Re: Windows patch mgmt.

From: steve (securityfocus_at_delahunty.com)
Date: 06/22/04

  • Next message: Kelly Martin: "SF new article announcement - Securing Apache 2: Step-by-Step"
    To: "bob martin" <bobmartin_613@hotmail.com>, <security-basics@securityfocus.com>
    Date: Tue, 22 Jun 2004 07:57:05 -0400
    
    

    I believe that PatchLink tests in their own environment prior to pushing out
    patches, Microsoft or otherwise. A product/vendor you might consider.

    ----- Original Message -----
    From: "bob martin" <bobmartin_613@hotmail.com>
    To: <security-basics@securityfocus.com>
    Sent: Tuesday, June 15, 2004 10:40 AM
    Subject: Windows patch mgmt.

    Hello all.
    Basic patching question for you.

    We have a small environment (approx. 300 desktops and 50 servers) and the
    question has come up how do we test all desktops/servers after a windows
    patch has been installed. Given that the networking/desktop team consists
    of 6 people, I'm a bit stumped on how we can do this efficiently. We use
    St. Benard's Update Expert to push out the patches and to verify they've
    been installed.

    Currently we push to a QA environment and let it soak for a week or two
    while it's being used for it's normal functions. The concern is if the
    server isn't being used for testing, then we may push a patch to a
    production server without it being "tested."

    Any suggestions would be very welcomed. Any more, there's so many windows
    patches that it's almost a full time job for one person to manage them.

    Thanks.
    Bob

    _________________________________________________________________
    Is your PC infected? Get a FREE online computer virus scan from McAfeeŽ
    Security. http://clinic.mcafee.com/clinic/ibuy/campaign.asp?cid=3963

    ---------------------------------------------------------------------------
    Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off
    any course! All of our class sizes are guaranteed to be 10 students or less
    to facilitate one-on-one interaction with one of our expert instructors.
    Attend a course taught by an expert instructor with years of in-the-field
    pen testing experience in our state of the art hacking lab. Master the
    skills
    of an Ethical Hacker to better assess the security of your organization.
    Visit us at:
    http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    ----------------------------------------------------------------------------

    ---------------------------------------------------------------------------
    Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off
    any course! All of our class sizes are guaranteed to be 10 students or less
    to facilitate one-on-one interaction with one of our expert instructors.
    Attend a course taught by an expert instructor with years of in-the-field
    pen testing experience in our state of the art hacking lab. Master the skills
    of an Ethical Hacker to better assess the security of your organization.
    Visit us at:
    http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    ----------------------------------------------------------------------------


  • Next message: Kelly Martin: "SF new article announcement - Securing Apache 2: Step-by-Step"

    Relevant Pages

    • Re: Learning process
      ... a million users on Windows would be ... Most of the patches are fixes for problems in security and a lot of ... pile of games or the SQL blaster which required 2 patchs - patch 1, ... holes *aren't* patched almost immediately. ...
      (alt.comp.lang.learn.c-cpp)
    • So Windows Update is a dog, now what?
      ... extension, that means that the soon-to-be-released Windows Update, ... How about someone getting serious about patch management over at ... In their explanation of the severity rating scheme, the Microsoft ... incredibly reliable mechanism for getting patches onto systems, ...
      (NT-Bugtraq)
    • RE: [Full-Disclosure] Whos to blame for malicious code?
      ... >> windows admins were and remain just plain lazy, ... > deploying patches to an enterprise in a timely manner. ... the problem is solved and the malicious code has no impact. ... this patch undoes what last weeks patches did. ...
      (Full-Disclosure)
    • Problems with MS03-042 (KB826232) patch?
      ... On a variety of computers ranging from Windows 2000 SP2 to SP4 plus all ... previous patches, whenever the KB826232 patch is installed, then other ... patches to the entire enterprise. ...
      (NT-Bugtraq)
    • 9_Recommended error codes (specifically return code 5)
      ... * "return code 2" indicates patches are already installed. ... * "return code 25" means a patches requires another patch that is not yet installed. ... With or without using the save option, the patch installation process ... Installing 114008-01... ...
      (SunManagers)