Security Basics mailing list archives

RE: MBSA 1.2


From: deniz () edizayn com tr (Deniz CEVIK)
Date: Thu, 12 Feb 2004 18:37:44 +0200

for windows auditing you should also try Windows base line analyzer and
hotfixchecker.


-----Original Message-----
From: Aditya, ALD [Aditya Lalit Deshmukh]
[mailto:aditya.deshmukh () online gateway technolabs net]
Sent: Wednesday, February 11, 2004 7:46 PM
To: Nagy Gergely; security-basics () securityfocus com
Subject: RE: MBSA 1.2

maybe you are using the wrong tool for this

we use gfi languard which has the ability to scan for missing patches also
download the latest update from the windows site

the address is there in the gfi langurd options

also there is a shareware avilabe for download from the website

-aditya

-----Original Message-----
From: Nagy Gergely [mailto:gergely.nagy () is-energy hu]
Sent: Tuesday, February 10, 2004 5:46 PM
To: security-basics () securityfocus com
Subject: RE: MBSA 1.2


Does Nessus run on XP?
How can I set it to scan all the Microsoft patches on the given system and
vulnerabilites?


-----Original Message-----
From: Rohan Amin [mailto:rohan () rohanamin com]
Sent: Thursday, February 05, 2004 1:51 AM
To: Nagy Gergely
Cc: security-basics () securityfocus com
Subject: Re: MBSA 1.2

A colleague and I have had success with using Nessus
(http://www.nessus.org) for this purpose.  Just modify smb_login.nasl
to use the various Administrator passwords that you have.  Nessus
already includes a few checks for some patches, but if you need more
you can always write some (its quite easy using NASL).  Of course, you
are trusting the registry to give you accurate information but it
might be better than nothing.

Hope this helps,

Rohan





On Tue, Feb 03, 2004 at 04:01:46PM +0100, Nagy Gergely wrote:
Hi all,

I have a very heterogenous infrasturcture, with most PC's
logged into NDS.
What is the use of MBSA (that requires local admin priv) if all the PC's
have different local admin passwords?
In this case, am I not able to scan the situation on the whole network?
Then what else tool could I use to determine the state of patches?

Br,

Gery



Ez a level virusellenorzesen esett at!

This message was checked against viruses!




------------------------------------------------------------------
---------
Ethical Hacking at InfoSec Institute. Mention this ad and get
$720 off any

course! All of our class sizes are guaranteed to be 10 students
or less.
We provide Ethical Hacking, Advanced Ethical Hacking, Intrusion
Prevention,
and many other technical hands on courses.
Visit us at http://www.infosecinstitute.com/securityfocus to
get $720 off
any course!

------------------------------------------------------------------
----------





Ez a level virusellenorzesen esett at!

This message was checked against viruses!



------------------------------------------------------------------
---------
Free trial: Astaro Security Linux -- firewall with Spam/Virus Protection

Protect your network with the comprehensive security solution that
integrates six applications for ease of use and lower TCO.

Firewall - Virus protection - Spam protection - URL blocking - VPN
- Wireless security.

Download 30-day evaluation at:
http://www.astaro.com/php/contact/securityfocus.php
------------------------------------------------------------------
----------





________________________________________________________________________
Delivered using the Free Personal Edition of Mailtraq (www.mailtraq.com)

---------------------------------------------------------------------------
Free trial: Astaro Security Linux -- firewall with Spam/Virus Protection

Protect your network with the comprehensive security solution that
integrates six applications for ease of use and lower TCO.

Firewall - Virus protection - Spam protection - URL blocking - VPN
- Wireless security.

Download 30-day evaluation at:
http://www.astaro.com/php/contact/securityfocus.php
----------------------------------------------------------------------------


---------------------------------------------------------------------------
Free trial: Astaro Security Linux -- firewall with Spam/Virus Protection

Protect your network with the comprehensive security solution that
integrates six applications for ease of use and lower TCO.

Firewall - Virus protection - Spam protection - URL blocking - VPN
- Wireless security.

Download 30-day evaluation at:
http://www.astaro.com/php/contact/securityfocus.php
----------------------------------------------------------------------------


Current thread: