RE: new IIS worm? (rcp lsass.exe)

From: Bax.Plemons@alltelmd.com
Date: 09/26/02


To: "Gaydosh, Adam" <GaydoshA@ctcgsc.org>
From: Bax.Plemons@alltelmd.com
Date: Thu, 26 Sep 2002 08:07:07 -0400


Actually you're only partially correct. Patches that do not enter registry
changes are not found by the baseline tool or hfnetchk even though they are
properly installed. Some good examples of this are some SQL patches.
Microsoft has a paper on this on their support site. Another possibility
that you may be running into is that most(not all) patches can be
overwritten by other patches or service packs which then requires you to go
through the patch process all over again.

Cheers

Bax Plemons
Corp Security

                                                                                                                                    
                      "Gaydosh, Adam"
                      <GaydoshA@ctcgsc. To: "'webbi@sapc.edu'" <webbi@sapc.edu>, incidents@securityfocus.com
                      org> cc:
                                               Subject: RE: new IIS worm? (rcp lsass.exe)
                      09/25/2002 03:40
                      PM
                                                                                                                                    
                                                                                                                                    

I've never heard about this, does anybody else care to comment on MS
patches
not actually installing the files? From what I understood, in cases where
the MS tools returned a vuln you thought you've covered, it's because they
require a work around and not a patch [e.g. the hfnetchk warning]. The
only
case I've seen a installed patch fail a check was when software I'd since
installed regressed a file.

-----Original Message-----
From: webbi@sapc.edu [mailto:webbi@sapc.edu]
Sent: Wednesday, September 25, 2002 12:24 AM
To: incidents@securityfocus.com
Subject: RE: new IIS worm? (rcp lsass.exe)

That means those updates didn't apply properly. What MBSA, and the HFNetChk
tools it's a limited version of, do is actually check if the files updated
by the patch are at the proper versions. Sometimes MS patches don't apply
right, so even though you've downloaded and installed it, and Windows
Update, which just checks if the registry says the patch is installed, says
it's installed, it's not actually installed. It's unfortunate that MS
patches often don't actually patch..

-----Original Message-----
From: James Williams [mailto:jwilliams@mail.wtamu.edu]
Sent: Tuesday, September 24, 2002 4:52 PM
To: Incidents; zeno
Subject: Re: new IIS worm? (rcp lsass.exe)

The only tool that I know of that almost does all of that is the MS
Baseline
Security Analyzer. It's a gui tool that scans your system and tells you
what
potential holes you have and tells you what patches you are missing. I have
had some problems with it as far as the patches go because it will tell me
that I'm missing updates that I know that I've already downloaded and
installed.

James Williams
Network Systems Technician
West Texas A&M University
http://www.wtamu.edu

----------------------------------------------------------------------------

This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • 9_Recommended error codes (specifically return code 5)
    ... * "return code 2" indicates patches are already installed. ... * "return code 25" means a patches requires another patch that is not yet installed. ... With or without using the save option, the patch installation process ... Installing 114008-01... ...
    (SunManagers)
  • Repost: Solaris Live Upgrade: questions about /var/sadm
    ... Newer patches will save the old files ... If the previous patch installation saved the old ... you should go back to the previous version before installing? ... Apply patch blabla-02 (BlaBla-01 saved) ...
    (comp.unix.solaris)
  • Patch Check Advanced
    ... I developed my own script - Patch Check Advanced (PCA). ... downloading and installing of patches from Sunsolve. ...
    (comp.unix.solaris)
  • Re: reinstall patch
    ... You have WinXP SP1 installed, the fixes in which supersede KB328310. ... Your reply also tells me that you're not up-to-date with IE/OE patches, ... alone installing WinXP SP2). ... > hi i get these patch: ...
    (microsoft.public.windowsxp.general)
  • Re: Inviting malware
    ... Downloading a good AV and installing OFF LINE is always my first step. ... long enough to make sure patches are up to date. ... they have drilled holes in the door and used self ... but 15 seconds with a screwdriver and the hasp is undone. ...
    (alt.computer.security)