Microsoft get back to baseline on security

ANALYSIS
Microsoft's new-found fondness for security is bearing fruit. The company has recently made the Microsoft Baseline Security Analyser (MBSA) available, a tool that checks for multiple vulnerabilities on Windows 2000 and XP machines. It won't run on NT 4, but will check such computers remotely. At heart, MBSA is an XML wrapper around a previously available tool, the Hot Fix Network Checker or HFNetChk. That's a command-line only utility that queries a database maintained by Microsoft containing the latest hot fixes issued for each product, checks those installed on the client machine and issues a list of discrepancies. It'll do this for the machine it runs on, or others by IP address, Netbios name, machine name or domain name -- administrator privilege is needed to scan a machine, but otherwise there is no limit on what can be scanned. While HFNetChk produces a text output of recent hotfixes, MBSA provides a windowed environment, grades the severity of the problem and provides links to Microsoft's site where the relevant files can be examined and obtained. It also adds extra features -- it checks machines for weak or non-expiring passwords, looks for other account vulnerabilities such as multiple administrators on the same machine, checks SQL and IIS for common misconfigurations, and also looks at Office, Outlook and Explorer. The approach it takes is quite simple-minded -- for the weak password check, for example, it tries logging in with blank, username, "password", "admin" or "Administrator" and reports back if it gets in. That's not configurable: the service check -- where MBSA sees if unauthorised services are running -- is more flexible. As standard the software looks for FTP, Telnet, RAS, Web and SMTP services, but by adding definitions to the services.txt file supplied with the analyser. It only works by name, though, so looking for unauthorised services that aren't known to Windows, such as file sharing or streaming applications, isn't possible. MBSA is quick to install and get running -- if you just want to scan the machine on which it's loaded, no configuration is required. It produces a list of problems with a straightforward ranking of red, yellow or green, together with details of each and a suggested remedy. So far, so good. Unfortunately, Microsoft is in some confusion about hot fixes and different processes -- such as Windows Update from the browser -- will give a different list of fixes required. We found it a bad idea to use MBSA on a system that hadn't been upgraded for a couple of months: it suggested old patches that themselves generated requirements for new ones, and despite repeated re-installs, downloads, restarts and checks we never managed to get a completely clean bill of health. We finally gave up after MBSA repeatedly reported a hot fix as missing when we had loaded it explicitly several times. The other aspects of the analyser were better behaved. It gave a good window onto account mismanagement, although fixing the problems usually meant following a link to the Microsoft website, chasing through a few pages of background, instructions, FAQs and so on, before finding and following the appropriate recipe. More work on automating the fix would save much time -- even just opening the appropriate management service would be welcome. It takes a couple of minutes to run per machine, and time-consuming options such as the weak password check can be disabled if a network's worth need to be looked at. MSBA is a good start, but still too slapdash to give great confidence that Microsoft has really grasped the importance of watertight security. A utility that quickly checks for various common vulnerabilities is a good idea: one that gets things wrong is a terrible idea. The analyser is still worth using, but -- of course -- as part of a bigger, structured security implementation. It's good for checking that all machines in your domain conform to your account policy, but don't get hung up on trying for a clean bill of health as there's a good chance that it will report problems that aren't there. We didn't catch it missing problems that weren't there -- false negatives being more dangerous -- but it's impossible to say that it wouldn't, nor does its behaviour give us great confidence.
Have your say instantly in the Tech Update forum. Find out what's where in the new Tech Update with our Guided Tour. Let the editors know what you think in the Mailroom.

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

16 minutes ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

59 minutes ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

1 hour ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

2 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

2 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
ramwellian

Your comments would seem pretty naive and immature. Your 'solution' appears to be, "gee, let's all just give in to the hackers and give them...

3 hours ago by ramwellian on Cloud computing security: no more oxymoron?
BugStalker

"Interesting thought ... If you installed Win7 as a dual boot on a machine that previously only had Linux, and it wrecked your Linux installation,...

3 hours ago by BugStalker on Windows 7 Declares War on GRUB
whs001

This is an excellent summary of Ubuntu and Mint and the interface differences between them. Most such articles take a very partisan position for...

3 hours ago by whs001 on A tale of two distros: Ubuntu and Linux Mint
Moley

@ewallace. Not so clear. Anyone can obtain the text, for example from here http://www.ustr.gov/webfm_send/2379. I support ACTA so long as it and...

3 hours ago by Moley on ACTA: Facts, misconceptions and questions
45283

I think WinRT is fantastic. I just wish it was an option for people that didn't want to go through Microsoft's App Store with its attendant...

6 hours ago by 45283 on Why Windows 8 needs architectural hygiene for WOA
Burn-IT

Nine people? £30m? Who's back pocket is that lot going in? And IF they say it is for new buildings, what about all the ones the government has...

7 hours ago by Burn-IT on Police set to launch three £30m e-crime hubs
ewallace

Just to be clear, nobody knows what is in the text of ACTA, here is a photograph of the text of ACTA http://twitpic.com/8h9iju as submitted to the...

7 hours ago by ewallace on ACTA: Facts, misconceptions and questions
fgvrg56

Unfortunately main issue is that ASUS is refusing to accept that they make some mistake on this version of asus Transformer prime. 1 - GPS sensor...

9 hours ago by fgvrg56 on Asus Eee Pad Transformer Prime Wi-Fi & GPS problems?
Ben Woods

@Marcus A fair question. Just talked with Archos which said it was working on an announcement for next week....

10 hours ago by Ben Woods on Archos confirms G9 Ice Cream Sandwich update schedule

Any update on this, considering the claimed "first week of February"?

11 hours ago by via Facebook on Archos confirms G9 Ice Cream Sandwich update schedule
apexwm

Bill Goodrich : Just as al_langevin pointed out, with Windows Server 2008 there is no Services for Macintosh anymore. It's gone, not available....

19 hours ago by apexwm on Windows Server 2008 drops the ball for Mac compatibility
txtrainguy

Replying to an old topic that I'm currently facing with my CEO (who is on a Mac). Our servers are primarily Windows Servers, office is about...

1 day ago by txtrainguy on Windows Server 2008 drops the ball for Mac compatibility
k0tcs3

Sure, that makes perfect sense. Pay wrong-doers money and thank them for breaching your security and pointing out your flaws, that would surely...

1 day ago by k0tcs3 on US indicts Romanian over NASA climate change hack
Random_Error

I think he's referring specifically to Android apps, as Apple do regulate their App Store, but Google seem to let any old crap onto the Android store!

1 day ago by Random_Error on RIM: BlackBerry will keep 'garbage' apps out of store
Paul Fezziwig

Keep the crap apps out?! How will they compete with Android and Apple's claim to fame of having so many life changing apps? I wonder if the media...

1 day ago by Paul Fezziwig via Facebook on RIM: BlackBerry will keep 'garbage' apps out of store