RE: Patch management tool

From: Todd Towles (toddtowles_at_brookshires.com)
Date: 09/07/04

  • Next message: Jérôme: "Re: Patch management tool"
    Date: Tue, 7 Sep 2004 11:31:03 -0500
    To: "roman one" <roman@pointyhats.com>
    
    

    Yum works really well, but it shouldn't be your only tool to check for
    updates. Yum only works with special list of rpm updates.

    I use Yum on my FC2 box. I modified my yum.conf to use all the mirrors
    and everything. After doing a Nessus scan on my own box, I saw that my
    SSH verion was pre-3.7.1

    Not good, yum didn't see it and I had to update my OpenSSH myself.

    Yum is good, but keeping up with software versions, knowing what is
    installed on your box and what is running, and watching vuln news is one
    of the best ways.

    I know this isn't the place for his question, but it isn't totally OT.
    Vuln scanning your computer with Nessus and other tools can help you
    find programs that need patches.

    Everyone on this list knows that you should test what will be used
    against you. The essence of Pen-Testing.

    -----Original Message-----
    From: roman one [mailto:roman@pointyhats.com]
    Sent: Saturday, September 04, 2004 7:24 PM
    To: 'Milind Nanal'; pen-test@securityfocus.com
    Subject: RE: Patch management tool

    As mentioned by another on this list, this isn't really the appropriate
    list for such an inquiry, however, not to leave you without an answer,
    for any linux distro that uses rpm's, yum - Yellow dog Updater, Modified
    would fit the need. It's used extensively and is relatively straight
    forward in implementation. You can find it here:

    http://linux.duke.edu/projects/yum/

    In the future, the focus-linux@securityfocus.com would be a better place
    for a linux related inquiry.

    HTH

    roman
    emperor@ensecure.org

    He who fights with monsters might take care lest he thereby become a
    monster. And if you gaze for long into an abyss, the abyss gazes also
    into you.
                         -Friedrich Nietzsche, Jenseits von Gut und Bose
    (1886)

    > -----Original Message-----
    > From: Milind Nanal [mailto:milindyn@rolta.com]
    > Sent: Friday, September 03, 2004 5:46 AM
    > To: pen-test@securityfocus.com
    > Subject: Patch management tool
    >
    >
    > List,
    >
    > Looking for best free tool /open source solution for Linux operating
    > system patches management. There are commercial tools available like
    > Novell zenworks, Shavlik Technologies.
    > But I am looking for non commercial option.
    >
    > Some thing like patch distribution server which possibly push the
    > recent OS patches to other linux systems. Linux distribution should
    > covering RedHat, Suse other linux flavors.
    >
    > Quick response is highly appreciated.
    >
    > Regards,
    >
    > Milind
    >
    > --------------------------------------------------------------
    > ----------------
    > Ethical Hacking at the InfoSec Institute. All of our class sizes are
    > guaranteed to be 12 students or less to facilitate one-on-one
    > interaction with one of our expert instructors.
    > Check out our Advanced Hacking course, learn to write exploits and
    > attack security infrastructure. Attend a course taught by an expert
    > instructor with years of in-the-field pen testing experience in our
    > state of the art hacking lab.
    > Master the skills of an Ethical Hacker to better assess the security
    > of your organization.
    >
    http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    ------------------------------------------------------------------------
    -------

    ------------------------------------------------------------------------
    ------
    Ethical Hacking at the InfoSec Institute. All of our class sizes are
    guaranteed to be 12 students or less to facilitate one-on-one
    interaction with one of our expert instructors. Check out our Advanced
    Hacking course, learn to write exploits and attack security
    infrastructure. Attend a course taught by an expert instructor with
    years of in-the-field pen testing experience in our state of the art
    hacking lab. Master the skills of an Ethical Hacker to better assess the
    security of your organization.

    http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    ------------------------------------------------------------------------
    -------

    ------------------------------------------------------------------------------
    Ethical Hacking at the InfoSec Institute. All of our class sizes are
    guaranteed to be 12 students or less to facilitate one-on-one interaction
    with one of our expert instructors. Check out our Advanced Hacking course,
    learn to write exploits and attack security infrastructure. Attend a course
    taught by an expert instructor with years of in-the-field pen testing
    experience in our state of the art hacking lab. Master the skills of an
    Ethical Hacker to better assess the security of your organization.

    http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    -------------------------------------------------------------------------------


  • Next message: Jérôme: "Re: Patch management tool"

    Relevant Pages

    • Re: Network guru please help: baffled by missing file
      ... If I try "sudo yum update" I get: ... Error: Cannot retrieve metalink for repository: updates. ... Connecting to mirrors.fedoraproject.org|209.132.176.122|:443... ... HTTP request sent, awaiting response... ...
      (Fedora)
    • Re: [Fwd: Fedora Legacy Project]
      ... Anyone have the instructions on setting up fedora 3 for yum? ... All Fedora Legacy packages are signed with GPG keys. ... to continue to receive updates. ...
      (Fedora)
    • Re: Easy way to update Fedora
      ... >>What is the easiest way to update Fedora. ... >>about yum but it has never worked for me, ... > packages or type a package name ... > UPDATES TO SYSTEM AND PROGRAMS: ...
      (Fedora)
    • Re: Cups problem
      ... but yum does updates with no problem ... The rest of the repos you can add by mv the files back but only do 1 or ... mv: cannot stat `NOT-USED/fedora-development.repo.rpmsave': No such file or directory ...
      (Fedora)
    • Re: yum mirrors not in sync
      ... What is happening to the updates repository? ... If I want to do a rational yum update I have to keep ... For FC4, there were local mirror lists, such as .us.east or .uk. ... I don't see any bugs on the sync issue, but I may not be looking at the ...
      (Fedora)