Home
Evaluation Guide
Contents
1. a ul ER lerts Repository Push r i i P 82378 i i 823803 TE E 823980 i i i P NN i i Y 224146 pd E n JER i h gg 828035 0828750 exe ECORAQA VMWXPPM WindowsServer201 ECORAQA BACH WindowsServer201 ECORAGA OMAHA ECORAGA VM2KADVSVR SP1 ECORAGA WMXPPO1 JUNNYEARS M Patch Found Patch Found M Patch Found ES Missing Patch 828750 exe ES Missing Patch ia exe M503 040 Manage Notes Approve Push Ignore Patch Approve Rollback Comment The following registry key has not been found SOFTWARE Microsoft Internet Explorer A ctivex Compatibility 4DB88046 D8FF 11CF 9377 0044003B 7411 HotFix 828750 Patch Not Found Explanation of analysis More Detailed Comments bE Windows Service Packs e Wed Oct 22 18 06 14 2003 E E Wed Oct 22 18 17 38 2003 AN a 3 0 828750 The following registry key has been found SOFTWARE Microsoft Internet Explorer ActiveX Compatibility 970C7E08 0547 11D0 8944 0040C09054129 Click here to retrieve the Microsoft KnowledgeBase Article Click here to download this patch now cumulative patch for Internet Explorer that affects a wide range of systems and includes fixes for vulnerabilities with existing exploits in circulation Ecora Software Corporation 8 9 Scroll down until you locate 828750 D For more information on this specific patch http www microsoft com technet treeview default asp url technet security bulle
2. ALBANY Server AMY V M Server BACH Server o BUNNYEARS ae Tip If possible select devices in DAYTON ae a DENYER Workstation a test lab or non production NEWYORK Sever 1 orkstation capacity The following sections OMAHA Serve include the deployment of a PORTLAND Server patch which should always be a0 tested In a minimum risk A Workstation No situation VM OFF2KSP2 POr ECORAGA WM SPANISHOFFIC Server No T Tip If you wish to use agents FrnRa nd VMXPPM Mark station NA the Start up Guide includes a Setete IE Avelet section on deploying agents from this dialog box Ecora Software Corporation 5 8 Click on the Systems Management 2x button aoe Properties Group name 9 Click on the New button sa XX est group 10 Enter a name such as test_ group Group description and description for the new group for the Patch Manager evaluation and click OK 11 Selectme AN Systems group ax in the upper pane so you can Group Windows Systems see all the discovered systems System Settings Agent Settings System Settings 12 In the lower pane use CTRL System Name a System Hole click or SHIFT click to select m some or all of the systems and NT Domain PEN es m click Add to Group mm na less Tip Usemame field should be entered as A Domain User name domain account or User 13 Select the new group from the User name Albion Admimis
3. Ecora Patch Manager 5 0 Evaluation Guide Table of Contents Mie A eS HAR ene 3 Ecora Patch Manager 5 0 OVErviCW ccccsceccssecsscerseeseeeesecnseesesaustseeetseseuenseusnseusnseseees 3 ASCANIO do te 4 DISCOVEF GrOUD SS Ca AO 5 Optional Exercises for Added Value kvis svens osar Brr der rr rr rr 11 APDOFOVAalS amp NOTCS irradia 11 USING PONCY Manada AAA 12 SOLANAS id il dla ico das 14 sie 1120 101 ER eo Gall AA oo A EN SANNE SENASTE rented A A A A esr eueeaees 16 Senequie AGENTS CaS ADA AA AA 17 Use the Onine Reporting Centers a 18 CONdrRAtUIatIOOS nc AA 19 GUISEOMMER Sup DO tbc cr ia iaa de 19 O Ecora Software Corporation 2 I ntroduction Patch Manager is an IT management and security tool that automatically discovers and analyzes missing or installed patches for mission critical platforms and applications The software displays the status of patch configurations provides information about the latest versions of security patches and hotfixes and allows administrators to deploy patches in groups individually or during off hours Software security and consistency can be easily maintained across the enterprise with Ecora s Patch Manager Ecora Patch Manager 5 0 Overview Sure Scan Rapid Scan Flexibility Your choice of Sure Scan analysis including file integrity verification for greatest accuracy and security or Rapid Scan for fastest results Customization Extensibility Customize or extend Patc
