MBSA ans SUS
Is there a way to configure MBSA so it does not go back to Microsoft to get its updates? I run MBSA on a secure Windows 2000 Active Directory network which also has a SUS server on it. When I run MBSA on a test W/S and use the SUS option, I get an error and it doesn't seem to run the scan properly. The error I get is "Unable to access Security.xml file". I thought that if I used the SUS server option during a scan, that MBSA would use the SUS server to identify which patches were missing on the test W/S. Am I wrong in my thinking? Any thoughts
Thank
Brun Tag: downloads Tag: 52053
Remove administrators from Local Profiles
Can anyone tell me how to prevent the Administrator Group from getting access automatically to any of the profiles under Documents and Settings?? ie. can Documents and Settings be setup such that when a new user logs in, their profile will only have the user and other "selected" users/groups with access to that profile?
I realise that anyone in the Administrators group will (probably) still be able to take ownership of the directory, I am just trying to "deter" prying....
Thanks
John. Tag: downloads Tag: 52051
secure web sites
Can any one help I can not connect to a secure web site using windows XP any
one any ideas I tried the http://support.microsoft.com/?id=261328 but this
didnt help any clues on what else I can do
many thanks
Lynnette Tag: downloads Tag: 52041
** READ THIS BEFORE POSTING - answers to frequently asked questions 2004.05.06
Before you post a question to a Microsoft.public.*.security newsgroup, note
that your question may already be answered below:
Answers to Top Frequently Asked Questions:
http://securityadmin.info
I'm getting an LSASS error message, and/or I have the Sasser virus.
1) Run anti-virus that is configured to download the latest updates every
week or even every day. www.grisoft.com is free anti-virus.
2) You also need to install all the patches for your system software from
http://windowsupdate.microsoft.com, starting with the MS04-011 patch.
Microsoft generally releases security patches on the second Tuesday of more
or less every month. [Theh MS04-011 patch is also available here:
http://www.microsoft.com/technet/security/bulletin/ms04-011.mspx
... though you still want to visit the Windows Update site to get all
patches.]
3) Once you're infected, you may need to download and run a free Sasser
virus removal tool such as the Stinger tool from www.McAfee.com or the free
tool from http://www.microsoft.com/security/incident/sasser.asp
4) You're not running a firewall, or your firewall isn't protecting you.
Running a firewall would have protected you from this. Free firewall
software is available from www.kerio.com, www.zonealarm.com and/or
www.sygate.com
5) You need to do ALL of these things, or you won't have much success.
You should also make sure you get the latest Microsoft patches monthly and
anti-virus updates at least weekly.
My question is not mentioned below. How do I get an answer immediately,
with no waiting?
http://securityadmin.info/faq.htm#moreinfo
See also: http://www.google.com/groups?as_ugroup=microsoft.public.*
See also: http://www.google.com/advanced_group_search
See also: http://www.google.com
I want to post a problem or question to the newsgroup. What info do I need
to post in order to get a correct answer quickly?
http://securityadmin.info/faq.htm#netiquette
I just heard about a new Microsoft security patch update. Where can I get
the patch?
http://windowsupdate.microsoft.com OR
http://www.microsoft.com/technet/security/current.asp
I just installed a Microsoft security patch update, and now my computer is
having problems.
http://securityadmin.info/faq.htm#patchbroke
I received an email from Microsoft / Microsoft Support / Microsoft Internet
Security Center claiming to be a security patch [or comprehensive Internet
Explorer update]. Is this a virus?
http://securityadmin.info/faq.htm#microsoftemail
ALSO NOTE: www.grisoft.com is free antivirus, USE IT.
I received a virus email from a Microsoft email address. Who do I report
this to?
http://securityadmin.info/faq.htm#microsoftemail
I have the RPC Blaster worm "virus," what do I do?
http://www.microsoft.com/security/incident/blast.asp
ALSO NOTE: www.grisoft.com is free antivirus, USE IT.
My computer is giving RPC Remote Procedure Call messages.
There is a TFTP message or file on my computer.
My computer keeps locking up, and/or rebooting, or telling me that it will
reboot in 1 minute.
http://www.microsoft.com/security/incident/blast.asp
ALSO NOTE: www.grisoft.com is free antivirus, USE IT.
Where can I download the Blaster worm / RPC DCOM patch?
http://windowsupdate.microsoft.com OR
http://www.microsoft.com/technet/security/current.asp
I'm having a problem caused by the JDBGMGR.EXE Teddy Bear "virus" hoax, or I
want to replace this file.
http://securityadmin.info/faq.htm#jdbgmgr
I forgot my Windows logon password and can't log in. How do I reset it?
http://securityadmin.info/faq.htm#password
I have a problem or a question with a virus or with antivirus.
http://securityadmin.info/faq.htm#virus
NOTE: www.grisoft.com is free antivirus, USE IT.
Why is Outlook Express blocking my attachments as "unsafe"?
http://securityadmin.info/faq.htm#attachments
How do I stop getting pop-up messages? Or adware? Or spyware?
http://securityadmin.info/faq.htm#pop-ups
How do I block people from viewing adult or objectionable content on a
computer?
http://securityadmin.info/faq.htm#contentfilter
How do I block spam emails?
http://securityadmin.info/faq.htm#spam
There is a Content Advisor password blocking me from certain web sites.
http://securityadmin.info/faq.htm#contentadvisor
How do I delete an FTP folder that a hacker put on my computer and I cannot
delete?
http://securityadmin.info/faq.htm#ftpfolder
Have I been hacked? What do I do if I've been hacked?
http://securityadmin.info/faq.htm#hacked
How do I re-secure a computer that has been hacked?
http://securityadmin.info/faq.htm#re-secure
How do I test or improve the security on my computer to avoid being hacked?
http://securityadmin.info/faq.htm#harden
How do I investigate a suspicious IP address that may be trying to hack me?
http://securityadmin.info/faq.htm#trace
How do I report a hacker?
http://securityadmin.info/faq.htm#reporthacker
How do I use a port scanner or vulnerability scanner to test my security?
http://securityadmin.info/faq.htm#portscanner
How do I encrypt my files and/or hard drive?
http://securityadmin.info/faq.htm#encryption
How do I get a firewall? IDS?
http://securityadmin.info/faq.htm#firewall
I want to use the IPSec filtering or IP filtering feature of Windows to
block certain ports and have a problem or question.
http://securityadmin.info/faq.htm#ipsec
I have a problem or question with the XP ICF firewall.
http://securityadmin.info/faq.htm#icf
I have a problem or question with the IIS URLScan tool.
http://securityadmin.info/faq.htm#urlscan
How do I change the banner on my computer or server to hide what software
version I'm using?
http://securityadmin.info/faq.htm#banner
How do I enable Windows Auditing to tell who logged into Windows or who
accessed a file?
http://securityadmin.info/faq.htm#auditing
How do I inspect and disable programs that start up when Windows starts?
http://securityadmin.info/faq.htm#startup
How do I use RUNAS or let someone use RUNAS to run commands as administrator
without having to type the password?
http://securityadmin.info/faq.htm#runas
How do I let non-administrator users run Defrag or change their IP address?
http://securityadmin.info/faq.htm#runas
My question is not mentioned above. How do I get an answer immediately,
with no waiting?
http://securityadmin.info/faq.htm#moreinfo
See also: http://www.google.com/groups?as_ugroup=microsoft.public.*
See also: http://www.google.com/advanced_group_search
See also: http://www.google.com
I want to post a problem or question to the newsgroup. What info do I need
to post in order to get a correct answer quickly?
http://securityadmin.info/faq.htm#netiquette
Note that this is NOT a full list of all the questions answered in the FAQ.
Chances are, your question has probably already been answered. The complete
FAQ is at:
http://securityadmin.info/faq.htm#contents
I hope this is helpful. Feedback, suggestions and criticism regarding the
FAQ are welcome and may be emailed to me.
kind regards,
Karl Levinson, CISSP, MCSE, MVP
email: levinson_k@despammed.com Tag: downloads Tag: 52034
Could someone explain please : re Sasser and others
Hi,
I have 1 pc running windows 2000 Adv Server and 2 machines running Windows
2000 and Windows XP.
All computers have a virus protection program and all sit behind an ADSL
Router and a 3com Firewall DMZ with all ports blocked except 25.
Q1. If I DON'T install the latest security updates am I vunerable to Sasser
or will the hardware firewall protect me?
Q2. What role exactly does the hardware firewall play in my configuration.
Thanks for any help to clear up this matter in my mind. Tag: downloads Tag: 52029
Application of MS04-011 to NT4W SP6a causes STOP 7B
Anyone seen this issue with application of MS04-011
(Sasser patch and others) on NT4 Workstation with SP6a?
Applied it in a roll out to about 15 machines on our
domain and 20% of them failed to start again with STOP 7B
errors (at which point I stopped the rollout). I need to
try to get these machines up and running, standard
solutions are a pain in the arse without easy access to
the drive and, of course, NT repair never works once
you've got SP6a Hi Encryption installed.
Any ideas would be appreciated.
Thanks,
Freakstone (reply by mail and post if possible, ta) Tag: downloads Tag: 52026
vpn
HI
one of my customer is using nortel vpn , i want o establish a vpn from my windows 2000 server using l2tp/ipsec to the nortel vpn is it possible from windows 2000.
is there any interoperability document between nortel vpn and windows 2000 vpn , any pointer or docs regarding this will help me a lot thanks Tag: downloads Tag: 52025
Someone is scanning your computer
HI,
I have a strange problem. My XP Pro system is connected to DSL all the time
and I have Sygate firewall installed. When I am working on the system,
occasionally I get alerts that somebody is scanning my ports giving a list
of port numbers. Roughtly 2-3 alerts in an hour. The strange part is that
these alerts never come when the system is idle even though the Net
connection is always on.
The source ip address always has the same Net id as mine.
Any ideas what could be happening? I doubt if somebody is actually scanning
my computer.
Thanks for any tips.
Ramesh Tag: downloads Tag: 52024
Getting tons of Low Risk Warnings with Norton
I have been inundated with "Low Risk" warnings under my
Norton Internet Security Program Control and it's driving
me crazy! In order to reduce the number of warnings, the
program suggests 1) Turning on Automatic Program Control
and 2) Running a Program Scan. I have done both and the
messages continue popping up on my screen. Any
suggestions on how to get rid of this continual barrage
of "Low Risk" warnings? Can't find anything in manual or
on Norton site to help me. Thanks for any suggestions
you can give me! Tag: downloads Tag: 52022
Security Update MS03-030 (Direct X buffer overrun))
I am using the Microsoft Baseline Security Analyzer to scan machines on our network. I have several Win2K Machines (Traditional Chinese) machines that show that "1 Security Updates could not be confirmed." Clicking on the Result details link shows that Security Update MS03-030 has not been installed. However, when I download the Security Update and it installs it, the installer tells me that the update can be applied only to DirectX 8.x and that the update is already included in the version I have installed (DirectX 9.0b).
Am I at risk for this security hole if I have DirectX 9.b installed? Can I ignore the 'Severe Risk' assessment for these machines? Is there any way to make this assessment go away
TIA Tag: downloads Tag: 52021
ie tools menu was changed
Hi
I was out of town for two weeks and somehow one line on the tools menu was changed. I think it was "Messenger" to some foreign language - I cannot read it. If I click - it delivers porno, damn..
Can someone help? How to get rid of it? Tag: downloads Tag: 52020
Windows update error
Having problems on my laptop. Everytime I attempt to
update windows (www.microsoft.com) I receive an error
message. No description. (WINDOWS UPDATE ERROR) Help. Tag: downloads Tag: 52015
Using xp firewall/ Crazy things going on!!
I'm experiencing some mous problems. Sometimes I'll try to click on a link and it won't do anything. Now if I close the web page and come back to it , I'm then able to click on a link, and its not all links that I'm unable to see, just some
I went to a link here on microsofts web page (security) to check for sasser worm. It said I wasn't enfected
what I'm curious about is 1: Does my internet provider also provide me with a firewall and 2: should I, and can I, without making it impossible to navigate the internet, enable my Xp firewall for added protection.
I'm also wondering if i should download this sasser patch everybodys talking about even though I don' have the worm yet
I've got the latest AVG control center, and it updates regularly and my AVG runs every night just like clockwork
In reference to my computer acting up. I'v recently disenfected it from a trojan worm as of a week ago.
I'd say my AVG is working profishiantly
can someone help Thanks Tag: downloads Tag: 52014
office 2000
everytime I tried to install office 2000 it gives me an error 1933. I tried the suggested instructions that were listed on this site but I still get the error. Please help! Tag: downloads Tag: 52012
XP Firewall
I've been using the McAfee Personal Firewall since I
bought my pc about a year and a half ago. I was also
running McAfee Viruscan up until this past weekend but
decided to get Norton (again) since it seems to run
better on my pc. I just uninstalled the firewall and
enabled the XP firewall. Is the XP firewall any good?
Will I get the same (or good enough) protection from it
that I was getting from McAfee?
Now I know with McAfee and other firewalls you can change
the programs that have access to the "outside world",
which came in handy every now and then. Is it possible to
view and change the programs or settings with the XP
firewall?
I DID run a hacker test from the Norton website and it
said that I was protected from all threats but I'm still
kinda "iffy".
My pc is just used at home, not for anything important
but playing blackjack, paying bills, reservations, dirty
pictures... the basic home user stuff. I just wanna make
sure that I'm safe. Tag: downloads Tag: 52010
abnormal traffic going out after applying the windows update and office update
Hi
our PCs using win2000 pro w/sp4 and office xp w/sp3.
Recently, on 20 April and 3 May, we applied the windows
updates and office xp updates over the web. AFter that we
discovered abnormal traffic sent out every 10 minutes
from the PCs which were applied the updates. This 10
minutes seems hardened on somewhere and cannot be changed
even I set the clock of the PC. The abnormal traffic
started to sent out 10 minutes after the PC start up and
continue to sent until the PCs was shutdown. This traffic
trying to go to many different IP addresses and are all
go to 129.x.x.x network. I have used symantec antivirus
7.5.1 with latest virus definition (5/5/2004)to scan
those PCs but no virsu was found.
Below is a traffic denied by the firewall:
cifs[623378450]: access denied for xxx.xxx.xxx.xxx to
129.133.164.224 [default rule] [no rules found]
Statistics: duration=0.48 id=4lh98 srcif=Vpn3
src=xxx.xxx.xxx.xxx/1040 svsrc=yyy.yyy.yyy.yyy dstif=Vpn4
dst=129.133.164.224/139 proto=cifs (Access denied)
some of the destination site:
129.133.164.224
129.77.42.8
129.66.122.232
129.101.12.104
129.61.184.104
129.56.98.200
129.64.177.136
129.63.190.8
129.67.94.232
129.62.145.40
129.62.216.72
129.53.206.8
some-darbishire.some.ox.ac.uk
ingw129-37-64-40.ny.us.prserv.net
stu0073.keble.ox.ac.uk
micron.ece.northwestern.edu
Wireless.campus.uidaho.edu
ath102311.utep.edu
v1006ash208.sju.edu
A235168.N1.Vanderbilt.Edu
Any expert can help me to solve the problem?
Many many thanks Tag: downloads Tag: 52009
need help please
I've noticed lately that my computer has been acting
strange. It seems almost as if someone else is controling
my computer in the backgroud. For example after a few
minutes of inactivity my screen saver will come on, and a
few minutes later the screen saver will stop and the main
desktop screen comes back on. It doesn't make scence for
this to occure since no one is working at the computer. I
scanned for computer viruses with Norton Antivirus 2002
and found none. It even has the newest virus definitions
and updates installed. I also scanned my computer for
spyware with Spybot Search & Destroy and found nothing.
