Folly of Patching - Revisited

From: Mark Deason (mdeason_at_SILVERSIDE.NET)
Date: 09/10/03

  • Next message: Thor Larholm: "Liu Die Yu findings verified, details"
    Date:         Wed, 10 Sep 2003 13:27:29 -0700
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    Russ,

    After testing the MS03-039 patch one of our Windows 2003 Standard boxes, I
    get the following MSDTC event (ID:4097) on reboot:

      MS DTC started with the following settings:

        Security Configuration (OFF = 0 and ON = 1):
            Network Administration of Transactions = 0,
            Network Clients = 0,
            Distributed Transactions using Native MSDTC Protocol = 0,
            Transaction Internet Protocol (TIP) = 0,
            XA Transactions = 1

    I can't find a shred of information on this new event through MS. You think
    that MS would have already defined the vectors (to help our administration
    brethren) to which programs and their respective settings affect this
    enumeration. There's going to be some scared administrators not knowing how
    to turn a "1" into a "0" on this event...

    Thanks,

    Mark Deason
    Director of IT
    Silverside Equipment Inc.

    ----
    Are You "Certifiable"? Summer's Hottest Certification Just Got HOTTER!
    With a growth rate exceeding 110%, the TICSA security practitioner
    certification is one of the hottest IT credentials available.  And now, for
    a limited time, you can save 33% off of the TICSA certification exam! To
    learn more about the TICSA certification, and to register as a TICSA
    candidate online, just go to
    http://www.trusecure.com/offer/s0100/
    ----
    

  • Next message: Thor Larholm: "Liu Die Yu findings verified, details"

    Relevant Pages

    • Re: Alert: Microsoft Security Bulletin - MS03-039
      ... The way that Microsoft patched the new RPC Part II vulnerability ... Summer's Hottest Certification Just Got HOTTER! ... To learn more about the TICSA certification, ...
      (NT-Bugtraq)
    • WHERE ARE NT4 OLD PASSWORDS STORED
      ... Sorry if this bores many of you (being an NT4 question), ... Summer's Hottest Certification Just Got HOTTER! ... you can save 33% off of the TICSA certification exam! ...
      (NT-Bugtraq)
    • Windows 2000 server issue
      ... accurately parse the lists of vulnerable machines produced by the scan ... of addresses directly on the script. ... Summer's Hottest Certification Just Got HOTTER! ... you can save 33% off of the TICSA certification ...
      (NT-Bugtraq)
    • Firewalls and DCOM
      ... Never underestimate the lengths to which your users will inadvertently go through to infect a network;)" ... Summer's Hottest Certification Just Got HOTTER! ... you can save 33% off of the TICSA certification exam! ...
      (NT-Bugtraq)
    • Re: Drivial Pursuit: Internet Explorer Browser & Your Files and Folders !
      ... The default Enhanced Security Configuration of IE ... access to files and folders on the local machine from the internet. ... With a growth rate exceeding 110%, the TICSA security practitioner certification is one of the hottest IT credentials available. ... And now, for a limited time, you can save 33% off of the TICSA certification exam! ...
      (NT-Bugtraq)