Archive

Posts Tagged ‘Patching’

WSUS 3.0 SP2 gone awry

September 11th, 2009 Michael de Bruin No comments

Full credit for this goes to Elianne van de Kamp, who’s been busy with the investigation for quite a while. What happened?

On the 9th of September, together with the regular MS updates an update for WSUS 3.0 came in: Service pack 2. The first issue we encountered was the fact it was announced as an upgrade. It performs a re-install though. This means you have to reconfigure the basic setup of WSUS. The computer list and grouping definitions are safe in the database. Things like which updates and which language to download will have to be configured again though. Being prepared here by making a note of current settings will help.

We ran into a new issue the next morning. The upgrade of WSUS also upgrades all clients with the Windows Update Agent. This runs flawless on 32 bit windows clients. It causes an issue on 64 bit windows however: two files, NT5IIS.CAT and IASNT4.CAT are replaced, probably by 32 bit versions. When you connect to the console of the server it will tell you about this in the form of a Windows File Protection Error. The choice is yours to cancel this warning and ignore like we did, because it concerns a database server and the files will never be used (NT5IIS for web server, IASNT4 for internet authentication). You could also cancel and replace the files manually from CD or service pack. Fact is that the files copied with this update are dated 25-05-2005, so very old and will most like cause problems when you ever need them.

I thought I’d share this information as I’m sure other people will run into this problem as well. Would be a shame if they had to go through the same cycle!

  • Share/Bookmark

Microsoft more vague than usual…

September 8th, 2009 Frank Breedijk No comments
Overview of Microsoft patches due today by Microsoft

Overview of Microsoft patches due today by Microsoft

Microsoft is even more vague than usual about the patches it plans to release today.

In this patch announcement Microsoft only states that it plans to release 5 patches.

This is the data currently known:

Read more…

  • Share/Bookmark

Defcon talk: Breaking the “unbreakable” Oracle with Metasploit – Chris Gates and Mario Ceballos

August 3rd, 2009 Frank Breedijk No comments

Chris and Mario presented and demonstrated the new Metasploit modules that are designed to find and identify Oracle databases, find the SIDs, brute force passwords and escalate privileges.

An interesting comment is that they where actually able to evade Snort detection by base64 encoding the attack.

Read more…

  • Share/Bookmark

Microsoft Sets Record With Monster Patch Tuesday

June 10th, 2009 Trey Guinn No comments

Time to get patching!

As seen on slashdot:  http://it.slashdot.org/story/09/06/09/2243247/Microsoft-Sets-Record-With-Monster-Patch-Tuesday

“Microsoft today issued 10 security updates that patched a record 31 vulnerabilities in Windows, Internet Explorer, Excel, Word, Windows Search and other programs, including 18 bugs marked ‘critical.’ Of the 10 bulletins, six patched some part of Windows, while three patched an Office application or component, and one fixed a flaw in IE. The total bug count was the most patched by Microsoft in a single month since the company began regularly scheduled updates in 2003. The previous record of 26 vulnerabilities patched occurred in both August 2008 and August 2006. ‘This is a very broad bunch,’ said Wolfgang Kandek, CTO at Qualys, ‘compared to last month, which was really all about PowerPoint. You’ve got to work everywhere, servers and workstations, and even Macs if you have them. It’s not getting any better, the number of vulnerabilities [Microsoft discloses] continues to grow.”

  • Share/Bookmark
Categories: Microsoft, WSUS Tags: , ,