It too was up to date. I have Windows XP firewall enabled
along with Norton's Personal Firewall. Any suggestions as
to what could be causing my screen saver to stop and the
main desktop screen to come back on for no reason? Please
email me. flowmaster85@charter.net Tag: downloads Tag: 52004
Virus I recieved by uploading from Microsoft - Hehlp
I recieved a trojan from downloading upgrades to windows
XP HE. the trojan is in my start up. my antivirus
programs are not getting rid of it. if anyone has had
this problem or can help me, please E-mail me at
YesReasons@aol.com. Tag: downloads Tag: 51998
Site unavailable - windows 2000 pro
I am not able to access secure sites since my latest
critical update. What settings might have changed in the
update to cause this? Tag: downloads Tag: 51992
What is mWinXp ,mWinXpD, mWinXpD2
While I was working last night these three new files
appeared in my windows 98 file area What are the files
mWinXp, mWinXpD, and mWinXpD2 are they form Microsoft? Or
are they some sort of Virus? And if they are from
Microsoft will they cause problems because they are meant
for Xp and I have windows 98 thank you.
Glen Tag: downloads Tag: 51988
Repeating Updates
Using Automatic Updates on WinXP Pro. Received KB835732
and installed it. Every time I go on line, it downloads
again. Any suggestions? Tag: downloads Tag: 51987
dloading updates
I get the message when dloading security updates (Security
Update for Windows XP (KB837001)Security Update for
Windows XP (KB828741)Security Update for Windows XP
(KB835732))
"this software has not passed windows logo testing yada
yada" and then a warning about continuinng to install the
updates and then they fail to install. Is it possible
updates from microsoft would give such an error msg?? Tag: downloads Tag: 51985
VIRUS THREAT
I WAS CHECKING MY EMAIL AND CAME ACROSS THE FOLLOWING=20
THREAT, THIS IS BOGUS, IT CONTAINS A W32.Swen.A virus
X-Apparently-To: shadowcat624@yahoo.com via 66.218.93.78;=20
Wed, 05 May 2004 01:39:47 -0700=20
Return-Path: <benecastan@terra.es>=20
Received: from 213.4.129.129 (EHLO tsmtp4.mail.isp)=20
(213.4.129.129) by mta173.mail.dcn.yahoo.com with SMTP;=20
Wed, 05 May 2004 01:39:42 -0700=20
Received: from njdts ([213.97.6.187]) by tsmtp4.mail.isp=20
(terra.es) with SMTP id HX8G1G00.A0F; Wed, 5 May 2004=20
10:39:16 +0200 =20
From: "MS Program Security Center"=20
<mpreekhiolnybzg@pvnfoayc.microsoft.net> Add to Address=20
Book=20
To: "Commercial Client" <client@pvnfoayc.microsoft.net>=20
Subject: latest microsoft pack=20
Mime-Version: 1.0=20
Content-Type: multipart/mixed; boundary=3D"qpzvbkgmsukl"=20
Content-Length: 58661=20
=20
=20
Microsoft All Products | Support | Search | =20
Tiscalinet.it Guide =20
TiscaliSEXHome =20
=20
Microsoft Client
this is the latest version of security update, the "May=20
2004, Cumulative Patch" update which fixes all known=20
security vulnerabilities affecting MS Internet Explorer,=20
MS Outlook and MS Outlook Express. Install now to protect=20
your computer from these vulnerabilities, the most serious=20
of which could allow an attacker to run executable on your=20
computer. Questo programma consente al vostro PC of all=20
previously released patches. =20
System requirements Windows 95/98/Me/2000/NT/XP=20
This update applies to MS Internet Explorer, version=20
4.01 and later
MS Outlook, version 8.00 and later
MS Outlook Express, version 4.01 and later =20
Recommendation Customers should install the patch at the=20
earliest opportunity.=20
How to install Run attached file. Choose Yes on displayed=20
dialog box.=20
How to use You don't need to do anything after installing=20
this item.=20
TISCALI Product Support Services and Knowledge Base=20
articles can be found on the Tiscali Technical Support web=20
site. For security-related information about TISCALI=20
products, please visit the Tiscali Security Advisor web=20
site, or Contact Us.=20
Thank you for using TISCALI products.
Please do not reply to this message. It was sent from an=20
unmonitored e-mail address and we are unable to respond to=20
any replies.
-----------------------------------------------------------
---------------------
The names of the actual companies and products mentioned=20
herein are the trademarks of their respective owners. =20
Contact Us | Legal | TRUSTe =20
=A92004 TiscalinetCorporation. All rights reserved. Terms=20
of Use | Privacy Statement | Accessibility =20
Attachment =20
=20
=20
=20
=20
upgrade7524.exe
.exe file
Scan and Download Attachment
Scan and Save to my Yahoo! Briefcase=20
Scan Results [Back to Message] =20
File name: upgrade7524.exe=20
File type: application/x-msdownload=20
Scan result: Virus "W32.Swen.A@mm" found.
You can not download this attachment. You have two=20
options:=20
1. Sign up for Yahoo! Mail Plus to get automatic cleaning=20
of infected attachments. Learn more.
