Comment
|
|
|
Whats on Vlad's Mind?
|
|
|
|
|
Sponsors: This blog is made possible by
Own Web Now Corp and ExchangeDefender.
If you like this blog and are in the need of products we offer I hope you give us some
consideration.
|
|
|
|
|
|
Get The Newsletter
|
Looking for a more focused, exclusive insight into the world of SMB tech & business? Sign up for my newsletter:
Click here to sign up
|
|
|
|
|
Vladfire Vlog
|
Vladfire is my video blog showcasing successful people and technology in small to medium business.
Below are a few recent episodes, check out the archive for all other films.
|

See more episodes...
|
|
|
SBS Show Podcast
|
SBS Show is a free weekly podcast (Internet for recorded radio show) focusing on small business and technology. More at sbsshow.com but check out our latest episode:
SBS Show #26
Erick Simpson
Managed Services Part 2

Listen to older shows..
|
|
|
|
| |
|
|
Categories
|
|
Archives
|
|
About
|
| Apple, Awesome, Beta, Blogroll, Boss, Cloud, Deals, E12, Events, Exchange, ExchangeDefender, Friends, Gadgets, Gators, Gaypile, Google, GTD, iPhone, IT Business, IT Culture, Legal, Linux, Microsoft, Misc, Mobility, Open Source, OS, OwnWebNow, Pimpin, Podcast, Programming, Rant, SBS Show, Security, Shockey Monkey, SMB, System Admin, Thieving Weasel, Uncategorized, Vista, Vladcast, Vladfire, Vladville, Web 2.0, Windows Home Server, WordPress, Work Ethic, Wrong |
 |
February 2012,
January 2012,
December 2011,
November 2011,
October 2011,
September 2011,
August 2011,
July 2011,
June 2011,
May 2011,
April 2011,
March 2011,
February 2011,
January 2011,
December 2010,
November 2010,
October 2010,
September 2010,
August 2010,
July 2010,
June 2010,
May 2010,
April 2010,
March 2010,
February 2010,
January 2010,
December 2009,
November 2009,
October 2009,
September 2009,
August 2009,
July 2009,
June 2009,
May 2009,
April 2009,
March 2009,
February 2009,
January 2009,
December 2008,
November 2008,
October 2008,
September 2008,
August 2008,
July 2008,
June 2008,
May 2008,
April 2008,
March 2008,
February 2008,
January 2008,
December 2007,
November 2007,
October 2007,
September 2007,
August 2007,
July 2007,
June 2007,
May 2007,
April 2007,
March 2007,
February 2007,
January 2007,
December 2006,
November 2006,
October 2006,
September 2006,
August 2006,
July 2006,
June 2006,
May 2006,
April 2006,
March 2006,
February 2006,
January 2006,
December 2005,
November 2005,
October 2005,
September 2005,
August 2005,
July 2005,
|
 |
Vlad says:
Thanks for checking out my blog. You've officially reached the end of the Internet so take in what you've read and don't look at it as gospel but an invitation to start thinking for yourself.
|
|
|
|
| |
Copyright © 2005-2010 Vlad Media, Inc. All Rights Reserved.
Content is provided AS-IS without warranty of any kind.
Syndicate this blog: 
|
|