[There's a reason that Yoda is the unofficial mascot of SBS.  Size indeed matters not.] August 09, 2005 - Posts - THE OFFICIAL BLOG OF THE SBS "DIVA"

August 09, 2005 - Posts

So in reading tonight's bulletins .... man if I had a vendor forcing me to stay on Windows 2000 service pack 3?  Right now I'd be screaming my little head off....one of them... the one on the Print Spooler issue.... if you can't patch because you are not on SP4 [which as of June 30, 2005 is the SP that they are supporting], I'm not sure you can add that registry edit to disallow annoyomous access to the print spooler pipes.  If you can't do that, can't patch... you can always disable the print spooler service....

uh.. you might want to decide what off the Internet you want to print first before you disable the service though....that kinda puts a crimp in you using your HP laserjet...

Dana and I were chatting tonight and he's already put the patches through his patch testing process whereby on VMware he pulls an image of his actual machine, patches it in testing before he deploys it on the real machine.  He uses a tool from Vmware for this that he gets from the VMware Technology Network subscription used for testing [hey... testing patches] and it will snap an image and virtualize a real machine.

...oh this sounds so cool... we might just have to make sure Dana chats about this up at SMBnation where he and I will be presenting...now mind you VMware testing is like testing the patches like I do on the machine here at home before deploying at the office... you won't catch any funky specific hardware stuff, but you will catch software related....

Oh I think I'm definitely going to buy this .... in my perfect world my SBS server would have a snap image-ability like this... something that would let me have a roll back feature so that no matter what the patches did to my box I'd be able to easily and quickly and ...without the sinking feeling of terror ... roll back.  While it's been a long time since anything bad has occurred.. it's one of those things that you just want to try to live your life without experiencing too many times...or at least have a real good plan of action.  I see a lot of people concerned about the fact that they can't truly have a duplicate spare server 'just in case'.  While I am legally allowed because of Software Assurance to have cold server rights, I've rather felt that I'd rather spend the money on good quality components than a duplicate device that couldn't be pulling an image 24/7. 

So ...you doing your patch testing?  Getting ready for deployment?  Read the next blog post for a reminder of some best practices....

Posted Tue, Aug 9 2005 23:49 by bradley | with no comments
Filed under:

Eric Schultze reports on the Patch Management listserve...

Please note that at least two of the IE patches for MS05-038 that are
currently available for download from Microsoft have invalid digital
signatures (XP SP2 and WS03 32 bit patches), and at least one patch is
not digitally signed (IE 5.01 SP4).

Right click and view properties for these patches once you've downloaded
them.  Select the digital signatures tab and click to view details.  The
GUI will then tell you if the signature is valid or not.

I'm guessing that Microsoft will re-post these patches shortly.

I've tested from two separate locations on the Internet with the same
results, though you're testing may vary.

--eric

So if you can't install those patches...that's why...hang loose....

Posted Tue, Aug 9 2005 12:41 by bradley | with no comments
Filed under:

Bulletin Summary:

http://www.microsoft.com/technet/security/Bulletin/ms05-Aug.mspx

Critical Bulletins:

Cumulative Security Update for Internet Explorer (896727)
http://www.microsoft.com/technet/security/Bulletin/ms05-038.mspx

Vulnerability in Plug and Play Could Allow Remote Code Execution and
Elevation of Privilege (899588)
http://www.microsoft.com/technet/security/Bulletin/ms05-039.mspx

Vulnerability in Print Spooler Service Could Allow Remote Code Execution
(896423)
http://www.microsoft.com/technet/security/Bulletin/ms05-043.mspx

Important Bulletins:

Vulnerability in Telephony Service Could Allow Remote Code Execution
(893756)
http://www.microsoft.com/technet/security/Bulletin/ms05-040.mspx

Moderate Bulletins:

Vulnerability in Remote Desktop Protocol Could Allow Denial of Service
(899591)
http://www.microsoft.com/technet/security/Bulletin/ms05-041.mspx

Vulnerabilities in Kerberos Could Allow Denial of Service, Information
Disclosure, and Spoofing (899587)
http://www.microsoft.com/technet/security/Bulletin/ms05-042.mspx

Re-Released Bulletins:

Vulnerabilities in Microsoft Word May Lead to Remote Code Execution
(890169)
http://www.microsoft.com/technet/security/Bulletin/ms05-023.mspx

Vulnerability in Microsoft Agent Could Allow Spoofing (890046)
(890169)
http://www.microsoft.com/technet/security/Bulletin/ms05-032.mspx


This represents our regularly scheduled monthly bulletin release (second
Tuesday of each month). Please note that Microsoft may release bulletins
out side of this schedule if we determine the need to do so.

If you have any questions regarding the patch or its implementation
after reading the above listed bulletin you should contact Product
Support Services in the United States at 1-866-PCSafety
(1-866-727-2338). International customers should contact their local
subsidiary.