4. SEATTLE ECORADA 14 In the lower left pane select the All Systems _ TELLURIDE ECORADA TELLURIDE ECORAQA group then click the Apply button 15 Click OK then Close to return to the GUI O Ecora Software Corporation 11 Using Policy Manager Create a Policy Policies allow you to create generalized rules about how you want systems in your environment configured presumably secured to the latest critical patches You may choose to prioritize certain groups for stricter policies for applications you consider higher risk Policies allow you to define these rules apply them to groups you create then schedule scans to ensure that you re always aware of systems that do not comply with your policies Since we ve tested patch 828750 and approved it for distribution HA let s create a policy that all systems in the test group must have 828750 installed to be in compliance oe Ecora PM5 Evaluation 1 Choose Tools Policy Management from the menu 2 Click the New button to access a dialog for creating a policy 3 Enter a name such as test policy and description such as Ecora PM5 evaluation for the new a Selection Criteria policy and click OK Platforms Applications Patches 4 In the Create Policy dialog box on sacar BR DAR the Selection Criteria tab click on the IA us a Maid P I atfo r m Ss ta b E Nests en sa T Use the plus and minus icons to E windows 2000 Server expand or col
5. and your company s bottom line The main user interface of Patch Manager Ecora Software Corporation 4 Discover Group amp Scan E Scan Wizard Ax 1 Click on the Scan button Settings 2 Choose the Scan Type Sure Scan or Rapid Scan and click Next gt 7 Sure Scan analysis includes file AA integrity MD5 checksum verification for greatest accuracy and security Rapid Scan analysis skips file integrity check for greater speed and Sure S can analyzes patches using file integrity verification fa ste r resu Its d i S p a y Sure Scan 3 Click on the Discover Systems button Please choose which scan type to use as your default scan type Rapid S can analyzes patches without using the file integrity verification F Hosts discover Rh Discover Options l P C Active Directory js NetBIOS Specify NetBIOS name ARR Doma Specify hosts EREN domain name Computer computer name Add 4 Select a network discovery option For this evaluation choose NetBI OS or Active Directory Els Hosts discover 21xj Domain selecti nian iced from fle Gave toile 2KDC1CHILD Click on the Next gt button Double click to select the domain s to discover and click Next gt 7 Double click to select a few 3 5 systems and click Finish Highlight All Selected ssp Beane Caos Computer Name lpAddress ComputerRole Selected E
6. as installed A El Huss saca WSDE 2000 r EDFA MDAC28 veda Peyer Orce 20 lt E on No 1009 20 15 2003 Internet Explorer 6 Intemet Explorer 6 SP1 2 All systems Follback Installed Pad Name i 2 CORA ZOO ANDER ty Patch Found Led SL exe El ys ThuNow 6 11 1240 2003 g vaming a FIGH gu i H wed Nov 5517 32 2003 Y Af amnng A MEDIUM Llao Ll exe Rf E dl Missing Superseded MEDIUM 322925 EXE 822925 Ev MEDIUM 024929 eve ow SY YP Ecora Software Corporation 10 Optional Exercises for Added Value Approvals amp Notes Patch Manager provides the ability to add notes and conditions to each patch This allows you to record your test findings or comments approve patches for approval or rollback and set certain patches to be ignored in analysis We have verified successful installation of patch 828750 and will now approve it for distribution and enable required approvals Combined with policies next section required approvals further tighten security controls 1 To enable approvals choose File Settings 212 General Settings Number of threads to use 64 Notify me if have not checked for updates in 5 days Skip the checksum Freferences 2 Click in the Require approval for installation rollback checkbox and click OK 3 Choose Tools Patch Attributes Management from the main menu V Store system credentials Don
