OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: miro.tomaciticorp.com
Date: Tue Jul 31 2001 - 02:36:17 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    On top of the below findindgs, I found some additional discrepancies (only
    checked for NT 4.0 fixes).
    The roll-up fix claims to supersede
      Q243649 (99-047)
      Q244599
    But there are files copied (updated ?) in the above fixes, but not in the
    rollup (q299444). These are
      null.sys beep.sys from Q244599
      lmmon.dll from Q243649
    While null.sys is on install CD and beep.sys is on both the install CD and
    SP6a, I can not find _any_ instance of lmmon.dll outside the Q243649 package...
    It neither matches in the DLL Help Database.

    I just notified MS on Friday, but they're "too busy" to answer.

    > -----Original Message-----
    > From: rubens [mailto:rubensaltimari.com.br]
    > Sent: Sunday, July 29, 2001 7:26 PM
    > To: focus-ms
    > Cc: rubens
    > Subject: Re: Post-Windows NT 4.0 Service Pack 6a Security Rollup
    >
    >
    > >
    > http://support.microsoft.com/support/kb/articles/q299/4/44.asp
    > ?ID=299444
    > > It would seem its a summary of all the hot fixes and
    > patches since SP6a.
    >
    > Just a small note: not *all* hot fixes: there are a
    > number of them that are still needed after applying q299444.
    > I just keep track of NT4/IIS4 patches, but if anyone is
    > interested, according to my own list, they are:
    >
    > for NT4:
    > http://www.microsoft.com/technet/security/bulletin/ms99-041.asp
    > http://www.microsoft.com/technet/security/bulletin/MS01-022.asp
    > http://www.microsoft.com/technet/security/bulletin/MS01-029.asp
    >
    > for IIS4:
    > http://www.microsoft.com/technet/security/bulletin/fq00-025.asp
    > http://www.microsoft.com/technet/security/bulletin/fq00-028.asp
    > http://www.microsoft.com/technet/security/bulletin/ms01-033.asp
    > http://www.microsoft.com/technet/security/bulletin/ms01-035.asp
    >
    > Some of them are pretty old, but I haven't found any
    > clear statement that they are not needed anymore.
    >
    > Rubens Altimari
    >