Re: Hfnetchk.exe

From: Jeff Cochran (jcochran)
Date: 07/21/02


From: jcochran at naplesgov dot com (Jeff Cochran)
Date: Sun, 21 Jul 2002 15:39:53 GMT


>Here is my defence from my orignal posting against using WU.
>
>"Why WU is not good...

Windows Update may not be the ideal tool in *your* situation, but that
hardly makes it a sin for anyone to use it. A responsible admin will
use the tools appropriate to their situation.

>1. I have to WALK to each workstation and click on Start Windows Update
>[wasting my time]

Or use a remote access tool...

>2. If I have Windows XP machines with the automatic Windows Update, I am
>relying on my end users to click on "ok" to load. This just doesn't happen.
>All machines in the office are going to pull down the same patch. In order
>to
>confirm that they did the install, I once again have to walk around to each
>machine and see if they did it....

Or set it to automatically install...

>Thus... WU and WU only will not give you ANY confirmation that all machines
>in
>your network are patched. All it takes is a weak link to get in....

Installing by running a patch file gives you no confirmation to speak
of, and you'd have to walk around to the stations to run them or use a
scripting method anyway.

>3. There are instances where certain hotfixes will not load via WU. You
>must
>shut down the underlying service in order to run WU.

Hmm... I've never run into any, but it sounds plausible. If you find
some, perhaps you'd share them.

>4. IMHO the only logical, "control" with verifiable "yes I did the patch on
>that particular day and I can confirm this with a printout" is to
>
>a. Purchase Update Expert from St. Bernard's Software or
>b. Shavlik's hfnetchkpro

I have no issues with pushing out patches using SMS, or any other
updates or software for that matter.

>Every third party security resource that I defer to [we're talking
>NTbugtrak,
>SANS yadda yadda... indicates that you should use a combo of BOTH hfnetchk
>and
>Windows Update to check your server. Just using one does not do the job.

Actually, using both won't do the job either. Unfortunately, security
actually requires an admin, and one that's vigilant and sometimes a
bit anal.

>5. There have been known cases where the patches that are identified via WU
>are not the same as hfnetck needed patches"

Gee, and HFNetChk keeps telling me to install a patch that I can't use
too. Again, there aren't any automated tools that can do it, it
requires an admin who isn't automated. And who knows what he's
installing and why.

The bottom line on this was your blanket statement never to use
Windows Update. On that I disagree, but on almost everything else
we're in a similar alignment.

Jeff



Relevant Pages

  • Re: IE patches killed internet connection
    ... If you have Microsoft Update (vs. Windows Update) installed, a shortcut to it will be found in the Start menu. ... I attempted to install 3 of those 4 patches, ... Later, Auto Update reoffered the security update, but I ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: Windows Update Error 0x8007F004 (Insufficient Privilege)
    ... it as the local administrator, the domain administrator, my own domain ... downloading one of the patches), and it doesn't come up with any permissions ... > When I tried to install Microsoft's latest patches (MS04-029 through ... > MS04-038) via Windows Update the process failed. ...
    (microsoft.public.win2000.windows_update)
  • Re: Solution to KB823353 & KB837009
    ... If you had KB823353 already installed, Windows Update then offered you and you successfully installed KB897715, and then Windows Update told you KB823353 still needed to be installed, I surmise (from other discussions ... My Windows Update History page details the following patches (in install ... Cumulative Security Update for Internet Explorer 6 Service ...
    (microsoft.public.windowsupdate)
  • Re: manual MS Update fails (gen. host proc. fail) but works automa
    ... I thought I'd post a quick update to my windows update issue with generic ... Updates were failing for various 'generic host process' errors with various ... The memory was added to the laptop when it had Vista to upgrade from 1 ... unresponsive when you try to install an update from Windows Update or ...
    (microsoft.public.windowsupdate)
  • Re: I am having connectivity problems
    ... Are you telling me that the ZA firewall AND the Windows Firewall was enabled when you installed SP3 via Windows Update? ... This Service "protects" Windows and disallows certain changes to be made (e.g., the changes install SP3 will make), so it should have been disabled prior to installing SP3. ... does the connection problem persist? ...
    (microsoft.public.windows.inetexplorer.ie6.browser)