Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


February 1999

Hotfixes to Secure Systems


RSS
Subscribe to Windows IT Pro | See More Hotfixes Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

Deciding which hotfixes you need

Determining which hotfixes you need to correct a particular security problem can be a tedious task. If you've ever visited Microsoft's FTP site looking for hotfixes, you've noticed the numerous patches available. In fact, as of October 1, 1998, I counted 45 post-Service Pack 3 (SP3) hotfix subdirectories at the site. A few hotfixes are obsolete, and their respective directories contain only a readme.txt file with a pointer to a current patch location.

You don't have to download every hotfix Microsoft publishes. Some hotfixes might not apply to software running on your system, and others might fix minor problems you're not interested in fixing, such as problems in assigning a drive letter to an Iomega Zip drive. But you need to download security-related hotfixes to keep your system safe.

To save you some time, I've undertaken the task of helping you decide which security hotfixes you need. I've discovered 16 Windows NT 4.0 post-SP3 hotfixes that correct particular security-related problems. This article briefly discusses each hotfix and directs you to Microsoft articles for more information on each hotfix. I've arranged the hotfixes categorically by major application to simplify your choice of appropriate hotfixes.

It is important to note that when you are considering which hotfixes will help protect your NT 4.0 system, you must consider what Microsoft-supported applications and hardware are running on that system. If you can't determine what hotfixes are on your NT systems, download a copy of SPQuery from MTE Software at http://www.mtesoft.com. SPQuery itemizes installed hotfixes for you and helps you download the hotfixes from within the SPQuery software. SPQuery can save a lot of time when it comes to patching NT systems. It costs about $195 for the network-enabled edition.

Locating Hotfixes
Microsoft stores US versions of NT hotfixes online at ftp://ftp.microsoft.com/bussys/winnt/winnt-public/fixes/usa/nt40/hotfixes-postsp3. You can get international versions of most Microsoft hotfixes by selecting your country's directory at ftp://ftp.microsoft.com/bussys/winnt/winnt-public/fixes. If you have trouble accessing Microsoft's main FTP site due to routing problems or high traffic loads, try the alternative FTP site at ftp://198.105.232.37/fixes.

Unless otherwise noted below, you can find all the hotfixes in this article at the sites I've listed above. I've used the hotfix directory name to reference each hotfix so you know where to find each one on the FTP site.

Hotfixes for NT 4.0
The Snk-fix hotfix corrects a denial-of-service problem with the Rpcss.exe routine of the Remote Procedure Call Subsystem (RPCSS). Spoofing UDP packets directed at port 135--­where they initiate a loop of rejection packets between systems--­causes the denial-of-service (DoS) attack. The loop will not break until one of the servers drops the package. The loop causes high processor loads and unnecessary bandwidth usage. The Microsoft article "Rpcss.exe Consumes 100% CPU Due to RPC Spoofing Attack" at http://support.microsoft.com/support/kb/articles/q193/2/33.asp discusses this scenario.

The priv-fix hotfix corrects an OS problem in which, via the utility sechole .exe, any user can gain membership to the local Administrators group and gain local administrative privileges. The priv-fix hotfix ensures that the server, not the client, checks access rights. The Microsoft article "SecHole Lets Non-administrative Users Gain Debug Level Access" at http://support.microsoft.com/support/kb/articles/q190/2/88.asp describes the details.

   Previous  [1]  2  3  Next 


Reader Comments
I picked up a utility from HewlettPackard forum: Belarc Advisor. I have run in more than once. The first time all was OK, now, the advisor has marked my need for seven "hotfixes" to reinstall. UPD238453, UPD256015, UPD259728, UPD273991, all for WIN 98SE. For WIN 98, UPD245729, UPD314147, UPD273017. I haven't found them available on Microsoft Support. They are on my WIN98SE Startup Disk, but I do not know how to get them in use. Particularly, I cannot do a satisfactory scandisk. I would really appreciate it if you would advise me how to repair this, if it is necessary. I am presently stuck in Safe Mode, with 256 MB RAM on a HP Pavilion 6535. Thank you.

Jane Bonwell April 25, 2003


W98 Belarc says to reinstall
UPD238453
UPD259728
UPD273991
Haven't had any luck yet finding one of these let alone all three.

Anonymous User November 19, 2004 (Article Rating: )


You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
PsExec

This freeware utility lets you execute processes on a remote system and redirect output to the local system. ...

Microsoft Delivers Service Pack 2 Beta 2 for Vista, Server 2008

Microsoft on Tuesday announced the availability of the Beta 2 version of Service Pack 2 (SP2) for Windows Vista and Windows Server 2008. Since both operating systems were developed from the same code base, they have a common servicing structure and thus ...

Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...


Security Whitepapers The Impact of Messaging and Web Threats

Why SaaS is the Right Solution for Log Management

Protecting (You and) Your Data with Exchange Server 2007

Related Events How IE7 & The New Extended Validation SSL Certificates Impact Your Site

Top 10 Email Security Challenges and Solutions

Introduction to Identity Lifecycle Manager "2"

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing