---
title: "har DU alla MS patchar !"
type: "forum-thread"
url: "https://www.webforum.nu/amne/datasakerhet/28664-har-du-alla-ms-patchar"
topic: "Datasäkerhet"
topic_url: "https://www.webforum.nu/amne/datasakerhet"
author: "stoffe-2k"
published: "2001-08-15T17:22:00.000Z"
updated: "2001-08-23T06:42:00.000Z"
replies: 17
views: 598
page: 1
pages: 1
language: "sv-SE"
site: "webForum — webforum.nu"
rights: "Upphovsrätten till varje inlägg tillhör dess författare."
attribution: "Citera som: webForum, https://www.webforum.nu/amne/datasakerhet/28664-har-du-alla-ms-patchar"
---

# har DU alla MS patchar !

## #1 — stoffe-2k, 2001-08-15T17:22Z

...det hadde inte (ens ;))jag...(fattades 6st, fast jag tror inte programet är 100% :l) 

men iaf ;) tanka hem och KÖR idag imorgon kan det vara försent §jr ..!

IDG "artikel" <http://nyheter.idg.se/display.asp?ID=010815-SOS2> 

Direkt till filen <http://download.microsoft.com/download/win2000platform/Utility/2.1/NT45/EN-US/nshc.exe> 

Till mer info hos MS <http://support.microsoft.com/support/kb/articles/q305/3/85.ASP?LN=EN-US&SD=gn&FR=0&qry=q305385&rnk=1&src=DHCS_MSPSS_gn_SRCH&SPR=MSALL>

Permalänk: https://www.webforum.nu/p/28664

## #2 — Reefer, 2001-08-15T18:02Z

Bah! Klart man har dom senaste patcharna (se min user agent) :e

Och vad ni än tror så finns det inga buggar eller säkhål i MS produkter.

Permalänk: https://www.webforum.nu/p/404080

## #3 — @nders, 2001-08-15T18:17Z

reefer: :e

Permalänk: https://www.webforum.nu/p/404081

## #4 — Skywalker, 2001-08-16T06:39Z

Hmm... Om man har tankat ner xmlfilen och inget händer så är allt frid & fröjd eller?

Permalänk: https://www.webforum.nu/p/404082

## #5 — His Divine Shadow, 2001-08-16T09:41Z

Det borde finnas nått program som är 'linkat' till MS och deras bugg databas som kunde kolla mjukvaran och se om man saknar någon patch, ett enkelt program som funkar t.ex. att när man startar det väljer man mellan olika program som man har installerade(IIS, Explorer, OE, Windows själv) och så scannaer programmet det man har valt och säger till om några patcher saknas.

Tänk va bra att ha.

Permalänk: https://www.webforum.nu/p/404083

## #6 — stoffe-2k, 2001-08-16T11:24Z

Skywalker: du kör väl progrmaet i ett DOS fönster.. om du bara dubbelkilckar så försvinner resultatet då fönstret stängsner...

Permalänk: https://www.webforum.nu/p/404084

## #7 — Zigma, 2001-08-16T11:39Z

Finns förresten en patch som ska innehålla alla IIS patchar: <http://www.microsoft.com/technet/security/bulletin/ms01-044.asp> 

Dock är de bara fem stycken, på vissa låter det som det vore tiotals patchar eller hundratals när de börjar tala om att det är ett "heltidsjobb" att patcha IIS, löjligt.

Den ska dock fixa alla, så här stod det i security bullentinen:

This patch is a cumulative patch that includes the functionality of
all security patches released to date for IIS 5.0, and all patches
released for IIS 4.0 since Windows NT(r) 4.0 Service Pack 5. A
complete listing of the patches superseded by this patch is provided
below, in the section titled "Additional information about this
patch". Before applying the patch, system administrators should take
note of the caveats discussed in the same section. 

In addition to including all previously released security patches,
this patch also includes fixes for five newly discovered security
vulnerabilities affecting IIS 4.0 and 5.0: 
 \- A denial of service vulnerability that could enable an attacker
   to cause the IIS 4.0 service to fail, if URL redirection has 
   been enabled. The "Code Red" worm generates traffic that can in 
   some cases exploit this vulnerability, with the result that an 
   IIS 4.0 machine that wasn't susceptible to infection via the 
   worm could nevertheless have its service disrupted by the worm. 
 \- A denial of service vulnerability that could enable an attacker 
   to temporarily disrupt service on an IIS 5.0 web server. WebDAV
   doesn't correctly handle particular type of very long, invalid
   request. Such a request would cause the IIS 5.0 service to fail;
   by default, it would automatically restart. 
 \- A denial of service vulnerability involving the way IIS 5.0 
   interprets content containing a particular type of invalid MIME 
   header. If an attacker placed content containing such a defect 
   onto a server and then requested it, the IIS 5.0 service would 
   be unable to serve any content until a spurious entry was removed
   from the File Type table for the site. 
 \- A buffer overrun vulnerability involving the code that performs 
   server-side include (SSI) directives. An attacker who had the 
   ability to place content onto a server could include a malformed 
   SSI directive that, when the content was processed, would result
   in code of the attacker's choice running in Local System context. 
 \- A privilege elevation vulnerability that results because of a flaw
   in a table that IIS 5.0 consults when determining whether a
process
   should in-process or out-of-process. IIS 5.0 contains a table that
   lists the system files that should always run in-process. However,
   the list provides the files using relative as well as absolute 
   addressing, with the result that any file whose name matched that
   of a file on the list would run in-process. 

