Re: Patch testing

From: Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP] (sbradcpa_at_pacbell.net)
Date: 08/21/03

  • Next message: Kurt Seifried: "Re: Patch testing"
    Date: Thu, 21 Aug 2003 11:20:04 -0700
    To: Todd Schubert <todd@toddschubert.com>
    
    

    In my SMB arena we post into community newsgroups and ask others what their results have been and get a "community"
    view of a patch. There is usually someone who has deployed it sooner than the rest and is willing to report their
    results.

    Susan Bradley

    http://www.microsoft.com/communities/default.mspx

    Find a usergroup, find a "community", find a group to share information with.

    Todd Schubert wrote:

    > Along the same lines...if you do have the resources to deploy some test
    > servers but not to recreate every type of server in the enterprise (dc,
    > web, exchange, certificate authority, db...) how should you go about
    > setting up the test servers? Is there a specific area that should be
    > focused on? Also how important is it to have the test servers running
    > the same types of hardware as the production environment?
    >
    > Brei, Matt wrote:
    >
    > >Greetings,
    > >
    > >I would like to get some industry wide standards or common practice for
    > >testing MS patches in the local environment. I am looking into
    > >deploying SUS or SMS but also need to set a policy for testing before
    > >network wide deployment. Seeing as we only have production servers and
    > >don't have cloned "test" server, how can a patch be tested in that local
    > >environment without risk of damage or loss of data? Any information
    > >that can be provided would be very helpful.
    > >
    > >TIA,
    > >Matt Brei
    > >Network Administrator
    > >
    > >
    > >
    > >---------------------------------------------------------------------------
    > >KaVaDo provides the first and only integrated Web application scanner and
    > >firewall security suite that prevent Web applications attacks, the most
    > >common form of online exploitation. Download a FREE whitepaper on Security Policy Automation for Web Applications.
    > >http://www.securityfocus.com/sponsor/KaVaDo_focus-ms_030818
    > >---------------------------------------------------------------------------
    > >
    > >
    >
    > ---------------------------------------------------------------------------
    > KaVaDo provides the first and only integrated Web application scanner and
    > firewall security suite that prevent Web applications attacks, the most
    > common form of online exploitation. Download a FREE whitepaper on Security Policy Automation for Web Applications.
    > http://www.securityfocus.com/sponsor/KaVaDo_focus-ms_030818
    > ---------------------------------------------------------------------------

    --
    "Don't lose sight of security. Security is a state of being,
    not a state of budget. He with the most firewalls still does
    not win. Put down that honeypot and keep up to date on your
    patches. Demand better security from vendors and hold them
    responsible. Use what you have, and make sure you know how
    to use it properly and effectively."
    ~Rain Forest Puppy
    http://www.wiretrip.net/rfp/txt/evolution.txt
    ---------------------------------------------------------------------------
    KaVaDo provides the first and only integrated Web application scanner and 
    firewall security suite that prevent Web applications attacks, the most 
    common form of online exploitation. Download a FREE whitepaper on Security Policy Automation for Web Applications. 
    http://www.securityfocus.com/sponsor/KaVaDo_focus-ms_030818 
    ---------------------------------------------------------------------------
    

  • Next message: Kurt Seifried: "Re: Patch testing"

    Relevant Pages

    • Voting on issues for this list and SecurityFocus (Focus-MS)
      ... community input we are considering implementing a more democratic process ... for making important decisions on the future of our mailing lists and the ... collectively guiding the Security Focus community forward. ... Download a FREE whitepaper on Security Policy Automation for Web Applications. ...
      (Focus-Microsoft)
    • Re: testing laptop based on bsd anyone
      ... "A new linux distribution for Wardrivers" ... I wasn't speaking about the relative strengths of security measures within ... As attacks through web applications continue to rise, ... vulnerability management needs. ...
      (Pen-Test)
    • Re: testing laptop based on bsd anyone
      ... Hopefully it will point at some nice BSD ... I wasn't speaking about the relative strengths of security measures within ... As attacks through web applications continue to rise, ... vulnerability management needs. ...
      (Pen-Test)
    • RE: focus-ms@securityfocus.com
      ... If I may....Quoting MS Security Resource Kit... ... Cached Credentials ... "By default, Windows NT, Windows 2000, and Windows XP cache the ... >Security Policy Automation for Web Applications. ...
      (Focus-Microsoft)
    • RE: Security for Win XP Home
      ... Security for Win XP Home ... very un-savvy users. ... Security Policy Automation for Web Applications. ... Download a FREE whitepaper on Security Policy Automation for Web Applications. ...
      (Focus-Microsoft)