MS defends MBSA

From: H C (keydet89@yahoo.com)
Date: 04/23/02


Date: Tue, 23 Apr 2002 07:08:32 -0700 (PDT)
From: H C <keydet89@yahoo.com>
To: focus-ms@securityfocus.com

Link to IDG article:

http://idg.net/ic_849313_4394_1-3921.html

The article author, Brian Fonseca, describes the MBSA
as "a more user friendly version of HFNetChk built
around a new GUI". However, the article says that
"users should be aware that differences occur in the
manner notes -- an advisory indicating no patch is
present -- and warnings are posted by each." That
came from Steve Lipner, director of security assurance
at Microsoft.

The article continues:
"Lipner said hotfixes could also lead to MBSA
misinterpretation." Aaaahhhh. Okay. The thing that
got me was the following statement from Lipner: "If a
hotfix was applied to plug a code exploit that did not
come directly from a Microsoft security bulletin, MBSA
will "guess" a system update has occurred".

That being the case...why would a patch be on an MS
system that did not come directly from an MS Security
Bulletin? Would this then provide a means by which a
malicious admin could fool the MBSA reports?

It sounds as if the author is also leaning toward the
usual journalistic FUD with this statement:
"Available for free download, MBSA is designed to
unearth Microsoft product holes". The tool doesn't
unearth holes...it reports patches/hotfixes, and a few
other things.

I, for one, would be interested in hearing anything
anyone has to offer about using this tool...the more
specific ("it rocks" or "it sux" is *not* specific)
the better.

__________________________________________________
Do You Yahoo!?
Yahoo! Games - play chess, backgammon, pool and more
http://games.yahoo.com/



Relevant Pages

  • RE: [Full-Disclosure] RE: Microsoft Baseline Security Analyzer not seeing KB887742 and KB886185
    ... I don't dispute that there are security concerns there however the tool ... The breadth of Windows is ... security implication that needed to be scanned by the MBSA it would take ... Subject: RE: Microsoft Baseline Security Analyzer ...
    (Full-Disclosure)
  • RE: Update List
    ... I suggest you use Microsoft Baseline Security Analyzer 2.0. ... MBSA to detect common security misconfigurations and missing security ...
    (microsoft.public.win2000.general)
  • RE: MBSA Error
    ... I believe the following message mentioned in the MBSA 2.0 FAQ is helpful: ... followed by "The catalog file is damaged or an invalid catalog"? ... Microsoft digital signature before being used. ... I get the folowing error when running a security scan for security ...
    (microsoft.public.win2000.general)
  • RE: MS defends MBSA
    ... Subject: MS defends MBSA ... Uninstall Client for Microsoft Networking and it will not run at all, ... come directly from a Microsoft security bulletin, ... malicious admin could fool the MBSA reports? ...
    (Focus-Microsoft)
  • Re: SMS 2003 Software Updates issues
    ... I don't *think* that there are any plans for the MBSA to support OE. ... As Microsoft moves towards the WUS Scanning Engine this ... You can still use normal SMS Software ... > be installed because the KB832894 hotfix has damaged something. ...
    (microsoft.public.sms.misc)