Penetration Testing mailing list archives

Re: Windows Patch Auditing & "File and Print Sharing" disabled


From: Nikhil Wagholikar <visitnikhil () gmail com>
Date: Fri, 1 May 2009 21:49:12 +0530

Hello Mike,

You can give a try to GFI Languard from GFI. Its one of the excellent
tools for checking and applying Microsoft Windows missing patches.
More Info: http://www.gfi.com/lannetscan

Besides this, you could also give a try to HFNetChk tool from Shavlik
Technologies.
More Info: http://www.petri.co.il/hfnetchk.htm

Best of Luck!!
---
Nikhil Wagholikar
Practice Lead | Security Assessment & Digital Forensics
Network Intelligence (India) Pvt. Ltd. [NII Consulting]
Web: http://www.niiconsulting.com/
Comprehensive Information Security Trainings
http://www.niiconsulting.com/services/education/Training%20Calendar.html

2009/4/30 Mike Drugov <DRUGOVM () nychhc org>

Hello list,

I need some advise

I'm trying to scan a Windows Network where all end nodes except Domain Controller have "File & Print Sharing" 
disabled.

What I'm trying to get a list of Microsoft Updates that are missing.


So far I tried Nessus & Foundstone and none of them are able to provide a report with missing patches.(I'm able to 
get a report from Domain Controller)

Nessus support stated that "File & Print Sharing" is required for patch auditing


What is my other options?

Thanks


-----------------------------------------
Visit www.nyc.gov/hhc

CONFIDENTIALITY NOTICE: The information in this E-Mail may be
confidential and may be legally privileged. It is intended solely
for the addressee(s). If you are not the intended recipient, any
disclosure, copying, distribution or any action taken or omitted to
be taken in reliance on this e-mail, is prohibited and may be
unlawful. If you have received this E-Mail message in error, notify
the sender by reply E-Mail and delete the message.

------------------------------------------------------------------------
This list is sponsored by: InfoSec Institute

Tired of using other people's tools? Why not learn how to write your own exploits?
InfoSec Institute's Advanced Ethical Hacking class teaches you how to write stack and heap buffer overflow exploits 
for Windows and Linux. Gain your Certified Expert Penetration Tester (CEPT) cert as well.

http://www.infosecinstitute.com/courses/advanced_ethical_hacking_training.html
------------------------------------------------------------------------


------------------------------------------------------------------------
This list is sponsored by: InfoSec Institute

Tired of using other people's tools? Why not learn how to write your own exploits? 
InfoSec Institute's Advanced Ethical Hacking class teaches you how to write stack and heap buffer overflow exploits for 
Windows and Linux. Gain your Certified Expert Penetration Tester (CEPT) cert as well. 

http://www.infosecinstitute.com/courses/advanced_ethical_hacking_training.html
------------------------------------------------------------------------


Current thread: