14 Guests, 0 Users
Welcome, Guest. Please login or register.
Did you miss your activation email?
February 10, 2012, 02:26:58 am

Login with username, password and session length

Author Topic: Major XP, 2003, 2000 vulnerability found, patch yer stuff!  (Read 449 times)

Offline Stormgren

  • =-[kI]-= Elder
  • *
  • Posts: 131
  • Justice! +12/-1
  • F10 Mastah
    • My L4D server stats
Major XP, 2003, 2000 vulnerability found, patch yer stuff!
« on: October 24, 2008, 10:16:12 am »

Article is here:  http://www.securityfocus.com/brief/844

Advisory is here:  http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx

Figured I'd help spread the word, this looks like another nasty one.



For a good time, call 989-272-7425
My Left4Dead Server status pages: http://chavez.bendorius.net/l4d

Offline anomaly

  • wtf?
  • =-[kI]-= Elder
  • *
  • Posts: 4943
  • Justice! +50/-15
  • looking for the path of least resistance...
Re: Major XP, 2003, 2000 vulnerability found, patch yer stuff!
« Reply #1 on: October 24, 2008, 10:40:45 am »
thanks.... notified my IT manager

installing patch now....
Doughnut?

Offline BoneyOne

  • =-[kI Clan]-=
  • *
  • Posts: 277
  • Justice! +4/-0
Re: Major XP, 2003, 2000 vulnerability found, patch yer stuff!
« Reply #2 on: October 24, 2008, 12:54:53 pm »
Yah....fun stuff. I got to poke fun at my girlfriend (she's a Windows Server Admin) about it (I use Linux for pretty much everything) when she started telling me how she (and her team of 3 others) have to patch some 230 servers at her work.

 :2funny:

Offline DAwG

  • =-[kI Clan]-=
  • *
  • Posts: 2219
  • Justice! +33/-61
Re: Major XP, 2003, 2000 vulnerability found, patch yer stuff!
« Reply #3 on: October 24, 2008, 01:24:35 pm »
shouldn't be too hard, that can easily be accomplished remotely

Offline BoneyOne

  • =-[kI Clan]-=
  • *
  • Posts: 277
  • Justice! +4/-0
Re: Major XP, 2003, 2000 vulnerability found, patch yer stuff!
« Reply #4 on: October 24, 2008, 03:09:30 pm »
Nah, not hard at all. Just takes time out of ones weekend to remote into the servers install the patch, reboot them, make sure all the services and programs needed start like they should. So your probably talking for her at least 5-6 hours total out of her weekend she has to spend remoted in to work doing updates.

Of course Linux has it's need for updates too though. Just fun to pick on her about it all.

I'm curious just how many people and company's out there aren't going to get their systems patched and a new worm gets released taking advantage of this hole.

Offline Stormgren

  • =-[kI]-= Elder
  • *
  • Posts: 131
  • Justice! +12/-1
  • F10 Mastah
    • My L4D server stats
Re: Major XP, 2003, 2000 vulnerability found, patch yer stuff!
« Reply #5 on: October 24, 2008, 04:47:12 pm »
shouldn't be too hard, that can easily be accomplished remotely

Have you ever had to patch that many servers by hand via remote desktop?  While the actual steps aren't that hard, it's a massive pain in the ass to make sure you didn't miss something.  It's not trivial by any means.

Better to shove the patch to a WSUS server and let that do all the heavy lifting for you.  :)
For a good time, call 989-272-7425
My Left4Dead Server status pages: http://chavez.bendorius.net/l4d

Offline DAwG

  • =-[kI Clan]-=
  • *
  • Posts: 2219
  • Justice! +33/-61
Re: Major XP, 2003, 2000 vulnerability found, patch yer stuff!
« Reply #6 on: October 24, 2008, 06:25:44 pm »
we were doing it on a much smaller scale on vmware.  Just roll it out to the various groups via the DC and tell them to update, I already forgot how to do it though, in one ear out the other  :rolleyes:
« Last Edit: October 24, 2008, 06:27:28 pm by DAwG »

Offline Harry Lee Smith

  • Witty Custom Title
  • =-[kI Clan]-=
  • *
  • Posts: 2037
  • Justice! +17/-6
  • I reject your reality and substitute my own.
Re: Major XP, 2003, 2000 vulnerability found, patch yer stuff!
« Reply #7 on: January 09, 2009, 02:54:46 pm »
Ever hear of WSUS????