7. Click the Policy button 2 Click on the Policy tab in the left p a n e l El Ecora Patch Manager e xj Fie Edit view Tools License Help 3 Click on the plus sign to lar E Es LO ER be i Scan Reports Test Center Systems Schedule Alerts Repository Push Update What s This expand the tree until you Ej Mar ecora locate your policy Al Installed Missing Hosts Product Policies Results E E Thu Det 23 11 09 20 2003 Policy Test Policy E E Thu Oct 23 12 24 51 2003 a 4 Select the policy in the left pane to see which systems E E Policies J Does Not Comply BUNNVEARS ECORADA i i E ye Test Policy Do Complies WIN2KDCBU ECORAQA comply in the right pane 9 Bp 9 Cooke WINK ECORAGA i 6 E Wed Oct 22 18 17 38 2003 By Complies VS SMS20 ECORAGA Y Tip Notice that any DO Compies VMXPPOT ECORADA systems that do NOT comply me have a checkbox for Do Complies VM SVE2KSERV ECORAGA remediation which includes Yoo Se lite omplies both installation and DO Complies VM2KADVSVR SP1 ECORAGA rollback if necessary to Mes TENPE copan Bp Compies TELLURIDE ECORAGA bring the system Into 19 Complies STORAGE ECORADA compliance with the policy O e ae or 3 0 Test Policy OY If you want to remediate by 4 policy select the checkbox click Push and follow the Patch Installation instructions Ecora Software Corporation 13 Set an Alert This section is strictly optional but
8. note in the Subject field Subject Mi M 7 Click OK 8 Click on the Triggers tab 9 Click New 10 On the Basics tab enter a Name and Description Ecora Software Corporation 14 21 xi 11 On the Condition tab select Scan zixi Tom he TYPE drop down list and Basics Condition Message Alerts Patch Missing as the Condition BESS Condition 12 Select the test group and verify the Type Scan al patch threshold IS 10 Condition Patch Missing kal 13 Accept the default on the Message tab Filters Group testou ial 14 On the Alerts tab click in the Threshold lid El patches checkbox next to the Alert you created and click OK 15 Click Close i ie E Send an email alert SNMP Alerts LL Send an SNMP alert Windows Event Log Alerts E Send an information event log alert Ecora Software Corporation 15 Schedule a Scan Let s schedule a scan for overnight for you to Name Production Scan review in the morning Description All production systems weekly 1 Click on the Schedule button 2 Click on the New button 3 Enter a name such as Evaluation Scan and a description for the task Override scan settings 4 Click OK Scan Settings H igh ight you r group and Cl ick the N Sure S can analyzes systems using file integrity verification Select button Click OK On the Task tab use the Run as field and use the Set Password but
9. t ask for scan description 4 Click on the Patch Name column head to sort by the patch name 5 Scroll to locate patch Q828750 exe and select it Ux Patches Require approval for installation rollback Y Tip You may see multiple listings for the patch a L ono This is because Microsoft releases one for each 2 NET Framework 1 0 NET Framework 1 7 i NET Framework 1 NET Framework 1 yen of IE being patched 14 NET Framework 1 1 NET Framework 1 1 6 Click the Properties button a ae 7 sUNWecsnd 10408 03 Click on the Approve Push tab 18 SUNWsnmag 104018 03 3 sUNwsnmet 104018 03 8 Click in the radio button for Approved for 110 SuNWsnmpd 10401803 a a SUNWeeefg 104018 09 installation SUNWccrev 104018 09 104018 09 9 In the lower left pane double click on All Systems to approve the patch for the All Systems group A ES 10 Verify the selection in the lower right results pane Approve Push and click the Apply button ApprovePush Approved for installation 11 On the Manage Notes tab click New C Not approved for installation 12 Name the Note or accept the numbered default Systems and Groups Available and click OK B All Systems i ps BOSTONECORADA BOSTON ECORAGA 13 Place the cursor in the text field and enter text clic a for the note perhaps Pushed without incident PORTLAND ECORAQA PORTLAND ECORAQA i SEATTLE ECORAQA
