Jump to content

dmitri

Member
  • Posts

    1
  • Joined

  • Last visited

  • Donations

    0.00 USD 
  • Country

    country-ZZ

About dmitri

dmitri's Achievements

0

Reputation

  1. I can't understand why don't you mention the critical updates of the last 1-2 weeks ? The risk of not applying them is VERY high. MS03-045 : Buffer Overrun in the ListBox and in the ComboBox Control Could Allow Code Execution (824141) MS03-044 : Buffer Overrun in Windows Help and Support Center Could Lead to System Compromise (825119) MS03-043 : Buffer Overrun in Messenger Service Could Allow Code Execution (828035) MS03-041 : Vulnerability in Authenticode Verification Could Allow Remote Code Execution (823182) Is there at last a page which will provide an archive with all the bat-files and names of the hotfixes maintained by a single person ? I think it is convinient for the user to be able to install only the updates missing. Can anoyone make it clear and summarize what are installation methods for MS Hotfixes ? I know WindowsUpdate, WindowsUpdate+SUS services, Shalvik HFNetCheckPro, HFNetCheckLite and a free utility based on MS Baseline security analyzer (there was a posting on ntbugtraq). Each of these programs have their pros and cons. Windowsupdate needs a Windowsupdate.com website (which is not good if the user doesn't have a high-speed connection) or a SUS server to operate (it requires a separate server machine). The Commercial Shalvik program can download and install patches of any language. Actually I haven't tried the download possibility because of using only it's free version. But for my opinion it's a very slow program with bloated interface. The free util I mentioned can accept input from MS baseline security analyzer (command line util) or HFnetCheckLite. It install patches remotely, and even can parse the mssecure.xml and try to download the patches from MS website. Then it can generate a webpage about the updates it could not download. Downloading these is a pain of choosing the right language, then renaming it into Qxxxxxx (there may be human errors in this manual step). Can anyone give a simple solution for automatic download and deployment of multilingual hotfixe (for example, in Russia we use both English and Russian versions of Windows)? This solution should apply not only to security specialists but also common users. Microsoft would never raise the security of it's products if it doesn't provide a simple and FREE way of doing that !
×
×
  • Create New...