Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 36 guests online
You are here:
EH-Net
May 25, 2013, 12:53:35 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Other
(Moderator:
don
) >
Scanning for missing Microsoft patches
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Scanning for missing Microsoft patches (Read 4129 times)
0 Members and 1 Guest are viewing this topic.
lorddicranius
Sr. Member
Offline
Posts: 447
Scanning for missing Microsoft patches
«
on:
December 05, 2011, 02:56:20 PM »
I was wondering if anybody might be able to help explain this result.
Trend Micro shows a computer is missing 3 security updates. I log into the computer, check Automatic Updates, and it's configured to run every night at 3am. I run Windows Update and there's no updates pending. I install Microsoft Baseline Security Analyzer 2.2 and scan the machine: 27 security updates missing, 3 service packs or update rollups are missing.
I can see how Trend Micro may differ in scanning a Windows machine for patches that are or aren't installed, but I can't explain the difference between Windows Update and Microsoft Baseline Security Analyzer showing such varied results. Especially after reading this from the
MBSA 2.2 download page
:
Quote
Built on the Windows Update Agent and Microsoft Update infrastructure, MBSA ensures consistency with other Microsoft management products including Microsoft Update (MU), Windows Server Update Services (WSUS), Systems Management Server (SMS), System Center Configuration Manager (SCCM) 2007, and Small Business Server (SBS).
Anybody have any ideas
I'm trying to get a patch management system implemented here, but the varying results from Microsoft tools themselves isn't helping my case much haha.
Logged
GSEC, eCPPT, Sec+
eth3real
Sr. Member
Offline
Posts: 309
Re: Scanning for missing Microsoft patches
«
Reply #1 on:
December 05, 2011, 03:18:15 PM »
Is this computer use a WSUS server for updates? If so, that WSUS server may not be set to automatically approve those patches. Just a thought.
Also make sure the computer is set to automatically update other Microsoft products, not just Windows, maybe those patches are for Office or something.
Logged
Put that in your pipe and grep it!
l33t5h@rk
Jr. Member
Offline
Posts: 79
Re: Scanning for missing Microsoft patches
«
Reply #2 on:
December 05, 2011, 03:25:12 PM »
I'm not sure how much control you have (and obv. proceed w/ caution) but I would try installing the Service Packs then re-running. Sometimes the patches are out of band from the service packs and may not show up until they are installed. Something kludgy like that.
Logged
lorddicranius
Sr. Member
Offline
Posts: 447
Re: Scanning for missing Microsoft patches
«
Reply #3 on:
December 05, 2011, 03:50:34 PM »
Quote from: eth3real on December 05, 2011, 03:18:15 PM
Also make sure the computer is set to automatically update other Microsoft products, not just Windows, maybe those patches are for Office or something.
Bingo! Microsoft Update wasn't installed so when I clicked on "Windows Update", it wasn't checking for updates for everything else. Installing Microsoft Update and running the check again shows all the updates. Thanks!
I wish I had an WSUS server (or a domain environment). It would make ensuring Microsoft Update is on these other 51 computers go so much faster/easier...
Logged
GSEC, eCPPT, Sec+
eth3real
Sr. Member
Offline
Posts: 309
Re: Scanning for missing Microsoft patches
«
Reply #4 on:
December 05, 2011, 06:35:34 PM »
Is this a work network? It would probably make things a lot easier to have a Domain Controller and WSUS. You could probably get away with having them on the same box. It would at least relieve some of the traffic from each computer downloading it's own updates, and definitely make things more manageable for you.
Logged
Put that in your pipe and grep it!
3xban
Hero Member
Offline
Posts: 608
Re: Scanning for missing Microsoft patches
«
Reply #5 on:
December 05, 2011, 07:57:28 PM »
Should be able to run WSUS on a DC so long as you aren't using it for anything else. Hell I've had Small Business Servers running Exchange, DC activity and WSUS along with file and print servers. Of course this goes against everything MS says to do with Servers but then again that is their own product doing it. Ugh, I hate SBS, but it proves how much a single box can do in a small environment. Not to mention it is very affordable for Small Business. Even more so if you are a non-profit. A friend of mine gets enterprise class licensing for a fraction of the cost that a big enterprise would pay. Yay for non-profits!
Once you go with WSUS, you will need to tweak and also make sure you only bring down the languages you need, by default it downloads ALL language packs of the patches.
Logged
Certs: GCWN
(@)Dewser
lorddicranius
Sr. Member
Offline
Posts: 447
Re: Scanning for missing Microsoft patches
«
Reply #6 on:
December 06, 2011, 04:44:42 AM »
Quote from: eth3real on December 05, 2011, 06:35:34 PM
Is this a work network? It would probably make things a lot easier to have a Domain Controller and WSUS. You could probably get away with having them on the same box. It would at least relieve some of the traffic from each computer downloading it's own updates, and definitely make things more manageable for you.
Yep, it's a work network. I'd love to use WSUS and have actually been trying to get this going (among everything else going on here haha). Does this require the machines to log into an Active Directory domain to get the updates? We have a domain setup, but I haven't been able to do anything with policies to prepare it for widespread use (it's currently only used by a few computers in our warehouse for a specific shipping application). A domain environment is something else I've been trying to get going, but it's been difficult with so many personally owned computers being used for business on the network.
