Penetration Testing mailing list archives

Re: Windows Patch Auditing & "File and Print Sharing" disabled


From: Jeffrey Walton <noloader () gmail com>
Date: Thu, 30 Apr 2009 15:03:19 -0400

Hi Jerry,

A lot of issues you may encounter are the same as those with MBSA.
Nessus may simply fail the test, while MBSA will fail and return an
error code. Take a look at Microsoft's MBSA faq:
http://technet.microsoft.com/en-us/security/cc184922.aspx

Jeff

-----Original Message-----
From: listbounce () securityfocus com [mailto:listbounce () securityfocus com]
On Behalf Of Mike Drugov
Sent: Thursday, April 30, 2009 12:01 PM
To: pen-test () securityfocus com
Subject: Windows Patch Auditing & "File and Print Sharing" disabled

Hello list,

I need some advise

I'm trying to scan a Windows Network where all end nodes except Domain
Controller have "File & Print Sharing" disabled.

What I'm trying to get a list of Microsoft Updates that are missing.

So far I tried Nessus & Foundstone and none of them are able to provide
a report with missing patches.(I'm able to get a report from Domain
Controller)

Nessus support stated that "File & Print Sharing" is required for patch
auditing


What is my other options?

Thanks


------------------------------------------------------------------------
This list is sponsored by: InfoSec Institute

Tired of using other people's tools? Why not learn how to write your own exploits? 
InfoSec Institute's Advanced Ethical Hacking class teaches you how to write stack and heap buffer overflow exploits for 
Windows and Linux. Gain your Certified Expert Penetration Tester (CEPT) cert as well. 

http://www.infosecinstitute.com/courses/advanced_ethical_hacking_training.html
------------------------------------------------------------------------


Current thread: