TIP: Click on subject to list as thread! ANSI
echo: nthelp
to: John Beckett
from: Geo.
date: 2003-05-01 18:46:12
subject: Re: where the hell is SP4???

From: "Geo." 

"John Beckett"  wrote in
message news:3eb0b5d4.623748683{at}news.barkto.com...

> I would worry about that because there is no guaranteed, precise
> documentation about what is happening. We don't know whether a hotfix
> needs a reboot before some other hotfix is installed.

Well actually I do know that it works because I have done this with all my
webservers and if it didn't work I'd have known soon as the machine was
rooted or crashed. All the security software shows the machines are
properly patched against known exploits (stuff like cybercop).

> I would at least run the QFEcheck that the above article mentions. It
> purports to check whether the installed hotfixes really are installed.

That just checks for the registry entries, it doesn't actually check to see
if the file versions are correct or if the machine is exploitable. The
other tools I use do check both.

> The above article outlines a reason why you MUST reboot between
> hotfixes (or must use qchain). I suppose that your list of patches has
> been carefully arranged in chronological order so -- if there is any
> justice -- you ~should~ not be affected by the particular example they
> outline.

Yes, it's just the order in which they were released, I updated my list
each time a new one came out and tested the machine as soon as the test
software had been updated to look for the new exploit.

> The situation is ghastly.

what really pisses me off is a service pack comes out and after installing
it you have to apply 3+ hotfixes. The only way I can see that Microsoft
could fix this situation is to make a current full build ISO available for
download as well as or in place of the fixes. That way each time a fix
comes out you download it and burn and you have a current install disk. All
they really need then is a boot option "install or patch" and you
could use the CD for anything without having to worry about unpatching
because it asked for the CD. CD's are cheap, people (those without the
bandwidth) would even pay to get one (shipping and handling) 4 times a year
or so.

Geo.

--- BBBS/NT v4.01 Flag-4
* Origin: Barktopia BBS Site http://HarborWebs.com:8081 (1:379/1.45)
SEEN-BY: 633/267 270
@PATH: 379/1 633/267

SOURCE: echomail via fidonet.ozzmosis.com

Email questions or comments to sysop@ipingthereforeiam.com
All parts of this website painstakingly hand-crafted in the U.S.A.!
IPTIA BBS/MUD/Terminal/Game Server List, © 2025 IPTIA Consulting™.