Quote from: 3xban on December 05, 2011, 07:57:28 PM
Once you go with WSUS, you will need to tweak and also make sure you only bring down the languages you need, by default it downloads ALL language packs of the patches.
That's good to know, thanks!
«
Last Edit: December 06, 2011, 04:47:50 AM by lorddicranius
»
Logged
GSEC, eCPPT, Sec+
eth3real
Sr. Member
Offline
Posts: 309
Re: Scanning for missing Microsoft patches
«
Reply #7 on:
December 06, 2011, 07:53:36 AM »
Typically, once you setup a Domain Controller and WSUS server, you would make a Group Policy that tells all the workstations on the domain to get updates only from the WSUS server. If many of the computers on your network are personally owned, then it may be difficult to get each person to agree to putting it on the Windows domain, and then there's also the fact that they would not be able to get updates except when they have access to your WSUS server.
Technically, they wouldn't have to login to Active Directory. The workstations could be joined to the domain, make use of the Group Policies, and still use local logins. However, in that case, you could probably just make a registry change on each computer to get updates from your WSUS server instead of going through all the trouble of joining a domain and setting up Group Policies.
It's a matter of "choose your battle."
Logged
Put that in your pipe and grep it!
3xban
Hero Member
Offline
Posts: 608
Re: Scanning for missing Microsoft patches
«
Reply #8 on:
December 06, 2011, 08:26:35 AM »
Microsoft has a good write-up on setting WSUS up as far as the GPO. The GPO is pretty simple though, the hardest part is ensuring the systems report properly. Windows Firewall tends to interfer a little and sometimes if the clients are not patched to a certain level, they don't report properly.
Also there is a server and client troubleshooting tool which comes in very handy when checking your configurations. If you get around to it and need a hand feel free to hit me up directly.
Logged
Certs: GCWN
(@)Dewser
lorddicranius
Sr. Member
Offline
Posts: 447
Re: Scanning for missing Microsoft patches
«
Reply #9 on:
December 06, 2011, 10:09:45 AM »
Quote from: eth3real on December 06, 2011, 07:53:36 AM
If many of the computers on your network are personally owned, then it may be difficult to get each person to agree to putting it on the Windows domain...
This is exactly why a domain environment hasn't been approved. It's not so much how many personally owned laptops, but who uses them...
Quote from: eth3real on December 06, 2011, 07:53:36 AM
Typically, once you setup a Domain Controller and WSUS server, you would make a Group Policy that tells all the workstations on the domain to get updates only from the WSUS server. If many of the computers on your network are personally owned, then it may be difficult to get each person to agree to putting it on the Windows domain, and then there's also the fact that they would not be able to get updates except when they have access to your WSUS server.
Technically, they wouldn't have to login to Active Directory. The workstations could be joined to the domain, make use of the Group Policies, and still use local logins. However, in that case, you could probably just make a registry change on each computer to get updates from your WSUS server instead of going through all the trouble of joining a domain and setting up Group Policies.
I think I've come across how to make the changes in the registry to have them use a WSUS server for updates, but changing registry settings on each and every computer on the network (nearly 200 of them) doesn't sound like much fun. Plus, I've been told that we'll eventually get to a domain environment, so I will be able to end up using a GPO to configure WSUS settings, it's just a matter of "when".
As for getting updates when machines are unable to access a WSUS server. How does this work for mobile users who use business laptops that are configured for a domain? Are you able to configure them to get updates directly from Microsoft if it's unable to access your WSUS? I have this capability with our anti-virus software, that'd be great if a domain-enabled Windows laptop would do that same...
Quote from: eth3real on December 06, 2011, 07:53:36 AM
It's a matter of "choose your battle."
Exactly
Quote from: 3xban on December 06, 2011, 08:26:35 AM
Microsoft has a good write-up on setting WSUS up as far as the GPO. The GPO is pretty simple though, the hardest part is ensuring the systems report properly. Windows Firewall tends to interfer a little and sometimes if the clients are not patched to a certain level, they don't report properly.
Also there is a server and client troubleshooting tool which comes in very handy when checking your configurations. If you get around to it and need a hand feel free to hit me up directly.
Thanks for all these tips on configuring WSUS. These will definitely come in handy and save me a lot of time/stress when we finally get there
Logged
GSEC, eCPPT, Sec+
eth3real
Sr. Member
Offline
Posts: 309
Re: Scanning for missing Microsoft patches
«
Reply #10 on:
December 06, 2011, 10:47:08 AM »
Quote from: lorddicranius on December 06, 2011, 10:09:45 AM
As for getting updates when machines are unable to access a WSUS server. How does this work for mobile users who use business laptops that are configured for a domain?
Not that I'm aware of. I believe my users with laptops only get updates when they're on the corporate network. If they're on the network at least once a week, I would think this is adequate.
There is also the option of having people download from your WSUS server over VPN, or open your WSUS server to the internet for your users, but that makes it a lot more dangerous to have to WSUS and Active Directory on the same box, and your bandwidth would take a hit.
Logged
Put that in your pipe and grep it!
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(30) by
don
Tools
: Symbolic Exploit Assistant project is looking for collaborators
(0) by
galapag0
Greetings
: Hi from the UK
(5) by
prats84
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(9) by
prats84
Network Pen Testing
: Want a challenge? Want a GXPN practice exam?
(0) by
ajohnson
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(1) by
prats84
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.