RE: New version of HFNetChk from Microsoft.

From: Daryl Maunder (dmaunder@midnightoil.com.au)
Date: 10/26/01


Subject: RE: New version of HFNetChk from Microsoft.
Date: Fri, 26 Oct 2001 08:27:03 +1000
Message-ID: <7400546A8E39414EB4AA7A8193047E84038410@MOC2.midnightoil.local>
From: "Daryl Maunder" <dmaunder@midnightoil.com.au>
To: <focus-ms@securityfocus.com>

FYI, it doesnt yet check Exchange, nor ISA, which I would have thought
was at least as important as SQL

The other dumb thing is that I run HFNETCHK on a weekly basis on all my
clients servers, and email the output to myself. When you run the old
version now, it detects that a newer version is available and output a
messages saying so. But this message not written to stdout, so it doesnt
get redirected with the standard >xx.txt command, so isnt inluded in the
email.

-----Original Message-----
From: Mark Medici [mailto:mark@dbma.com]
Sent: Thursday, 25 October 2001 1:18 PM
To: focus-ms@securityfocus.com
Subject: New version of HFNetChk from Microsoft.

Microsoft released a new version of HFNetChk today.
 
A couple of errors were fixed with the utility itself, and the
readme.txt file was updated to include instructions on using HFNetChk if
you cannot or do not want to update to at least MS Internet Explorer 5.0
(these instructions might have been there before, but I don't recall
seeing them).
 
If you are not familiar with HFNetChk, it is an excellent tool for
determining whether your WinNT or Win2k systems (workstations and
servers) have the recommended hotfixes installed. You run it from a
Command Prompt and HFNetChk downloads the current patch list from
Microsoft then checks to see if the system is up-to-date. (The patch
list, in XML format, is saved to the default directory, so you can also
test systems that aren't on the network.) Not only is the operating
system itself checked, but HFNetChk also knows how to check Exchange,
SQL and IIS. You can check systems across the network and can specify
multiple systems to be checked with one command. The output can be
redirected to file for detailed review and historic documentation
purposes.

Using HFNetChk alone won't completely secure your system, but it does
make the process of checking for missing patches more manageable.
 
See http://www.microsoft.com/Downloads/Release.asp?ReleaseID=31154 and
the links therein for more info.

______________________________________________________________________
Mark A. Medici | DBM Associates -=]#[=- Computer Sales and Services
Sr. Systems Eng.| One Salem Square #104W, Whitehouse Station, NJ 08889
mark@dbma.com | Phone: 908-534-1665 Fax: 908-534-1244 www.dbma.com



Relevant Pages

  • Re: MS patch-scanner for Win-NT, 2K, IIS, SQL
    ... I must say I am, overall, impressed with Hfnetchk. ... thing that Microsoft should have had out years ago. ... haven't been applied but won't tell me if I'm missing service packs. ... For instance, on the NT4 machine I'm testing this on, I have SQL Server ...
    (Focus-Microsoft)
  • HFNetChk 3.3 now available
    ... HFNetChk version 3.3 is now available. ... Microsoft Download Center page: ... SQL Server 7.0 and SQL Server 2000. ... downloaded mssecure.cab file has been signed by Microsoft. ...
    (NT-Bugtraq)
  • A response to Bruce Schneier on MS patch management and Sapphire
    ... Slammer worm that struck Microsoft SQL Server in January. ... HFNetChk both failed to detect the presence of the well-known vulnerability ... MBSA and HFNetChk are Microsoft's official patch status verification ...
    (Bugtraq)
  • [Full-Disclosure] A response to Bruce Schneier on MS patch management and Sapphire
    ... Slammer worm that struck Microsoft SQL Server in January. ... HFNetChk both failed to detect the presence of the well-known vulnerability ... MBSA and HFNetChk are Microsoft's official patch status verification ...
    (Full-Disclosure)
  • HFNetChk 3.3 now available
    ... HFNetChk version 3.3 is now available. ... Microsoft Download Center page: ... SQL Server 7.0 and SQL Server 2000. ... downloaded mssecure.cab file has been signed by Microsoft. ...
    (Focus-Microsoft)