Penetration Testing mailing list archives

Re: Patch management tool


From: Alvin Oga <alvin.sec () Mail Linux-Consulting com>
Date: Sat, 4 Sep 2004 07:30:39 -0700 (PDT)



On Fri, 3 Sep 2004, Chris Griffin wrote:

Some thing like patch distribution server which possibly push the recent OS
patches to other linux systems. Linux distribution should covering RedHat,
Suse other linux flavors.

it's trivial to write one ... or create one

and use the standard pkg management tool for that distro

creating the "tested" patch server for all your production machines
is a bit trickier ... espif those production machines cannot go down
due to some ooppss some place down the line or up the tree

c ya
alvin

- we use our own patch tools  ... for any flavor *nix ...
        ( free patches since the patches are free from
        ( redhat/suse/debian/slackware...

        - the update.pl patch script is not released

        simplified in one (update.pl) script

        if redhat ...
                rpm from red-patches.your-domain.com

        if suse
                rpm from suse-patches.your-domain.com

        if debian
                apt-get from debian.your-domain.com

        if sun 
                upgradepkg from sun.your-domain.com

        -- add/maintain more distros as you need



------------------------------------------------------------------------------
Ethical Hacking at the InfoSec Institute. All of our class sizes are
guaranteed to be 12 students or less to facilitate one-on-one interaction
with one of our expert instructors. Check out our Advanced Hacking course,
learn to write exploits and attack security infrastructure. Attend a course
taught by an expert instructor with years of in-the-field pen testing
experience in our state of the art hacking lab. Master the skills of an
Ethical Hacker to better assess the security of your organization.

http://www.infosecinstitute.com/courses/ethical_hacking_training.html
-------------------------------------------------------------------------------


Current thread: