Re: Question about automatic updates

From: Miha Pihler (miha.pihler_at_Atlantis-N0Spam.si)
Date: 07/31/03


Date: Thu, 31 Jul 2003 22:32:57 +0200


Hi Ed,

all patches, service packs etc from Microsoft are signed. This signature is
checked before patch or service pack is applied to the system. If anyone
would to edit (modify) or if a virus would infect such package signature
would not match and patch/service pack would not be applied ...

-- 
Mike
MCSA 2K, MCSE 2K, MCT, ...
"Ed" <vessel@usc.edu> wrote in message
news:055f01c357a1$70e17200$a101280a@phx.gbl...
> Hi there -
>
> I have a general question about the automatic update
> feature of Windows XP (i.e. the "new updates are available"
> info bubble).
>
> I am a pretty security conservative person and would
> typically shy away from any update system which
> automatically contacts me due to the possibility that it
> could be spoofed.  However, XP is so insistent about its
> update process that I have caved in and allow it to
> download updates.
>
> My question is ... are there any known viruses, trojan
> horses, etc. out there which are known to exploit this?
> I.e., is it at all possible that someone could have opened
> an email attachment or visited a website with an auto
> download that would then proceed to masquerade as the XP
> automatic update service in the future to download or
> upload data?  The reason I ask is because the nature of the
> explanation of the downloaded security patches are often so
> vague that I often feel powerless to know if I really need
> something or if I should ignore it and seek out security
> patches on my own when I hear about them.
>
> thanks,
> Ed


Relevant Pages

  • Re: [SLE] YOU
    ... signature check for patch into files failed. ... Cannot load patch information. ... When YOU finished downloading the patches i will execute: ... Why is it giving me that error when i used wget to download ...
    (SuSE)
  • Re: Patches -v- Updates
    ... > I am assuming that patches are offered once a problem is ... > Windows Updates as part of an overall security update. ... There are basically two kinds of such updates: patches and service packs. ... Windows Update, in the security bulletins, the Microsoft Download Center, ...
    (microsoft.public.security)
  • Must I download entire Office Service Pack?
    ... Again, Eric and John, thank you for taking the time to ... The Office download center reports ... >that I should download the latest Office Service Packs. ... Patches are one way of keeping Bill Gates' ...
    (microsoft.public.office.setup)
  • Re: Problems with Automatic Updates - Help !!!
    ... >> Windows Update to go and download the patches with Admin Powered ID, ... Wrong John Doe. ... away from open flames, naked flames and old flames; avoid inhaling fumes; ...
    (alt.os.windows-xp)
  • Re: Patch clusters
    ... Is there a link to a cluster of the free patches, ... I installed Sol 10 on a system, registered it, and then ran smpatch ... it hangs during download but it's not uncommon. ... The connections I am using are what I would consider to be very reliable: ...
    (comp.sys.sun.admin)