Re: Hotfixes overwritten?

From: Tod Beardsley (todb@planb-security.net)
Date: 05/20/02


Date: Mon, 20 May 2002 09:21:04 -0700
From: Tod Beardsley <todb@planb-security.net>
To: focus-ms@securityfocus.com

Greene, Michael (Friday, May 17, 2002, 9:00 AM) wrote:

> Does anyone else find [hotfix overwrites] disturbing? Is there a
> solution?

Unfortunately, the solution is to reapply hotfixes after installing
anything that touches hotfixed files. You can check your machine with
HFNetCheck or What Changed? or somesuch, and base your hotfix reinstall
decision on those results, but today, there's no easy, automated way
to make sure hotfixes "stick" after a component install.

You could set up some security auditing to drop events in the log,
based on file writes, then run some kind of log scraper (like NetIQ)
to watch for changes. But you'd have to tag each file you cared about
on each machine (scriptable, but the initial labor would be
irritating). And, your events would end up potentially buried in your
security log, and not someplace sensible like your system log.

I wonder if you could mess with Windows File Protection to get the
results you're after? I haven't fooled around with WFP too much.

-- 
Tod Beardsley (GCIA, MCSE)
"It's okay to yell fire in a crowded theater if
the theater is actually on fire."



Relevant Pages

  • Reinstall _ Fresh Install
    ... Having problems installing XP ... Installed Microsoft Hotfixes ... Symantec Corporation - Norton AntiVirus 1 ... Microsoft Corporation - Internet Explorer Version 6.00.2800.1106 * ...
    (microsoft.public.windowsxp.help_and_support)
  • RE: Help with XP Hotfixes and Patches
    ... hotfixes require a certain level of XP underneath (same as Win2K hotfixes, ... Help with XP Hotfixes and Patches ... > After installing I immediately went to Windows Update to try ...
    (Focus-Microsoft)
  • Re: StartDocPrinter call not issued
    ... If you have 14 hotfixes listed in Control Panel, Add or Remove Programs, you ... almost certainly do not have Service Pack 2 installed. ... The hotfixes have SP2 in their name because the problems those hotfixes ... > ask before installing and it didn't ...
    (microsoft.public.windowsxp.print_fax)
  • Re: Creating a bootable, slipstreamed Win2000 CD with all current
    ... these updates aren't hotfixes I realize now... ... Is it related to installing over the network?? ... >> burner at present as mine is broken. ...
    (microsoft.public.win2000.general)
  • Tape drive not responding after SP4
    ... After installing SP4 and hotfixes the exabyte 8700 (FW ... 8700 tape drives. ...
    (microsoft.public.win2000.hardware)