As we contact people to patch their systems, we’re getting replies saying they have been patched or they are running Linux.

 

Windows 2000 Advanced Server SP4 shows vulnerable but has been patched and rebooted twice according to the SA.

Windows 2000 Professional SP3 shows vulnerable but has been patched and rebooted twice according to the SA.

 

Two different Red Hat 7.3 machines have shown up as vulnerable.

 

We had a similar issue with 11835 in the fall flagging patched Windows systems as vulnerable.  In talking to this list and looking into those, we found that the patch for MS03-039 (11835) was not updating all files.  I have asked the Windows SA’s to check the file data in the Microsoft knowledgebase article for MS04-011 to see if they have all been updated.  The problem is, I do not have direct access to the Windows machines in question and cannot look for myself.

 

So, my question is, as it was in the fall, what is the confidence level of this test?  How can I prove or disprove the positive results other than badgering SA’s to go through the file list (may not be a way, I know)?

 

Any help, ideas, constructive thoughts, welcome.

 

Thanks,

Carl

_______________________________________________
Nessus mailing list
[EMAIL PROTECTED]
http://mail.nessus.org/mailman/listinfo/nessus

Reply via email to