[Full-Disclosure] SQL Server patch - why doesn't Windows update help?

From: Darren Reed (avalon@coombs.anu.edu.au)
Date: 01/30/03

  • Next message: auto68182@hushmail.com: "[Full-Disclosure] Re: iDEFENSE Security Advisory 01.28.03: SSH2 Clients Insecurely Store Passwords"
    From: Darren Reed <avalon@coombs.anu.edu.au>
    To: full-disclosure@lists.netsys.com
    Date: Fri, 31 Jan 2003 02:30:05 +1100 (Australia/ACT)
    

    I was just thinking to myself, hmmm, I have SQL Server something*
    installed on one of my Win2K boxes (service is turned off), I wonder
    if I have this patched as I do regular checkups with "Windows Update"...

    Well, either I haven't or I have and the "Windows Update" web site is
    lieing and "Add/Remove Programs" is in league with it.

    Strange. I do a scan with "Windows Update" and it still doesn't pick
    it up.

    It doesn't show up under "Office Update" either.

    What gives ?

    I ask myself have I been deceived into thinking that this "Windows Update"
    was not doing as I expected and is in fact doing far less ? I wonder how
    many other people do regular updates, using "Windows Update" and expect
    it to catch all of the patches required for their system(s) and don't
    give it much further thought ?

    The catch I now find myself in is if "Windows Update" doesn't know it
    should have installed the hotfix for SQL Server, how the hell am I
    (or anyone else for that matter) meant to now work out what has and
    hasn't been applied that is relevant ? How much trust can I now put
    in the "Windows Update" service to deliver me the correct patches that
    my system needs ? I wonder if I would have been one of the unsuspecting
    masses that got infiltrated if I had of been trusting "Windows Update"
    to keep my 'net exposed SQL servers up to date ?!

    Maybe this is a "known bug" or "caveat" with "Windows Update" but if
    it is, it'd sure be nice if it behaved as expected - read the "About
    Windows Update" sometime. I don't think I've got unreasonable
    expectations, based on how they advertise the service, that this should
    have been patched for me, already!

    I wonder if you'd have a case for suing Microsoft for damages if you got
    hit and used their update service on a regular basis, with it failing to
    install the patch, leading to you being crompromised for (if nothing else)
    false advertising of the "Windows Update" service capabilities...

    Darren
    * - it is one of the versions advertised as being vulnerable and no,
        there are no copyright problems with the installed products.

    p.s. This is the kind of email that now gets censored from bugtraq,
    I just hope it's appropriate for full-disclosure...
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html



    Relevant Pages

    • Re: IE patches killed internet connection
      ... If you have Microsoft Update (vs. Windows Update) installed, a shortcut to it will be found in the Start menu. ... I attempted to install 3 of those 4 patches, ... Later, Auto Update reoffered the security update, but I ...
      (microsoft.public.windows.inetexplorer.ie6.browser)
    • Re: Windows Update Error 0x8007F004 (Insufficient Privilege)
      ... it as the local administrator, the domain administrator, my own domain ... downloading one of the patches), and it doesn't come up with any permissions ... > When I tried to install Microsoft's latest patches (MS04-029 through ... > MS04-038) via Windows Update the process failed. ...
      (microsoft.public.win2000.windows_update)
    • Re: Solution to KB823353 & KB837009
      ... If you had KB823353 already installed, Windows Update then offered you and you successfully installed KB897715, and then Windows Update told you KB823353 still needed to be installed, I surmise (from other discussions ... My Windows Update History page details the following patches (in install ... Cumulative Security Update for Internet Explorer 6 Service ...
      (microsoft.public.windowsupdate)
    • Re: manual MS Update fails (gen. host proc. fail) but works automa
      ... I thought I'd post a quick update to my windows update issue with generic ... Updates were failing for various 'generic host process' errors with various ... The memory was added to the laptop when it had Vista to upgrade from 1 ... unresponsive when you try to install an update from Windows Update or ...
      (microsoft.public.windowsupdate)
    • Re: I am having connectivity problems
      ... Are you telling me that the ZA firewall AND the Windows Firewall was enabled when you installed SP3 via Windows Update? ... This Service "protects" Windows and disallows certain changes to be made (e.g., the changes install SP3 will make), so it should have been disabled prior to installing SP3. ... does the connection problem persist? ...
      (microsoft.public.windows.inetexplorer.ie6.browser)