(Note: Not all viruses can be cleaned.)=20
2. Contact the message sender and request that they resend=20
the attachment to you after cleaning it with anti-virus=20
software=20
=20
=20
=20 Tag: downloads Tag: 51977
I need help with kazaa media desktop 2.6
I downloaded kazaa, and when i tried to uninstall it, it
seemed to go fine and i thought it was gone. I restarted
the computer and it was back on the add/remove programs
list. I tried to uninstall it again, and I had a problem.
I got the following message, "InstallShield (R) Setup
Launcher has encountered a problem and needs to close. We
are sorry for the inconvenience." I searched the hard
drive for files concerning kazaa and found none. I need
some suggestions on how to deal with this problem. Tag: downloads Tag: 51972
DO I NEED TO DO ANYTHING ELSE TO KEEP MY COMPUTER W/OUT ANY VIRUSES
I am currently running an antivirus ---- McAfee do I need to add or download anything else to keep my computer safe form viruses. I heard there are some things in your web page you can load to keep your Microsoft programs without any viruses. What are they if there are any and how do I know if I have them or if I need to install them or how do I even get them if they are not installed? Oh, I am currently using Windows XP. Thanks for the help before hand. Tag: downloads Tag: 51969
security web
PLEASE PLEASE HELP I can not open a security web page it keeps coming up web
page not found I am using windows xp if that helps many thanks in advance
Lynnette Tag: downloads Tag: 51962
MS04-011 on DELL CPxJ corrupts video?
Running NT4 SP6a after installing the patch, the video is
corrupted and will only run using the default VGA drivers.
Removing / reinstalling drivers doesn't fix. the only way
to get it to work is by removing the patch.
This is a DELL Lattitude CPxJ, NT4, SP6a, ATI Rage
Mobility video.
Please help! Tag: downloads Tag: 51954
MSSQL Stack Overflow?
Hi:
My Norton Firewall blocks this message numerous times a
day. B4 this same companies were blocked with another
message having to do with backdoor ports. anyone having
similar problems, and should i be concerned. ? Should I
restore my computer back a month or so? Thx Tag: downloads Tag: 51952
AVOID THESE LIKE THE PLAGUE!
If you need to protect your computer from malware
(unwanted pop-ups from software installed on your
computer, browser/homepage hijackings, dialers,
keyloggers, etc.), then please get Ad-Aware, Spybot Search
& Destroy and some others; they are REPUTABLE!
However, do NOT get the following; they are programs that
SAY they will protect you, but have been found by various
websites/individuals to actually HARM your computer!
Notice some have similar names to the REPUTABLE programs
like the fantastic Ad-Aware, Spybot, SpywareBlaster, etc.
So...
AVOID THESE LIKE THE PLAGUE:
Spy Wiper
AdWare Remover Gold
BPS Spyware Remover
Online PC-Fix SpyFerret
SpyBan
SpyBlast
SpyGone
SpyHunter
SpyKiller
SpyKiller Pro
SpywareNuker
TZ Spyware-Adware Remover
SpyAssault
InternetAntiSpy
Virtual Bouncer
AdProtector
SpyFerret
SpyGone
SpyAssault
Pal Spyware Remover
NoAdware
Spyware Killa
Scanspyware
ALSO: XP Antispy is LEGIT, however, their former domain
was taken over by someone who's pushing a dialer and
trying to pass it off as XP Antispy. My suggestion: avoid
XP Antispy for now to be on the safe side! You never know
which one you are getting!
If anyone else has anything to add to the list, feel free
but make sure it deserves the "recognition" (in other
words, don't put it here because you "don't like it"; put
it here because a reputable researcher found it to be bad).
And please, send this list to all your friends/co-workers
so the word spreads about these programs that will do
NOTHING but harm your computer and betray your trust. Tag: downloads Tag: 51927
Manually installed patches do not show up
1) When I Download&Save updates/patches for our current
corporate configuration (Office 97, and Outlook2K) and
manually install them (successfully) When I check using
the automatic install, M/S say's that these
patches/updates need to be installed.
What's going on? Do I have to use the automatic installer
from the internet for every client PC ? Tag: downloads Tag: 51922
lsass.exe, problems after applying ms04-11
Hello,
I had several calls concerning the patch ms04-11 needed
for the sasser. There are articles about the problems
related to it, but nothing's talking about printers
malfunctioning. Anybody had similar problems? I asked
the local support people to reinstall the printers with
the drivers to see if the problem persists. Tag: downloads Tag: 51916
Sasser: How critical is "not critical"
From
http://www.microsoft.com/technet/security/bulletin/ms04-011.mspx
Are Windows 98, Windows 98 Second Edition, or Windows Millennium Edition
critically affected by any of the vulnerabilities that are addressed in this
security bulletin?
No. None of these vulnerabilities are critical in severity on Windows 98, on
Windows 98 Second Edition, or on Windows Millennium Edition.
Any comment welcome. Tag: downloads Tag: 51915
Help with MS Baseline Security Analyzer
I am somewhat confused by the results of a scan I just ran with the MS
Baseline Security Analyzer. It is telling me that two security updates
are out of date and 3 could not be confirmed as follows:
MSXML 3 lacks the latest service pack SP 4
MSXML 4 lacks the latest service pack SP 2
MS)#-008
MS03-030
MS03-051
Yet when I run Windows Update it tells me there are no critical
updates to be installed? Exactly what are the MSXML service packs and
what do they do? Where can they be found to download?
