Re: Hfnetchk scans every file

From: Tod Beardsley (todb@planb-security.net)
Date: 05/23/02


Date: Wed, 22 May 2002 17:06:20 -0700
From: Tod Beardsley <todb@planb-security.net>
To: focus-ms@securityfocus.com

Michael Green (Monday, May 20, 2002, 12:23 PM) appeared to be
quoting Darren W. MacDonald when he wrote:

> A : Hfnetchk examines several values before it reports on the status of a
> patch.

Just to pipe in with a personal preference -- I almost always skip the
registry check with the "-z" switch. If the files are the right
version, the right age, and have the right checksum, I consider the
system patched -- after all, exploit code run against my machines
isn't going to bother checking the registry for patch presence, so why
should I?

To me, the registry check seems pretty unnecessary.

BTW, it would appear that the MS Baseline Security Analyzer lacks the
"write your own XML reference file" functionality of HFNetCheck.
Anyone have an inside scoop as to why? I asked Microsoft about it, and
was advised to use the (unreleased) MS Windows Update Corporate
Edition instead. For some reason.

-- 
Tod Beardsley (GCIA, MCSE)
"It's okay to yell fire in a crowded theater if
the theater is actually on fire."



Relevant Pages

  • Re: Help for Low Vision
    ... You /may/ need a patch, ... Then go to the third link and download the ZIP file that will fix the registry. ... If it says the patch is already on your machine, then just go straight to the third link. ... 'usable/active' OE New Message form available for her in Desktop ...
    (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
  • Re: "The update cannot be applied."
    ... Verify that the patch package exists and that you can access it ... Do I have to reboot after the registry changes? ... The four folders I moved off of Windows include all of the ... Select "Detect and Repair errors in my Office installation". ...
    (microsoft.public.officeupdate)
  • Re: protecting against Conficker
    ... I wouldn't change GPOs or registry permissions, ... If you have an uninfected machine with the patch ...
    (microsoft.public.windows.server.sbs)
  • Re: Too many Problems
    ... I successfully did that patch, but the registry thing scares me when I ... I lost one operating system once already a few years ... In your case, compacting manually will not remove the prompt to compact, ...
    (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
  • Re: Too many Problems
    ... I successfully did that patch, but the registry thing scares me when I read ... I lost one operating system once already a few years ... Manually compacting will now reset the registry counter to Zero in WinXP/SP2 ...
    (microsoft.public.windows.inetexplorer.ie6_outlookexpress)