In addition, this patch eliminates a side effect of the previous IIS
cumulative patch (discussed in the Caveats section of Microsoft
Security Bulletin MS01-026) by restoring proper functioning of
UPN-style logons via FTP and W3SVC.

Permalänk: https://www.webforum.nu/p/404085

## #8 — Robban, 2001-08-16T16:18Z

> Dock är de bara fem stycken ...

Nja, fem nyupptäckta säkerhetshål (sedan senaste patchen). Står ju: ***in addition to** including all previously released security patches, this patch also includes fixes for five newly discovered security vulnerabilities*.

> på vissa låter det som det vore tiotals patchar eller hundratals när de börjar tala om att det är ett "heltidsjobb" att patcha IIS, löjligt

Inte heltidsjobb, men ändå omfattande. Jag vet, för det är en av mina arbetsuppgifter att patcha IIS-servrarna på vårt jobb.

Våra Apache-servrar har jag f.ö. inte behövt patcha någon gång i år. Inte boota om heller. Ett hundra procents tillgänglighet i år alltså - bra mycket mer än vad IIS-servrarna kan stoltsera med. :e

Permalänk: https://www.webforum.nu/p/404086

## #9 — His Divine Shadow, 2001-08-16T16:42Z

IIS får ju såklart intrycket av att ha mest buggar eftersom så många 'hackar' MS produkter, men detta är bara bra, IIS blir tätare och tätare mens servrar som Apache kan ha vem vet hur mpnga hål som aldrig upptäckts...

Permalänk: https://www.webforum.nu/p/404087

## #10 — Zigma, 2001-08-16T16:59Z

Precis, håller med, IIS är en av de mest hackade och därmed mest testade servrarna i världen.

Vilken ska man välja ? En som påstås inte innehålla några säkerhets hål eller en som testats i det oändliga.

Blev inte så imponerad av patch programmet som tråden startade med, trots den samlade patchen installerats gnäller den att patchar saknas.
 

\[Redigerat av Zigma den 16 aug 2001\]

Permalänk: https://www.webforum.nu/p/404088

## #11 — Muzzafarath, 2001-08-16T18:28Z

> IIS blir tätare och tätare mens servrar som Apache kan ha vem vet hur mpnga hål som aldrig upptäckts...

Öh, Apache är väl den mest använda webservern i världen, det är nog en massa människor som försöker hacka den med skall du se...

Permalänk: https://www.webforum.nu/p/404089

## #12 — Zigma, 2001-08-16T18:41Z

Det tror jag faktiskt inte, på grund av det enormt stora Microsoft hatet som finns bland open source nissarna så är det ju främst IIS som hackas.

Dessutom har IIS en majoritet av SSL servrarna ( dvs e-commerce ) vilket förmodligen är mer intressant att hacka än servrar med student sajter på.

Permalänk: https://www.webforum.nu/p/404090

## #13 — Muzzafarath, 2001-08-16T20:24Z

\[r\]Halvdumt inlägg.

\[Redigerat av Muzzafarath den 16 aug 2001\]

Permalänk: https://www.webforum.nu/p/404091

## #14 — Robban, 2001-08-17T09:38Z

Om IIS "hackas" mer än andra servrar p.g.a. Microsoft-hat vet jag inte om jag håller med om. Men det är ju i vilket fall som helst orelevant för mig som IIS-användare. Jag är ju lika utsatt oberoende av vad angreppen beror på.

Permalänk: https://www.webforum.nu/p/404092

## #15 — stoffe-2k, 2001-08-17T10:58Z

OT

Robban:

Vad kör du när din "user agent" är:

*Mozilla/4.0 (compatible; MSIE 6.0; **Whistler**)*

Eller har du hackat dit den själv...

Permalänk: https://www.webforum.nu/p/404093

## #16 — Spender, 2001-08-18T20:27Z

WINDOWS 2000 SP2

                Patch NOT Found MS00-077        Q299796
                Patch NOT Found MS00-079        Q276471
                Patch NOT Found MS01-007        Q285851
                Patch NOT Found MS01-013        Q285156
                WARNING         MS01-022        Q296441
                Patch NOT Found MS01-025        Q296185
                Patch NOT Found MS01-031        Q299553
                Patch NOT Found MS01-037        Q302755
                Patch NOT Found MS01-041        Q298012

        Internet Information Services 5.0

                Patch NOT Found MS01-025        Q296185
                Patch NOT Found MS01-044        Q301625

Det där bådar inte gott va? ;)

Permalänk: https://www.webforum.nu/p/404094

## #17 — Robban, 2001-08-22T13:28Z

> Eller har du hackat dit den själv ...

Japp. :)

Satte dit den innan IE6 var klar, och alla "MS-nissar" blev så avundsjuka så. ;)

Permalänk: https://www.webforum.nu/p/404095

## #18 — stoffe-2k, 2001-08-23T06:42Z

OK :D

Permalänk: https://www.webforum.nu/p/404096

---

Tråden på webben: https://www.webforum.nu/amne/datasakerhet/28664-har-du-alla-ms-patchar
