RE: Best way to deploy MS security patches ??

From: Reksopuro, Marjono (Reksopuro.Marjono@con-way.com)
Date: 03/14/02


From: "Reksopuro, Marjono" <Reksopuro.Marjono@con-way.com>
To: "Kip Sr." <kipsr1@yahoo.com>, security-basics@securityfocus.com
Date: Thu, 14 Mar 2002 11:29:44 -0800

There's a new tools that MS will provide very soon, it's called Corporate
Windows Update Server, it will provide new administrative template, and you
can add it into the Group Policy.

So, it will works seamlessly with your Win2K environment.
You can even cascade the Servers, so that you'll multiple 'Patches' servers.
The beauty of this concept is that you can test the patches/fixes before
deploying it.

http://www.microsoft.com/technet/treeview/default.asp?url=/TechNet/ittasks/s
upport/corpwu.asp

It will also utilize all available tools like HfNetChk, Baseline Network
Analyzer, Microsoft Personal Security Advisor, etc.

PS: You might want to consider Shavlik - HfNetChk Pro as part of Admin Suite

Marjono B. Reksopuro - MCSE
CII Technical Architecture
 
Ph: (503)450-6464 Fax: (503)450-5790
E-mail: reksopuro.marjono@con-way.com

-----Original Message-----
From: Bardaville, Phil [mailto:pbardaville@gltg.com]
Sent: Wednesday, March 13, 2002 5:41 PM
To: David Ellis; Kip Sr.; security-basics@securityfocus.com
Subject: RE: Best way to deploy MS security patches ??

We use HFNETCHK
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/
tools/hfnetchk.asp
in conjunction with
QCHAIN.EXE http://support.microsoft.com/default.aspx?scid=kb;EN-US;q296861
 
QCHAIN usually only requires one reboot for all the patches, it saves gobs
of time. Too bad Microsoft doesn't advertise this wonderful tool more.

Philip Bardaville
UNIX Network Engineer
GLTG

-----Original Message-----
From: David Ellis [mailto:dellis@unicam.com]
Sent: Tue 3/12/2002 7:37 PM
To: 'Kip Sr.'; 'security-basics@securityfocus.com'
Cc:
Subject: RE: Best way to deploy MS security patches ??
 
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Update expert from Bernard software

Sincerely,
David Ellis
Systems/Security Engineer
MCSE, CCSE, CCA, CCNA
Tecnomatix - Unicam Inc.
Two International Drive - Suite 150
http://www.tecnomatix-unicam.com
603.766.9664 Tel (Direct)
603.765.3341 Mobile
603.431.9516 Fax

- -----Original Message-----
From: Kip Sr. [mailto:kipsr1@yahoo.com]
Sent: Tuesday, March 12, 2002 1:01 AM
To: security-basics@securityfocus.com
Subject: Best way to deploy MS security patches ??

Hi there!

I have 180 Win2K desktops, and am looking for an
automated solution to quickly and efficiently deploy
patches throughout the enterprise. I have used SMS
before, but find it cumbersome and time consuming to
use. Does anyone have any other suggestions? Tips?
Tricks?

Much obliged,
Kip

__________________________________________________
Do You Yahoo!?
Try FREE Yahoo! Mail - the world's greatest free email!
http://mail.yahoo.com/

-----BEGIN PGP SIGNATURE-----
Version: PGPfreeware 7.0.3 for non-commercial use <http://www.pgp.com>

iQA/AwUBPI6fMqraIKo8Q3RHEQLODACgsWRLlu6bOhvsLoJ/wVDoGOCpR54Anjbu
UGahLUH3p6oYtcfiL+ScZ5h4
=0SL/
-----END PGP SIGNATURE-----



Relevant Pages

  • Re: Changes in IDS Companies?
    ... Things like port scans and DoS attacks very often ... >> If people are running insecure web servers, ... when people don't update their patches at ... > downplay the vulnerability to save face, so admins even if they are trying ...
    (Focus-IDS)
  • RE: Betr.: Re: MS Patches Management software: SUS vs 3rd party
    ... We are also currently looking at a solution for updating our clients and servers. ... The major drawback is that if a new unpatched client connects to it, it retrieves all patches at once. ... There is no management in SUS, ... >The Presidio integrates PGP data encryption and XML Web Services security to ...
    (Security-Basics)
  • Re: [Full-disclosure] Getting Off the Patch
    ... There are something like 800 heterogeneous servers where I work. ... As for having to spend a lot of cycles testing patches, ... engineer who has been playing this patching game for 20 years. ... who want audit verification of how vulnerabilities are being mitigated. ...
    (Full-Disclosure)
  • Re: Betr.: Re: MS Patches Management software: SUS vs 3rd party
    ... > it retrieves all patches at once. ... There is no management in SUS, ... > If they are planning to include the Windows NT 4.0 servers for the ... >> simplify the management and deployment of PGP and reduce overall PGP ...
    (Security-Basics)
  • FW: Server problems caused by the application of a Microsoft Secu rity Patch
    ... Microsoft Security patches cause SAP outage for our Production Instance. ... which could not be resolved by COMPAQ H/W engineer who was ...
    (NT-Bugtraq)