Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [ISSForum] Problems with XPU updates after SP5 - SOLUTION |
|---|---|
| Date: | Fri, 28 Jan 2005 12:38:28 -0800 |
We have had numerous issues with this with our clients. I thought I would publish the solution: SP5 has changed the way XPUs and updates are downloaded. This has introduced a problem for those people using proxies, proxy-firewalls, or Internet-content filters (like websense). When something is downloaded over HTTP, it has a content-type associated to it. Common types are "application\msword" or "image\jpg". When Site Protector connects to the ISS site, the communications use a non-standard content-type for their XPU updates and downloads. If you use a proxy firewall, proxy device, or are doing any content-type restrictions though an Internet content device, ISS's XPU updates will fail because of this unusual content type. The content type ISS is using is "application\octect-stream" The standard content type is "application\octet-stream" Many firewalls and proxy devices will not recognize this content type. As such, they will block it. You may need to reconfigure your proxy/firewall to allow this content type. If your firewall or proxy servers do not do any blocking based on content type, then this issue should not be a problem for you. XPU updates also do not happen exclusively over port 443. Site Protector downloads information off the ISS site first using regular old HTTP. Then it switches over the HTTPS for the actual downloads. ___________________________________ Andrew Plato, CISSP President/Principal Consultant ANITIAN ENTERPRISE SECURITY 3800 SW Cedar Hills Blvd, Suite 298 Beaverton, OR 97005 503-644-5656 Office 503-214-8069 Fax 503-201-0821 Mobile www.anitian.com ___________________________________ GPG fingerprint: 16E6 C5B0 B6CB F287 776E E9A9 AF47 9914 3582 633D GPG public key available at: http://www.anitian.com/corp/keys.htm <blocked::http://www.anitian.com/corp/keys.htm> _______________________________________________ ISSForum mailing list ISSForum@iss.net TO UNSUBSCRIBE OR CHANGE YOUR SUBSCRIPTION, go to https://atla-mm1.iss.net/mailman/listinfo/issforum To contact the ISSForum Moderator, send email to mod-issforum@iss.net The ISSForum mailing list is hosted and managed by Internet Security Systems, 6303 Barfield Road, Atlanta, Georgia, USA 30328.
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: [ISSForum] Linux Server Sensor, Buelna, Derek |
|---|---|
| Previous by Thread: | Re: Blocked by subject (Original Subject: Re: Blocked by subject (Original Subject: RE: [ISSForum] Key Licence Failure on Upgrade)), Luis Daniel Lucio Quiroz |
| Indexes: | [Date] [Thread] [Top] [All Lists] |