Jump to content

Proactive Security Auditor


Tomalak

Recommended Posts


I'm using windows 2000 sp4 german edition.

While windows update is completely happy (testet 10 seconds ago) PSA FE (date:14.3.2006) tells me 7 Bulletins not installed:

MS02-064 (KB327522) - default permissions allows trojan horse

MS04-016 (KB839643) - DirectPlay allows DoS

MS04-028 (KB833987) - JPEG (GDI+) allows code execution

MS05-009 (KB885492 and 887472) - PNG leads to Buffer Overrun

MS05-044 (KB905495) - FTP allows local transfer

MS05-050 (KB904706) - DirectShow allows remote code execution

MSXML 3.0SP7 should be installed instead of SP5

someone with same experiences? something I must do?

thanx

Edited by murvun
Link to comment
Share on other sites

Microsoft Baseline Security Analyzer:

Windows safety updates: no missing update :thumbup

That's strange, PSA works perfectly for me (Win XP SP2 though, not Win 2000). Does the tool really say "missing" or just "note"? I've some of those as well, the helpfile tells about the status "note":

This is a special status. It means that PSA was not able to determine whether the patch is installed or not. This is not due to PSA error, but because the mssecure.xml file contains no information about affected files and/or registry keys for this bulletin.

So you may indeed have all patches installed and there is no discrepancy between WU/MU, MBSA and PSA.

Link to comment
Share on other sites

Tomalak: You are right: they are only signed as a note - I did not read, what 'note' was meaned... so they are installed, but mssecure.xml contains no information, how to detect them...

All: have a nice weekend. /me is in Cyrodiil. :)

Link to comment
Share on other sites

  • 3 weeks later...

just to pull this thread on top:

Proactive Security Auditor FE (Freeware Edition) is a free, small, fast and easy to use program to assist system administrators and ordinary users to keep their computers secure by identifying what security updates are installed on local and remote machines, and allowing to download and install missing patches from Microsoft web site.

the great +++ against Windows Update and MS Baseline security Analyzer is: you don't need the service "SERVER" running! even the command line mbsacli.exe needs "SERVER" running

just my 2 cents.

Edited by murvun
Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...