WinInfo Daily UPDATE, December 11, 2003

The mysterious delivery of a critical security patch this week, the same week in which Microsoft announced it wouldn't deliver any critical-security-patch bundles, had the company scrambling yesterday to find out what happened.

Paul Thurrott

December 10, 2003

4 Min Read
ITPro Today logo in a gray background | ITPro Today

Argent Software
http://www.argent.com/products/download_whitepaper.cgi?product=mom&&Source=WNT

===============

1. In the News
- Patch-Delivery Snafu Snares No-Patch December 2. Announcement
- Take Our Print Publications Survey! 3. Event
- New--3 Microsoft Security Road Shows! 4. Contact Us
- See this section for a list of ways to contact us. ==== Sponsor: Argent Software ==== NETWORK TESTING LABS COMPARES MOM TO THE ARGENT GUARDIAN
Network Testing Labs, one of the world's leading independent research companies, put together a comprehensive Comparison Paper on two leading enterprise monitoring solutions. Their conclusion: "The Argent Guardian easily beats out MOM in all our tests ... The Argent Guardian will cost far less than MOM and yet provide significantly more functionality." Find out for yourself why organizations like Major League Baseball, GE Capital, AT&T, Harley Davidson, and Nokia all rely on The Argent Guardian for their enterprise monitoring and alerting needs. Download this Comparison Paper now:
http://www.argent.com/products/download_whitepaper.cgi?product=mom&&Source=WNT ==== 1. In the News ====
by Paul Thurrott, [email protected] Patch-Delivery Snafu Snares No-Patch December
The mysterious delivery of a critical security patch this week, the same week in which Microsoft announced it wouldn't deliver any critical-security-patch bundles, had the company scrambling yesterday to find out what happened: A glitch in the company's Windows Update patch-delivery mechanism was responsible for the delivery of the erroneous patch, which fixes a problem with the Microsoft FrontPage Server Extensions, a software add-on for Microsoft's Web server software. The company issued a Microsoft Knowledge Base article describing the patch more than a month ago, although it didn't publish the patch to Windows XP users until this week. Microsoft says it should have published the patch and Knowledge Base article simultaneously and for all affected systems.
The FrontPage Server Extensions fix is critical only for XP and Windows 2000 systems that have Windows SharePoint Services (WSS) 2003 installed, and Microsoft apparently distributed the patch to Win2K users on November 11. The patch is rated "moderate" for most XP systems (i.e., XP systems without FrontPage Server Extensions installed, which is most of them).
In related news, a new Microsoft Internet Explorer (IE) 6.0 vulnerability that researchers recently discovered could potentially put users' data at risk. According to a security bulletin released earlier this week by the Danish security company Secunia, this newly discovered IE 6.0 vulnerability could let intruders spoof Web sites by loading a different page when users enter a genuine URL in IE's address bar. If the vulnerability is compromised correctly, attackers could emulate an e-commerce site such as Amazon.com or eBay and cause users to inadvertently enter sensitive information. Microsoft says it's "aggressively investigating the public reports" about this vulnerability and, if warranted, might issue a patch outside of its regular monthly patch packages. The next set of patch packages is due in the second week of January. ==== 2. Announcement ====
(from Windows & .NET Magazine and its partners) Take Our Print Publications Survey!
To help us improve the hardware and software product coverage in the Windows & .NET Magazine print publications, we need your opinion about what products matter most to you and your organization. The survey takes only a few minutes to finish, so share your thoughts with us at
http://websurveyor.net/wsb.dll/12237/editorsproduct.htm ==== 3. Event ====
(brought to you by Windows & .NET Magazine) New--3 Microsoft Security Road Shows!
Don't miss out on three new Security Road Show events in December. Join industry guru Mark Minasi, and learn more about tips to secure your Windows Server 2003 and Windows 2000 network. There is no charge for this event, but space is limited, so register today!
http://www.winnetmag.com/roadshows/security2003dec ==== Sponsored Link ==== Sybari Software
Free! "Admins Shortcut Guide to Email Protection" from Sybari
http://ad.doubleclick.net/clk;6574227;8214395;q?http://www.sybari.com/ebook

=========

4. ==== CONTACT US ==== About the newsletter -- [email protected]
About technical questions -- http://www.winnetmag.com/forums
About product news -- [email protected]
About your subscription -- [email protected]
About sponsoring UPDATE -- [email protected]

==============

This email newsletter is brought to you by Windows & .NET Magazine, the leading publication for IT professionals deploying Windows and related technologies. Subscribe today.
http://www.winnetmag.com/sub.cfm?code=wswi201x1z

Manage Your Account
You are subscribed as #EmailAddr#.

To unsubscribe from this email newsletter, send an email message to mailto:#mailing:unsubemail#.

To make other changes to your email account such as change your email address, update your profile, and subscribe or unsubscribe to any of our email newsletters, simply log on to our Email Preference Center.
http://www.winnetmag.com/email

Copyright 2003, Penton Media, Inc.

About the Author

Paul Thurrott

Paul Thurrott is senior technical analyst for Windows IT Pro. He writes the SuperSite for Windows, a weekly editorial for Windows IT Pro UPDATE, and a daily Windows news and information newsletter called WinInfo Daily UPDATE.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like