MS upgrades tool that verifies system configuration
- 21 January, 2004 12:21
- Comments
As part of the overhaul of its patch management tools, Microsoft Corp. on Tuesday released the next version of a tool that detects bad configurations that could leave users open to security vulnerabilities.
The Microsoft Baseline Security Analyzer (MBSA) 1.2 includes support for a number of new Microsoft products, including Exchange 2003 and the past three versions of BizTalk Server. The 1.2 version also is available in three additional languages, French, German and Japanese. MBSA 1.2 includes support for Office 2000, XP and 2003, however, users can only scan the machine where the MBSA software is running. Remote scans of Office are not supported.
MBSA allows users to scan one or more Windows-based computers to ensure they are up-to-date with the latest security patches. The software checks the operating system and other components, including Internet Information Server and SQL Server.
The additional components and servers supported in MBSA 1.2 include BizTalk Server 2000, 2002, and 2004; Commerce Server 2000 and 2002; Content Management Server 2001 and 2002; Host Integration Server 2000 and 2004; SNA Server 4.0; Microsoft Virtual Machine; and Microsoft XML 2.5, 2.6, 3.0, 4.0. MSXML is an XML processing engine that works with Internet Explorer.
The new software also supports Microsoft Data Access Component 2.5, 2.6, 2.7, and 2.8, which should avoid a repeat of the problems users recently had installing Microsoft patch MS04-003.
MBSA 1.2 also performs configuration checks on the Internet Connection Firewall, Automatic Updates, Internet Explorer zones and for the version of MBSA itself.
Microsoft is upgrading its tools based on criticism from users who have suffered through patch and security issues over the past few years, most notably the Slammer worm.
MBSA is but one component of Microsoft's patch overhaul that will include a common assessment engine to verify whether patches are needed; automatic update capabilities for every product; and standardized uninstaller technology. Microsoft also is cutting the number of patch installers from eight to two and developing a single patch-update site for Microsoft products.
Many of the features Microsoft is adding are already available from third-party patch management tools such as those from Shavlik Technologies LLC, which licenses some of its software to Microsoft. Other vendors such as Aelita Software Corp., BigFix Inc., ConfigureSoft Inc., Ecora Corp., PatchLink Corp. and St. Bernard Software Inc. also offer patch management tools.
Those tools also offer some features not supported by Microsoft.
"We can do remote scans of Office," says Eric Shultze, Shavlik's director of product research and development, referring to the company's HFNetChkPro. The company's tools also can check configurations on servers that Microsoft itself has yet to support including Internet Security and Acceleration Server.
- Bookmark this page
- Share this article
- Got more on this story? Email Computerworld
- Follow Computerworld on twitter
- Securing Vital Infrastructure
- Business Process Management, Service-Oriented Architecture, and Web 2.0: Business Transformation or Train Wreck?
- Beyond Dropbox: Requirements for Enterprise Secure File Sharing
- FIBRE CHANNEL SOLUTIONS GUIDE - state of the fibre channel industry
- Secure File Sharing in the Cloud: Maximizing the Benefits
- iPhone 5 rumour rollup for the week ending February 10
- 3D mapping revives underwater city
- Academic challenges Turnbull over NBN satellite criticism
- What are you saying: Telstra’s customer service slowly improving, SA minister urging Facebook to overturn its photo ban
- In pictures: Capgemini opens new Canberra office
-
Maingear's six-core laptop has 1.8TB of SSD storage
-
After Megaupload shuts, BTJunkie follows
-
Windows Event Viewer phishing scam remains active
-
NeuroSky MindWave: Fun with Brainwaves
-
20 popular Ubuntu Linux apps you may want to try
-
Teach Yourself Visually Windows Vista
-
Revit Architecture
-
Twitter Tips, Tricks, and Tweets, 2nd Edition
-
Beginning Mac OS X Snow Leopard Programming
-
Programlive CD - Stand Alone Version
-
Microsoft® CRM 3 for Dummies®
-
Wordperfect Office 2002 for Dummies
-
Software Engineering
-
(WCCS) Custom for the University of Manitoba, Selected Chapters From Weverka












Comments
Post new comment