RE: [Full-Disclosure] Patching networks redux

From: Alan Kloster (akloster_at_spp.org)
Date: 07/31/03

  • Next message: debian-security-announce_at_lists.debian.org: "[Full-Disclosure] [SECURITY] [DSA-355-1] New gallery packages fix cross-site scripting"
    To: <full-disclosure@lists.netsys.com>
    Date: Wed, 30 Jul 2003 17:58:16 -0500
    
    

    Paul Schmehl wrote:
    >testing has shown that some patch management tools
    >are incorrectly reporting that MS03-026 is installed when it's not
    >(notably Windows Update and Update Expert, among others.) The accuracy
    >of the tool depends on how they check for the patch level. If they
    >check the registry (like Windows Update and Update Expert do) they will
    >*incorrectly* report that MS03-026 has been installed when if fact the
    >files have not been updated. If they do MD5 checksums (like Hfnetchk or
    >MBSA), they will correctly report the patch level.

    Reading the notice from Microsoft MS03-026 suggests that nothing below Win2k SP3 or NT SP6a can be patched effectively. They kind of hid this in one of the extra pull downs on the website. We are finding that the patch can be applied to systems that don't meet this criteria, but doesn't take, and the Eeye scanner still shows them vulnerable. Just a heads up for people who haven't applied the service packs, but think they are safe. Windows update also doesn't show the patch as available for machines at the wrong SP level.

    Props to Eeye for helping us all with the scanner tool.

    Alan Kloster
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: debian-security-announce_at_lists.debian.org: "[Full-Disclosure] [SECURITY] [DSA-355-1] New gallery packages fix cross-site scripting"

    Relevant Pages

    • Re: Bug in IE critical patch?
      ... The patch is important for your security, ... > I may have left Norton running while installing the patch. ... >> Did you "download" the patch via Windows Update? ...
      (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
    • Re: 891711/MS05-002 Updated (fixed) for Win9x
      ... I am still confused as to whether it is better to | just update and overwrite the old patch through Windows Update or is it much | safer and or better to remove the original patch and update to the new one | through Windows Update. ... |> current form, is a more or less a permanent solution, with the update |> still running as a background process? ... security |> update ...
      (microsoft.public.security)
    • [Full-Disclosure] OT but related.
      ... Windows Update doesn't check files, ... "For the rest of you, testing has shown that some patch management ... Update Expert will incorrectly assert ... they will correctly report the patch level. ...
      (Full-Disclosure)
    • RE: Print Current Record Only
      ... >> Microsoft Access Support ... >> to visit Windows Update at ... >> the patch. ...
      (microsoft.public.access.gettingstarted)
    • RE: Windows XP with SP2 installed, no access to updates.
      ... Thank you Jeff for the trouble that you have taken. ... > which a patch was applied. ... > caution (download even ones you're not sure are SP2-only), ... Now go to microsoft.com and the Windows Update site, ...
      (microsoft.public.windowsupdate)