Security Basics mailing list archives

Re: MS Service Packs


From: "Marco Araujo" <amon87secfx () hotmail com>
Date: Wed, 18 Jun 2003 17:19:53 -0300

Hi Thad,

The list of updates included and bugs fixed is on the Service Pack Release Notes.

As a example, let's talk about Win2k SP3.

The homepage for this SP is:

http://www.microsoft.com/windows2000/downloads/servicepacks/sp3/default.asp

The list of updates can be found at the 'List of Updates' at the URL above:
http://support.microsoft.com/default.aspx?scid=kb;en-us;320853

Anyway, the best pratice for Windows, IIS and SQL server updating is install the latest SPs and then run MBSA. (http://www.microsoft.com/technet/security/tools/Tools/MBSAhome.asp)

Regards,

Marco Araujo
MCSE
Recife/PE - Brasil

From: Thad Horak <thadhorak () yahoo com>
To: security-basics () securityfocus com
Subject: MS Service Packs
Date: Wed, 18 Jun 2003 08:59:08 -0700 (PDT)

All,

Has anyone had any luck decyphering what security
fixes are include in what MS service packs. For
example, if I apply SP3 to a W2K Server will this
patch all security issues found for the base OS up
until the release of SP3. What about IIS/SMTP/FTP, etc
fixes. Do I need to install these Qfixes and rollups
seperately? I've looked through the readme for the SP,
but it's not that clear. Hoping someone on the list
has tackled this and can shed some light. Many thanks.

Thad

_________________________________________________________________
Help STOP SPAM with the new MSN 8 and get 2 months FREE* http://join.msn.com/?page=features/junkmail


---------------------------------------------------------------------------
Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts!
The Gartner Group just put Neoteris in the top of its Magic Quadrant,
while InStat has confirmed Neoteris as the leader in marketshare.
Find out why, and see how you can get plug-n-play secure remote access in
about an hour, with no client, server changes, or ongoing maintenance.
Visit us at: http://www.neoteris.com/promos/sf-6-9.htm
----------------------------------------------------------------------------


Current thread: