Re: [Plugins-writers] Checking Windows Patches Using Registry

From: Renaud Deraison (deraison@private)
Date: Thu May 13 2004 - 12:32:37 PDT

  • Next message: Sarju Bhagat: "[Plugins-writers] Change Script category for exim_mult_overflow.nasl"

    On Thu, May 13, 2004 at 03:24:50PM -0400, hallnk@private wrote:
    > There are some patches for Windows which are covered by more than one
    > hotfix. Accurately checking for these patches requires checking multiple
    > keys in the windows registry. One example of this is MS03-027 (Nessus
    > plug-in #11792). This hotfix is also included in the Windows XP Update
    > Rollup 1 (see http://support.microsoft.com/?kbid=826939). Therefore to
    > check if the hotfix is applied both the key
    > "HKLM\SOFTWARE\Microsoft\Updates\Windows XP\SP2\Q811493" and
    > "HKLM\SOFTWARE\Microsoft\Updates\Windows XP\SP2\K826939" must be
    > checked. If either key is present the vulnerability is patched. Between
    > the XP Update Rollup and some cases where one patch supersedes another
    > there is the possibility of false positives in scans.
    > 
    
    Good point - I've integrated your patch, thanks !
    _______________________________________________
    Plugins-writers mailing list
    Plugins-writers@private
    http://mail.nessus.org/mailman/listinfo/plugins-writers
    



    This archive was generated by hypermail 2b30 : Thu May 13 2004 - 12:33:54 PDT