Subscribe to Windows IT Pro

 

Get Newsletters

  • Get the Latest News
  • Product Updates
  • Helpful Tricks
  • Productivity Tips

Subscribe Now!

April 01, 1999 12:00 AM

Managing Service Packs and Hotfixes

Windows IT Pro
InstantDoc ID #4996
Rating: (0)
Keep your network up-to-date and secure without burning the midnight oil

Microsoft recently responded to several new security holes in Windows NT. Some of these security holes required only a configuration change to protect the system, but many required Microsoft service packs or hotfixes.

Security experts estimate that patches (i.e., configuration changes, service packs, or hotfixes) are available for over 90 percent of system breaches that occur. Security suffers if you don’t apply patches in a timely manner. You can reduce your risk by keeping up-to-date with new exploits and their patches. However, managing service packs and hotfixes is daunting when you have hundreds or thousands of systems to maintain. For example, Microsoft often releases, updates, and removes hotfixes at its FTP sites without informing users. Documentation regarding hotfix installation and cumulative compatibility is sometimes contradictory and confusing. In addition, native NT functionality doesn’t permit easy distribution of updates to multiple computers. To further complicate matters, some hotfixes require you to make risky Registry changes to activate the patch’s functionality. Even simple hotfixes can destabilize systems and introduce new bugs. Finally, obtaining enterprisewide reports on current update levels is difficult, and total cost of ownership (TCO) soars when you maintain systems at wildly disparate update levels.

Without an easy method for administering patches, your costs increase and your security and stability suffer. In this article, I discuss how you can securely manage updates by using simple batch files, NT’s native tools, and inexpensive or free tools and services that are available on the Internet. The process involves discovery, evaluation, testing, deployment, and tracking. (For more information about service packs and hotfixes, see "Related Articles in Windows NT Magazine.")

Discovery
A proper discovery process depends on your level of specialization and responsibility in security matters. In the past, systems administrators often waited until they ran into a problem before they looked for a patch. But current security demands necessitate a proactive approach: You must search for fixes before you need them.

For years, UNIX users have had security bulletin services such as the Computer Emergency Response Team (CERT) and Computer Incident Advisory Capability (CIAC), which announce new exploits and vendor patches. Microsoft only recently introduced its Security Notification Service. At a minimum, you’ll want to subscribe to this service. (Go to http://www.microsoft.com/security/ services/subscribe.asp.) However, this vendor-based information source provides only information that serves Microsoft’s best interests.

Mailing lists exist on which the industry’s best hackers and security experts discuss exploits and fixes. My favorite resource is the NTBugtraq mailing list. You can subscribe to this list at http://www.ntbugtraq.com. Discussion on this list revolves around NT exploits and fixes. Russ Cooper effectively moderates the list, which more than 15,000 users subscribe to. NTBugtraq is one of the best resources for untangling hotfixes’ idiosyncrasies and contradictory documentation. For additional NT security mailing lists, go to http://www.ntsecurity.net and http://www.iss.net/vd/maillist.html.

The volume of email from security mailing lists can be overwhelming. I direct all the mail to an NT Security folder in Microsoft Outlook. Once a day, I scan the subject lines for topics of immediate relevance. I also scan the authors, because I’ve learned to recognize the regular posters whose messages are consistently valuable. This method lets me spend a minimal amount of time keeping up-to-date. When I have some downtime, such as on a flight, I scan the rest of the messages for new problems, tricks, and insights.

If you’re trying to solve a particular problem, you might have difficulty finding the appropriate hotfix. You can use NTBugtraq’s free service at http://ntbugtraq.ntadvice.com/ntfixes.asp to search for hotfixes by language, NT version, processor type, and service pack. The tool even highlights hotfixes that the vendor has updated or removed.

Related Content:

ARTICLE TOOLS

Comments
  • Barbaros
    8 years ago
    Jun 04, 2004

    I am trying to automate the patch deployment. Can this article be used for Windoes 2000 and 2003?

  • Kent Karrer
    13 years ago
    Aug 11, 1999

    Great article! Good info.
    Thanks

  • HC
    13 years ago
    Aug 05, 1999

    Interesting and timely article...though it did fall sadly short in some areas. Of particular interest was the complete absence of any mention of Perl. ActiveState's ActivePerl is an excellent tool...one that every sysadmin should become familiar with...it's too bad Microsoft didn't see fit to provide such a scripting engine for NT.

    Perl can be used to query all NT systems across the enterprise for a variety of information...to include SP and hotfix levels...use Win32::Registry, or Win32::TieRegistry. Want to get/set permissions on a file, directory, or Registry key? Dave Roth's Win32::Perms is the answer. Jens Helberg did an outstanding job with Win32::Lanman.

    Perl can be used to secure an enterprise worth of NT machines from a single location. Want to roll out hotfixes? Put the hotfix on a share and submit AT jobs across the enterprise...automate this with Win32::Lanman, or use soon.exe from the RK.

    Good article. Timely. However, it fails to leverage the technology that is available....

    K

You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

White Papers

Get your Windows 7 deployment off to the right start by implementing PC lockdown. A locked-down environment is easier and cheaper to support since users are less likely to make unnecessary changes to the core system configuration - read more here!

Essential Guides

Is your iSCSI "lossy"? The reality is that most off-the-shelf Ethernet hardware deployed for iSCSI can lose packets, resulting in slow performance or application downtime. Learn how to assess your current iSCSI infrastructure and engineer an advanced iSCSI SAN infrastructure.

Web Seminars

What's the best way to keep your network safe from malware? In this web seminar, security expert Greg Shields suggests an alternative method to the traditional blacklisting approach that is common with anti-virus and anti-malware solutions.

eLearning Series

We bring the experts direct to you to share their real-world perspective and expertise. During each event, three sessions stream in real time, so you can learn, ask questions, and get solutions.
Upcoming event: Getting the Most with Exchange 2010 with Paul Robichaux

Subscribe to Windows IT Pro!

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.