Showing posts with label mbsa. Show all posts
Showing posts with label mbsa. Show all posts

Wednesday, March 21, 2012

MBSA and MSXML 2.6

Dear All,
MBSA is saying that I currently have MSXML 2.6 SP2, and that I should
upgrade to SP3. When I did a search on the net, not only is SP3 not
publicly available, it is also included in MS SQL 2000 SP3 that I
already have installed.
How come I am still getting these errors from MBSA despite my servers
having MS SQL 2000 SP3 installed?
Is there a way to manually check my version of MSXML 2.6?
Has anyone had a similar problem?
Thanks.
Aramid"Aramid" <aramid@.hotmail.com> wrote in message
news:63drc112j512d4dntnt2t5q3butk2v51h3@.
4ax.com...
> Dear All,
> MBSA is saying that I currently have MSXML 2.6 SP2, and that I should
> upgrade to SP3. When I did a search on the net, not only is SP3 not
> publicly available, it is also included in MS SQL 2000 SP3 that I
> already have installed.
> How come I am still getting these errors from MBSA despite my servers
> having MS SQL 2000 SP3 installed?
> Is there a way to manually check my version of MSXML 2.6?
This may seem funny but it's no joke: the only KB article I could find, for
checking the XML version called by IE was to get filemon.exe from the
SysInternals.com site, open an XML file with IE, locate the reference to
msxml?.dll in filemon output, and get its properties to check its version.
Here's the article, it's a scream:
http://support.microsoft.com/defaul...kb;en-us;296647
This one is also an interesting read, and it contains links to the how-to
for upgrading your installed parser:
http://support.microsoft.com/defaul...kb;en-us;269238
-Mark

> Has anyone had a similar problem?
> Thanks.
> Aramid

MBSA 2.0/SQL Server 2005

When will there be a version of MBSA that does the SQL Server checks for SQL Server 2005. MBSA 2.0 does not.

Thanks,
SharonSuch a version is worked on but there is no release date set yet.

Thanks
Laurentiu|||Thanks!

Sharon|||

Sharon asked the question about MBSA and SQL Server 2005 in november 2005 - has there been any progress on this yet?

MBSA 2.0/SQL Server 2005

When will there be a version of MBSA that does the SQL Server checks for SQL Server 2005. MBSA 2.0 does not.

Thanks,
SharonSuch a version is worked on but there is no release date set yet.

Thanks
Laurentiu|||Thanks!

Sharon|||

Sharon asked the question about MBSA and SQL Server 2005 in november 2005 - has there been any progress on this yet?

sql

MBSA 1.2 and slammer

Does MBSA 1.2 check for sql slammer vulnerability?"Ender Wiggins" <ender@.nospam.com> wrote in message
news:uaK$J3GGFHA.548@.TK2MSFTNGP14.phx.gbl...
> Does MBSA 1.2 check for sql slammer vulnerability?
>
I do not believe it does, Microsoft released a separate scanner:
http://www.microsoft.com/security/incident/slammer.mspx
Steve|||MBSA will flag any unpatched SQL/MSDE server. The latest service pack is
sp3a, which contains the Slammer patch.
Thanks,
Kevin McDonnell
Microsoft Corporation
This posting is provided AS IS with no warranties, and confers no rights.|||"Kevin McDonnell [MSFT]" <kevmc@.online.microsoft.com> wrote in message
news:jMesNoQGFHA.400@.TK2MSFTNGXA02.phx.gbl...
> MBSA will flag any unpatched SQL/MSDE server.
Good to know, thanks Kevin!|||No worries.
Thanks,
Kevin McDonnell
Microsoft Corporation
This posting is provided AS IS with no warranties, and confers no rights.|||Thanks kevin.
The slammer scan that MS provides only scans a few machines in the domain
and sometimes just fails sometimes when run on windows 2003 server.
"Kevin McDonnell [MSFT]" <kevmc@.online.microsoft.com> wrote in message
news:NOvS1WTGFHA.2424@.TK2MSFTNGXA02.phx.gbl...
> No worries.
> Thanks,
> Kevin McDonnell
> Microsoft Corporation
> This posting is provided AS IS with no warranties, and confers no rights.
>
>|||The SLammer tools where designed to identify both MSDE and SQL machines
that were unpatched.
I would recommend using MBSA 1.2 to scan your servers for missing Windows
and SQL updates. If we fail to scan the
Windows 2003 Server, please let me know the details.
Thanks,
Kevin McDonnell
Microsoft Corporation
This posting is provided AS IS with no warranties, and confers no rights.

MBSA "Identity"

My Windows login is a domain administrator. I run MBSA and ask it to scan only my computer. I have removed Builtin\administrators from the sysadmin role in my SQL Server 2000 installation. The login is still there. MBSA is still able to get into my SQL Server and report that there is a guest user in Northwind and Pubs. It does not, however, report on the logins with weak passwords, which it did when Builtin\Administrators was a member of sysadmins. This leads me to believe that it does use the BuiltIn\Adminstrators login to access the SQL Server. Is this correct?

Thanks,
Sharon

I've been looking for an answer to your question. I'll post back when I'll get one.

Thanks

Laurentiu

|||

MBSA connects with the user credentials and the analysis it can do will depend on the user rights. If you connect to the server thorugh the Builtin\Administrators group login and not some dedicated login, and if you removed this login from the sysadmin group, then MBSA will perform the checks as a non-privileged principal.

Thanks

Laurentiu

|||

Thanks. That's what I determined from my testing and I am glad to have it confirmed.

Sharon