Can some kind soul explain what is happening and should I attempt to
download and install the above updates even though Windows Update
doesn't recognize the need?
Thanks for any assistance.
Frank Tag: downloads Tag: 51914
Possible security threat - Passport and Sympatico.ca users
If you receive the following email, you may be at risk
from a malicious attack if you follow the instructions
contained within. Can anyone verify the validity of this
email?:
---------------------------
-----Original Message-----
From: Microsoft .NET Passport
[mailto:PPMSVCMG@PASSPORT.NET]
Sent: May 5, 2004 12:15 AM
To:
Subject: Important message from Microsoft .NET Passport -
action
required
Hello :
This is an important message from Microsoft concerning
the Microsoft .NET Passport account associated with your
sympatico.ca e-mail address.
Both Microsoft and Bell Canada are committed to
simplifying your online experience. Therefore we are
taking efforts to ensure that active Bell Sympatico
Internet customers can continue to use the .NET Passport
that is associated with their sympatico.ca e-mail
address.
Since there is a Passport account associated to your
Sympatico e-mail address, we ask that you please verify
that you are the user of the Passport account and that
you give consent to Bell Canada to manage your
Microsoft .NET Passport account. It's a quick and easy
process to verify your account.
Instructions on how to verify your account are below, as
well as some important questions and answers.
To verify your Passport account:
1. In your Web browser, type passport.net in the
Address bar and press Enter.
2. On the Passport home page, click the Sign In
button, and sign in to your Passport account.
3. Follow the instructions to verify your e-mail
address.
If you did not register the Passport using this e-mail
address, or if you do not agree to give Bell Canada
consent to manage your Passport account, take no action,
and we will disable the Passport account 20 days from the
date this message was sent. This will have no affect on
your Sympatico subscription or sympatico.ca e-mail
address.
To request additional help from Passport Customer
Support, click
http://register.passport.net/contactus.srf?LC=1033.
Important Questions and Answers
What is a .NET Passport account?
Microsoft .NET Passport is a service that enables you to
sign in to multiple services, such as MSN Messenger or
Hotmail, with a single e-mail address and password. For
more information, visit the Passport home page at
http://www.passport.net.
I don't have a Passport account. Why am I seeing this
message?
Another person may have created a Passport account with
your current sympatico.ca e-mail address (such as a
family member, or an individual who had the e-mail
address before you). This does not mean that the user has
access to your e-mail messages or any other personal
information - it simply means that they have used the e-
mail address as a sign-in name for their Passport account.
If this is the case, you can ignore this e-mail message
and do nothing, and 20 days from the date this message
was sent, we will disable the user from using your e-mail
address as their Passport sign-in name.
What does it mean to give consent to Bell Canada to
manage my sympatico.ca .NET Passport?
As the owner of the sympatico.ca domain, Bell Canada
assigns sympatico.ca e-mail addresses. In addition,
sympatico.ca is now a 'sponsored domain' which is
associated with a special kind of .NET Passport where
Bell Canada will ensure only Bell Sympatico Internet
customers can obtain sympatico.ca .NET Passports.
What happens if I don't verify my e-mail address or give
Sympatico consent to manage my Passport account?
After 20 days from the date this e-mail message was sent,
if you have not yet verified your e-mail address with
Passport, you will no longer be able to sign in to any
Passport participating site until you change the e-mail
address in your Passport account.
In addition, you will lose data associated with your
Passport sign-in e-mail address, such as your MSN
Messenger contact list.
No matter what your decision is, your existing Sympatico
subscription and e-mail account will not be affected.
Only your Passport account will be affected.
ADDITIONAL INFORMATION:
Passport is committed to protecting your privacy. We
encourage you to review the Passport privacy statement
at:
http://www.passport.net/privacypolicy.asp
To request additional help from Passport Customer
Support, click
http://register.passport.net/contactus.srf?LC=1033
Please do not reply to this message; it was sent from an
unmonitored e-mail address and we are unable to respond
to any replies. Tag: downloads Tag: 51913
SUS require admin previlegies on client to install
No, that's right, I do not want the users to be admins.
But if the not are admins, no security patches from the
SUS server will be installed.
Solution?
<- Christer ->
>-----Original Message-----
>Christer wrote:
>> Is it possible to install security patches from a SUS
>> server without having admin previlegies on the client?
>>
>> Today all XP users are administrators on there own
>> computers to get updates from the SUS server installed.
>
>If you want the best from SUS, you want the end users to
NOT be admins.
>
>--
><- Shenan ->
>-- Tag: downloads Tag: 51912
Re: Problems with installing Security patch Q837009
Hi Bill,
Thanks for the reply post!
Having looked at the version installed in Help (as you suggested) it shows
version 6.00.280.1123. This would mean that I am running OE6 with IE
version 6.0.2800.1106.xpsp2.030422-1633.
Do either of these versions have flaws that make them incompatible? Both
are updated via Microsoft Official Updates site and I have no problems
updating from the site. My problem seems to come when installing individual
patches...
alba.
"Bill Sanderson" <Bill_Sanderson@msn.com.plugh.org> wrote in message
news:%23mrP3EkMEHA.2532@TK2MSFTNGP10.phx.gbl...
When you go to Help, about, in Outlook Express--what version number is
displayed?
It is possible to be running Outlook Express 5.x and IE 6, because of a flaw
in the upgrade process. It is important to fix this because the older OE
has some bugs which are not getting patched.
"alba" <alba1314@ntlworld.com> wrote in message
news:%23Tg4bTgMEHA.3944@tk2msftngp13.phx.gbl...
I am running Windows XP Pro and Internet Explorer 6, along with Outlook
Express 6 and am having problems installing Security patch Q837009.
Each time I try to install the patch I get a Microsoft Internet Explorer
Update message telling me that Outlook Express 6.0 needs to be installed -
Surely OE6 is part of IE6 and therefore installs when Windows is installed??
I have tried to download OE 6.0 as a separate download from IE and on trying
to install it I am told that I have a newer version already on my PC!
This is not the first time that I have experienced problems with installing
patches relating to Outlook Express - The problem seems to occur whenever I
download and install individual patches. Whenever I download and install
patches using Critical Updates on the Microsoft Update site, I don't seem to
have this problem.
Can anyone advise why this happens?
alba.
---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.677 / Virus Database: 439 - Release Date: 04/05/2004 Tag: downloads Tag: 51910
Sasser virus
I read alot about this Vasser worm or virus and that
Microsoft has a patch for it. I run Windows update and
there are no updates available for my system. Windows ME.
I then check my install history for updates and the patch
for this Sasser MS835732 does not show as being installed.
I have Works Suite 2000.
Should I manually install this patch or just forget about
it. I don't appear to be infected.
Thanks Tag: downloads Tag: 51908
Scanning tool?
I wanted to ask everyone in the group what they are using to track trends
caused by for example the sasser worm. Is anyone using a tool that can track
machines that are trying to spam segments of a network or at least could
send notifications of a pattern?
TIA... Tag: downloads Tag: 51906
** READ THIS BEFORE POSTING - answers to frequently asked questions 2004.05.05
Before you post a question to a Microsoft.public.*.security newsgroup, note
that your question may already be answered below:
Answers to Top Frequently Asked Questions:
http://securityadmin.info
I'm getting an LSASS error message, and/or I have the Sasser virus.
1) Run anti-virus that is configured to download the latest updates every
week or even every day. www.grisoft.com is free anti-virus.
2) You also need to install all the patches for your system software from
http://windowsupdate.microsoft.com, starting with the MS04-011 patch.
Microsoft generally releases security patches on the second Tuesday of more
or less every month.
3) Once you're infected, you may need to download and run a free Sasser
virus removal tool such as the Stinger tool from www.McAfee.com or the free
tool from http://www.microsoft.com/security/incident/sasser.asp
4) You're not running a firewall, or your firewall isn't protecting you.
Running a firewall would have protected you from this. Free firewall
software is available from www.kerio.com, www.zonealarm.com and/or
www.sygate.com
5) You need to do ALL of these things, or you won't have much success.
You should also make sure you get the latest Microsoft patches monthly and
anti-virus updates at least weekly.
My question is not mentioned below. How do I get an answer immediately,
with no waiting?
http://securityadmin.info/faq.htm#moreinfo
See also: http://www.google.com/groups?as_ugroup=microsoft.public.*
See also: http://www.google.com/advanced_group_search
See also: http://www.google.com
I want to post a problem or question to the newsgroup. What info do I need
to post in order to get a correct answer quickly?
http://securityadmin.info/faq.htm#netiquette
I just heard about a new Microsoft security patch update. Where can I get
the patch?
http://windowsupdate.microsoft.com OR
http://www.microsoft.com/technet/security/current.asp
I just installed a Microsoft security patch update, and now my computer is
having problems.
http://securityadmin.info/faq.htm#patchbroke
I received an email from Microsoft / Microsoft Support / Microsoft Internet
Security Center claiming to be a security patch [or comprehensive Internet
Explorer update]. Is this a virus?
http://securityadmin.info/faq.htm#microsoftemail
ALSO NOTE: www.grisoft.com is free antivirus, USE IT.
I received a virus email from a Microsoft email address. Who do I report
this to?
http://securityadmin.info/faq.htm#microsoftemail
I have the RPC Blaster worm "virus," what do I do?
http://www.microsoft.com/security/incident/blast.asp
ALSO NOTE: www.grisoft.com is free antivirus, USE IT.
My computer is giving RPC Remote Procedure Call messages.
There is a TFTP message or file on my computer.
My computer keeps locking up, and/or rebooting, or telling me that it will
reboot in 1 minute.
http://www.microsoft.com/security/incident/blast.asp
ALSO NOTE: www.grisoft.com is free antivirus, USE IT.
Where can I download the Blaster worm / RPC DCOM patch?
http://windowsupdate.microsoft.com OR
http://www.microsoft.com/technet/security/current.asp
I'm having a problem caused by the JDBGMGR.EXE Teddy Bear "virus" hoax, or I
want to replace this file.
http://securityadmin.info/faq.htm#jdbgmgr
I forgot my Windows logon password and can't log in. How do I reset it?
http://securityadmin.info/faq.htm#password
I have a problem or a question with a virus or with antivirus.
http://securityadmin.info/faq.htm#virus
NOTE: www.grisoft.com is free antivirus, USE IT.
Why is Outlook Express blocking my attachments as "unsafe"?
http://securityadmin.info/faq.htm#attachments
How do I stop getting pop-up messages? Or adware? Or spyware?
http://securityadmin.info/faq.htm#pop-ups
How do I block people from viewing adult or objectionable content on a
computer?
http://securityadmin.info/faq.htm#contentfilter
How do I block spam emails?
http://securityadmin.info/faq.htm#spam
There is a Content Advisor password blocking me from certain web sites.
http://securityadmin.info/faq.htm#contentadvisor
How do I delete an FTP folder that a hacker put on my computer and I cannot
delete?
http://securityadmin.info/faq.htm#ftpfolder
Have I been hacked? What do I do if I've been hacked?
http://securityadmin.info/faq.htm#hacked
How do I re-secure a computer that has been hacked?
http://securityadmin.info/faq.htm#re-secure
How do I test or improve the security on my computer to avoid being hacked?
http://securityadmin.info/faq.htm#harden
How do I investigate a suspicious IP address that may be trying to hack me?
http://securityadmin.info/faq.htm#trace
How do I report a hacker?
http://securityadmin.info/faq.htm#reporthacker
How do I use a port scanner or vulnerability scanner to test my security?
http://securityadmin.info/faq.htm#portscanner
How do I encrypt my files and/or hard drive?
http://securityadmin.info/faq.htm#encryption
How do I get a firewall? IDS?
http://securityadmin.info/faq.htm#firewall
I want to use the IPSec filtering or IP filtering feature of Windows to
block certain ports and have a problem or question.
http://securityadmin.info/faq.htm#ipsec
I have a problem or question with the XP ICF firewall.
http://securityadmin.info/faq.htm#icf
I have a problem or question with the IIS URLScan tool.
http://securityadmin.info/faq.htm#urlscan
How do I change the banner on my computer or server to hide what software
version I'm using?
http://securityadmin.info/faq.htm#banner
How do I enable Windows Auditing to tell who logged into Windows or who
accessed a file?
http://securityadmin.info/faq.htm#auditing
How do I inspect and disable programs that start up when Windows starts?
http://securityadmin.info/faq.htm#startup
How do I use RUNAS or let someone use RUNAS to run commands as administrator
without having to type the password?
http://securityadmin.info/faq.htm#runas
How do I let non-administrator users run Defrag or change their IP address?
http://securityadmin.info/faq.htm#runas
My question is not mentioned above. How do I get an answer immediately,
with no waiting?
http://securityadmin.info/faq.htm#moreinfo
See also: http://www.google.com/groups?as_ugroup=microsoft.public.*
See also: http://www.google.com/advanced_group_search
See also: http://www.google.com
I want to post a problem or question to the newsgroup. What info do I need
to post in order to get a correct answer quickly?
http://securityadmin.info/faq.htm#netiquette
Note that this is NOT a full list of all the questions answered in the FAQ.
Chances are, your question has probably already been answered. The complete
FAQ is at:
http://securityadmin.info/faq.htm#contents
I hope this is helpful. Feedback, suggestions and criticism regarding the
FAQ are welcome and may be emailed to me.
kind regards,
Karl Levinson, CISSP, MCSE, MVP
email: levinson_k@despammed.com Tag: downloads Tag: 51903
Accesing data from a slaved hard drive
Hi
We have a little problem - a customer's system no longer
boots up and he needs the data from it (No backups- of
course). We are trying to put it onto another system as a
slave drive (like with 95/98/ME) but windows will not
allow access -displays 'Access Denied' when you try and
open the customers personal data.
My question is - is there any way round this? Or is the
data no effectivly lost.
(Just for info - the HDD and data is fine, it just won't
boot!)
Thanks In Advance
Jamie Tag: downloads Tag: 51902
iareghn
what is this eating up my files poping on screen
file call Iarghn cant find the file on my pc just
show up then dipp aging Tag: downloads Tag: 51900
SUS require admin previlegies on the client
Is it possible to install security patches from a SUS
server without having admin previlegies on the client?
Today all XP users are administrators on there own
computers to get updates from the SUS server installed.
Regards,
Christer Johansson Tag: downloads Tag: 51895
Office/Active Directory Compatibility?
I run a network with 40 machines, at the moment we have an
older version of office (2000) running on a Win 2000
server driven network and a mixture of 2000 and XP
workstations.
Although the active directory lets me set options on win
explorer to limit access to files and folders the settings
do not apply to the explorer plug-in built into office.
This allows staff to browse other area of the netwok
wihout permissions.
If I upgrade to office 2003 will there be a better
integration with active directory, or are there any other
ways of securing the office explorer?
Mnay Thanks
Dave Tag: downloads Tag: 51894
CA Enterprise SCEP-Add on
Hi
I have a CA Enterprise (2003) in a 2003 Active Directory Domain. I have installed the SCEP-Add on to enroll a certificate to a PIX 525 (Ver. 6.32). When I make a request, from the PIX console, to enroll a certificate, it is rejected by the CA with this message: denied by policy module
I had read that there is a different configuration with "SCEP-Add on" in a CA Enterprise. I need to kno
which are the steps needed to configure SCEP-Add on in a CA Enterprise. The "SCEP-Add on" release note tells that these steps are described in Windows 2003 Resource Kit Documentation, but i didn't found them
Thanks in advanc
Paolo Tag: downloads Tag: 51891