Anyone else having serious repercussions from applying W2k sp4 se curity rollup patch?

From: gerald (geraldf_at_westernsaw.com)
Date: 06/30/05

  • Next message: Matthew Murphy: "Microsoft Windows NTFS Information Disclosure"
    To: bugtraq@securityfocus.com
    Date: Thu, 30 Jun 2005 11:04:07 -0700
    
    

    Hi,all;

    Has anyone else had serious trouble after applying Security rollup patch for
    w2k server sp4?

    Immediately after applying patch, DNS zones disappeared and all file
    replication between DCs was terminated. Enforced replication was prevented
    with "Access denied" message. DCs just stopped talking to each other.
    Appears to be a Kerberos problem. I guess this puts a new definition to the
    term "ROLLUP".

    ONLY solution thus far is to do an FSMO role seize off all DCs other than
    one DC running DNS (very difficult because of "Access denied " status).
    Then each stripped DC, which will only respond to the Dcpromo /forced, is
    demoted to standalone status (Dcpromo for demotion will not work). Have to
    use "ADSI edit" and "Metadata cleanup" to purge Active Directory of
    references to former DCs.

    Stripped all former DCs and rebuilt, then rejoined the domain and ran
    Dcpromo on all.

    MSFT assisted in the recovery. Noone seems to know what happened, but we
    can damn close to a total network loss due to one patch. They tried
    regenerating Kerberos tickets and reestablishing the secure channel...no
    luck..."Access denied" was the only response.

    The only thing I saw out of the ordinary was after applying the patch and
    rebooting, about 5 minutes later the DC which was the DNS server
    spontaneously rebooted. No core dump, just a mystery reboot. When it can
    back up, the Network was hosed.

    I have avoided all prior snafus with MSFT service packs and patches since
    the days of NT3.5 by hanging back a little and watching for warnings on
    Bugtrac. Got nailed good this time. So this is my turn to sound the
    warning and give payback to all who have kept me out of trouble in the past
    by taking the time in the midst of a crisis to post.

    Lesson learned: when dealing with MSFT, there is no such thing as a trivial
    service pack or patch.

    I guess that's why they pay us the big bucks...to recover from what hackers,
    users, power surges, or vendors (and even sometimes ourselves ;--) do to
    our networks. Ya gotta love this job!

    gerald


  • Next message: Matthew Murphy: "Microsoft Windows NTFS Information Disclosure"

    Relevant Pages

    • Re: problems with KB951746
      ... Then, if you are CONFIDENT that you are okay there and the speed issue remains, reconfigure SBS and point it to another DNS server that is known to be patched and working. ... Wien the server-side DNS-vulnerability patch is installed, all my SBS2K3 systems are exhibiting the same problem: extremely show internet access when the system is under load, meaning when three or more clients are trying to access the internet at once. ... My indecision stems from the fact that no symptoms show if there is no load, so if I call CSS after hours I can't show them any symptoms, and I don't want to load the patch during a work day because access is so slow that client work slows to a virtual standstill, the remote branches connections to Exchange server stop responding, and local clients can't do any work that involves the internet. ...
      (microsoft.public.windows.server.sbs)
    • Re: Attn: Susan: Inet browsing problems w/DNS patch 951746
      ... Did you reboot after entering the exclusions, then install the patch ... that your DNS forwarders are still correct. ...
      (microsoft.public.windows.server.sbs)
    • djbdns misformats some long response packets; patch and example attack
      ... The DNS packet format allows names to be compressed by replacing the ... (At the bottom of this email, there is a patch for this.) ... rejected these records as poison, but it's possible other DNS caches ...
      (Bugtraq)
    • Re: DNS / Exchange2003 Problem driving me crazy
      ... Yes we did that patch, but that is when the problem started - could that be ... See if your windows servers and clients have the July DNS ...
      (microsoft.public.exchange.admin)
    • Re: Slow replication of changes
      ... Are the DCs already physically ... always about "controlling replication across a WAN". ... Check DNS for AD ... Herb Martin, MCSE, MVP ...
      (microsoft.public.win2000.active_directory)