RE: IE headers w patch level

From: Omar Koudsi (omark@jeeran.com)
Date: 12/24/01


From: "Omar Koudsi" <omark@jeeran.com>
To: "'Daniel Bowers (Satus)'" <daniel.bowers@satus.com>, <focus-ms@securityfocus.com>
Date: Mon, 24 Dec 2001 17:09:33 +0200

I posted about this a while back with a surprising 0 response. I don't
know what MS's aim behind this, but letting people know the level of
patching of your browser or if you are patched or not, is not the most
bright idea that comes to mind.

-----------
Omar Koudsi
IT Architect
Network Security Center
Special Systems Company
http://security.sscjo.com
omark@sscjo.com
Tel: (9626) 5664221
Fax: (9626) 5681557

-----Original Message-----
From: Daniel Bowers (Satus) [mailto:daniel.bowers@satus.com]
Sent: Sunday, December 23, 2001 8:08 PM
To: focus-ms@securityfocus.com
Subject: IE headers w patch level

After MS01-058 (13 Dec "cumulative patch"), IE 5.5/6 started including
the patch-level in the http request header:

Mozilla/4.0+(compatible;+MSIE+6.0;+Windows+98;+Q312461)
Mozilla/4.0+(compatible;+MSIE+5.5;+Windows+98;+AltaVista+1.01.01;+T31246
1)
Mozilla/4.0+(compatible;+MSIE+6.0;+Windows+98;+Win+9x+4.90;+T312461;+Q31
2461
)

Does anyone know if this will be done with future patches, and what the
purpose might be?

Daniel Bowers
Satus Tech LLC
daniel.bowers@satus.com