Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | broken chain of MS updates |
|---|---|
| Date: | Thu, 13 Oct 2005 10:52:28 -0400 |
All, While doing Nessus scans you possibly have seen that after several updates using MS Windows Updates service some hosts still show up sets of vulnerabilities. We used Altiris patch management/assessment SW to check where it happened. We found that file(s) in the update set failed to update and have old version while others were updated and have correct version. Following, some later updates failed to install either. Investigating recently a few cases of "dirty" computers having multiple vulnerabilities, I found in several Nessus scans that there is a "genetic" sequence of in each (I used DB report showing the most vulnerable in a scan): MS04-007 (KB828028, Nessus plugin 12052) -> ->MS04-011 (KB835732, Nessus plugin 12205) -> ->MS05-018 (890859, Nessus plugin 18022 ) It is likely to be a birth defect in KB828028, which affected the chain. I fixed the problem by completely uninstalling ALL patches/fixes, and installing back using Windows Update. In this case Update works. Mikhail Utin AIS Security utinma@npt.nuwc.navy.mil 401-832-6584
_______________________________________________ Nessus mailing list Nessus@list.nessus.org http://mail.nessus.org/mailman/listinfo/nessus
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: Making plugins work - getting a SIGSEGC error, George A. Theall |
|---|---|
| Next by Date: | Sun and ID 11834 - Source routed packets, chmod077 |
| Previous by Thread: | OT: Nessus Naming, Lachniet, Mark |
| Next by Thread: | Sun and ID 11834 - Source routed packets, chmod077 |
| Indexes: | [Date] [Thread] [Top] [All Lists] |