OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
NTBugtraq And NTSecurity Archives: Re: SP6a now available from

Re: SP6a now available from Microsoft - correction


Russ (Russ.CooperRC.ON.CA)
Wed, 24 Nov 1999 17:25:14 -0500


-----BEGIN PGP SIGNED MESSAGE-----

The information I based my recommendation on was incorrect. SP6a
Download is IDENTICAL to SP6a CD.

There are 2 deployment scenarios for SP6/SP6a;

1. SP6 + original TCP-ISN fix + AFD Hotfix. Use this deployment if you
want the additional randomness in TCP ISNs.

2. SP6a alone. Use this deployment if you don't want/need the
additional ISN randomness. An updated version of the TCP-ISN fix will
be released that can be used on SP6a (as well as previous SPs).

If you apply the original TCP-ISN fix to SP6a, you will re-introduce
the Winsock ports "regression error", so don't do it.

My sincerest apologies for the confusion my earlier message has
created. What I did was done in an honest attempt to save you
time/effort. It had/has nothing to do with some problem, exploit, or
vulnerability that I know about and won't talk about.

Cheers,
Russ - NTBugtraq Editor

-----BEGIN PGP SIGNATURE-----
Version: PGP 6.0.2

iQCVAwUBODxmaRBh2Kw/l7p5AQGyJgQAuXWbpICdDlPVik2G6wWVYToVCr2VHNMC
gKPG0QAohvjRV+Vnv3/G4NT+t5vCJJUesnzc4UfEv3YsbNBmLV98V0ldC5rF04D8
MHq0TJP/SyEN/SVMrGy03URQU5AM47sp++nKvFx0UUhBO9Axqlmb32o0WfzEH+Fy
DynVJJT+Oso=
=R0j+
-----END PGP SIGNATURE-----



This archive was generated by hypermail 2.0b3 on Wed Nov 24 1999 - 16:26:40 CST