[Full-Disclosure] Patching networks redux

From: Schmehl, Paul L (pauls_at_utdallas.edu)
Date: 07/31/03

  • Next message: Alan Kloster: "RE: [Full-Disclosure] Patching networks redux"
    To: <full-disclosure@lists.netsys.com>
    Date: Wed, 30 Jul 2003 17:09:14 -0500
    
    

    For all those experts who have mastered patching your networks, please
    ignore this post.

    For the rest of you, testing has shown that some patch management tools
    are incorrectly reporting that MS03-026 is installed when it's not
    (notably Windows Update and Update Expert, among others.) The accuracy
    of the tool depends on how they check for the patch level. If they
    check the registry (like Windows Update and Update Expert do) they will
    *incorrectly* report that MS03-026 has been installed when if fact the
    files have not been updated. If they do MD5 checksums (like Hfnetchk or
    MBSA), they will correctly report the patch level.

    The Retina tool from eEye (and I would assume the IIS commandline tool
    as well) is correctly reporting what *is* patched and what is *not*
    patched, so you need to rely on those to give you accurate information.
    You could actually have users going to Windows Update and finding no
    patches available when in fact they are still vulnerable. You could
    also have users for whom you've pushed out the patch who have
    overwritten the files with older versions, yet your tools are reporting
    them as patched.

    Of course the experts never have these problems, but for the mere
    mortals, caveat emptor.

    Paul Schmehl (pauls@utdallas.edu)
    Adjunct Information Security Officer
    The University of Texas at Dallas
    AVIEN Founding Member
    http://www.utdallas.edu/~pauls/
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Alan Kloster: "RE: [Full-Disclosure] Patching networks redux"

    Relevant Pages

    • [Full-Disclosure] Patching networks redux (fwd)
      ... Windows Update and Update Expert, ... well) is correctly reporting what *is* patched and what is *not* patched, ... You could actually have users going to Windows Update and finding no patches ... Adjunct Information Security Officer ...
      (Full-Disclosure)
    • [Full-Disclosure] RE: Patching networks redux (fwd)
      ... Windows Update and Update Expert, ... well) is correctly reporting what *is* patched and what is *not* patched, ... actually have users going to Windows Update and finding no patches available ... Adjunct Information Security Officer ...
      (Full-Disclosure)
    • Re: KB 905915 and KB 910437 automatic update, USB failures, Delayed Write Error for external USB 2.0
      ... The second is a Windows Update to fix broken Windows Update. ... >those two checkboxes on and the two patches installed got me nowhere, ... >unchecked the two checkboxes in the XP firewall and tried copying, ... mileage irrespective of what the patch is supposed to do. ...
      (microsoft.public.windowsxp.general)
    • Re: Windows Update for XP
      ... I tried the windows update from the toolbar which was ... It showed me a patch from MAR 2002!!!! ... I have been judicious about keeping up on patches. ... > missing) and the WU in my toolbar think it is missing? ...
      (Focus-Microsoft)
    • Re: A patch is preventing the system from starting. - Which one?
      ... You are probably using a hardware driver that can't handle one of the patches. ... You can easily select one patch at a time to test, using system restore to go back on failure. ... You can also try to detect the problem using the error reporting available in the Windows Update app. ... update says I have xx patches to install. ...
      (microsoft.public.windows.vista.general)