Handler's Diary
WMF FAQ (NEW) — Last Updated: 2006-01-02 03:18:03 UTC by Johannes Ullrich (Version: 2(click to highlight changes)) — [a few users offered translations of this FAQ into various languages. Obviously, we can not check the translation for accuracy, so use at your own risk.
Context & Ripple Effects
The WMF zero-day is entering its second week: since more than 50 exploit variants surfaced in the wild on December 29, defenders have had no vendor patch, only workarounds — including the contested DEP mitigation covered in the DEP controversy. Into that vacuum, Johannes Ullrich has published version 2 of the Handler's Diary WMF FAQ, consolidating what the incident-response community knows into one living document.
Two details make this update notable rather than routine. First, it formalizes SANS as the de facto reference point for administrators managing exposure without official guidance — the same risk-calculus territory Jesper explores in his argument for conscientious risk management around WMF. Second, readers are producing unofficial translations of the FAQ into multiple languages, which SANS explicitly disclaims as unverifiable — global demand outpacing the channel's ability to certify accuracy.
First-order effects
- Administrators deciding whether to apply interim mitigations now have a single, versioned reference (updated by Ullrich on January 2), reducing reliance on fragmented mailing-list threads while no patch exists.
- Non-English-speaking operators gain access through fan translations that carry an explicit accuracy disclaimer, trading reach for the risk of mistranslated technical instructions.
Second-order effects
- With Microsoft yet to issue its own detailed advisory, community outlets like the Handler's Diary absorb the advisory function, raising the bar for what the vendor must publish when it does respond.
- The translation phenomenon pushes other responders to consider multilingual distribution of their own guidance or cede parts of the audience to unverified copies.
Third-order effects
- If the pattern holds, major zero-day response becomes a race of continuously versioned community documents alongside official channels, with accuracy assurance — not raw information — emerging as the scarce resource.
The trend: Incident response is shifting from one-shot vendor bulletins toward living, community-maintained FAQs that set the reference narrative during unpatched zero-day windows.