Virus.Org  IT Security News and Information Portal. We offer the latest IT security news, updates, product reviews, books, and articles for all you IT security professionals out there. Enter and get the best IT security information on the Internet.

 

. Welcome to the Virus.Org Mailing List Archive  
.
.


[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]


Re: Getting patch information on Systems without ADMIN rights !?
.

  • To: "Patch Management Mailing List" <[EMAIL PROTECTED]>
  • Subject: Re: Getting patch information on Systems without ADMIN rights !?
  • From: [EMAIL PROTECTED]
  • Date: Fri, 30 Apr 2004 14:57:00 -0700
  • Reply-to: "Patch Management Mailing List" <[EMAIL PROTECTED]>
.
 

There are tools like Eeye's Retina scanner and ISS's scanner that can test for vulnerabilities that the patches address.  In addition, NMAP is free and can test for numerous vulnerabilities.  Rather than seeing if the patch is installed, these scanners determine if the system is vulnerable regardless of proper patch installation.  Tools like this should be used in conjunction with vulnerability and patch tools to better determine whether patches were actually installed correctly.  Each patchmanagement software / vulnerability software determines whether patches are installed via different methods (registry setting exists, dll's are updated, file checksums, etc).  However, these types of scanners can determine if the system is still vulnerable regardless of whether patchmanagement or Windows Update says it is patched.  This gives you more of a view from the exploiters perspective.  Let's face it, their scanning tools will only determine if it is vulnerable so they can attack it or their worm will scan and exploit the vulnerability.  So these types of scanners have their purpose for determining where your still vulnerable while addressing the need to find systems that do not have patches installed.  If it's vulnerable, then the patch is not installed.  No admin rights required.

Joe Maloney CCSA, GSEC
Security Administrator


--- To unsubscribe send a blank email to [EMAIL PROTECTED]  
.
.
 
Copyright (c) Virus.Org 1997-2006.
All Trademarks Acknowledged.
Please view our Terms and Conditions and our Privacy Policy.