10. 0217 1436 16 Every day at 1300 TEAT I2EDCICHILD CHICAGO Online io 112 Up To Date 2005 02 17 13 35 22 Every day at 13 00 2005 00 17 12 04 4 EDCICHILD MEMPHIS Ondine ha 112 Up T Oe 2005 02 17 T20 Emery dap at 18 00 2005 02 17 12 04 44 MILWAUKEE Onire 101 112 Up To Date 2006 02 17 132608 Every day at 1900 2005 00 17 12 04 4 CHILDDCT Onine D 01 112 Up To Date 2005 02 17 13 35 28 Every day ot 1800 2005 00 17 12044 ALEXEI LORA Up To Date 2006 02 17 13 35 38 Every day at 19 00 2006 00 17 12004 4 AQDEVSERVER Onine ji UpToDate 2005 0217 1236 22 Every day amp 19 00 2005 02 17 12044 BE NLEYXP hnne Up To Date 2006 02 17 13 35 28 Every day at 19 00 2008 00 17 1204 BOSTON 1 01 112 Up To Date 2005 0217 13 36 22 Every day t 19 00 2005 08 17 12 044 DAYTON jnn Up To Date 2005 0217 13 36 15 Every daya 19 00 2005001712044 IMALACHIZI Onine tot ite Up To Date 2006 02 17 43 35 24 Every day at 18 00 2006 00 17 1204 MAMI Oni 101112 UpToDate 2005 0217 13357 Every day at 19 00 2005 02 17 12044 MANZO On 101 112 Up To Date 2005 02 17 13 36 24 Evesy day ar 19 00 2006 00 17 12084 i Mm o EE A E FE mmama Tae 1 Choose Tools Agents or click on the Agent button 2 Locate and select the agent you wish to schedule 3 Click the Schedule Analysis button and set the frequency for automatic analysis on a recurring basis S Schedule Scan HX 4 Click in the checkbox to Enab
11. 1 Click on the Rules tab Selection Criteria Patches 12 Click on plus signs to expand each Faces Et Bein oat betas Mustnorbe stated paa version of Internet Explorer to see a eee eee cam patches locate patch 828750 MZ 324929 MS02 068 C O G pe 0328970 exe 328970 MS02 066 O 9 wherever it occurs and click in a a a a k radio button Must be I nstalled G7 0813489 ere 813489 MS03 015 O i i be P Q818529 exe 818529 MS03 020 O amp Your policy IS thus that ANY Windows gi 0822925 EXE 822925 MS03032 C O system running the specified version MES 09257500 828750 MS03040 6 c c of Internet Explorer MUST have this ei ed lr S l patch installed and click OK aaa de o ea G Internet Information Services 5 0 Windows 2000 Gold 13 Click OK to close aral irion cares Bl eaa A Ser G Internet Information Services 5 0 Windows 2000 Servi Apply the Policy 1 Click Yes when asked if you d like to attach the policy to systems or El Policies Selection 2 x Available Policies choose Tools Policies Select Al S el e cti on EY Test Policy Ecora PM5 Evaluation Select the policy in the upper pane Policies Management 3 Select the test group you created in the lower pane 4 Click on the Attach Policy button to apply the policy to the test group 5 Click OK Systems and Policies Policies for the current system group Attach Policy Detach Policy View by Policy Compliance
12. Engine MSDE 20007 Patcher 100 Oi out of 1 patches installed Missing SCA Server 2000 Patches 50 3 out of 6 patchesinstalled Missing Windows Media Payar 6 4 For Windows NT d O Patches Hie i out of 5 patches installed Missing Windows NT Workstation 40 Patches 67 22 out of 69 patches instilled E OFA DAA TON Missing Intenet Explorer 6 Matches T Sout d 5 patches installed Missing Windows Media Player for Windows XF Palehes T EL of 3 patehas installed Missing Windows XP Professonal Parches i 21 wit nF Fi parha inci aller E DORADA DAYTON Mining Tahanmak Seplnrer El dape h 17 rhat 17 pashrhes installed Missing Microsoft SOL Server 2000 Desktop Engine MSDE 20001 Potchi 100 0 out of 2 patches instnded Missing Windows Media Player for Windows XP Palches De 6 out of E patches installed Mising Wineries XP Profacenal Patches AS rad nf AE patches inal Ecora Software Corporation 18 Congratulations You have implemented Ecora Patch Manager conducted a security patch analysis of hosts in your environment and responded immediately to detected vulnerabilities by deploying a high exposure patch all from your desk If you proceeded with the optional exercises you have also tried the Test Center approved a patch for deployment established a model patch policy compared your systems to it and scheduled a scan and an alert Patch Manager enables you to immediately r
13. J ALBION Execute Immediately fr AR 12 Schedule Execution Transfer Only Date Time 12 28 2005 12 02 39 F Apply settings to all machines Job Description Enter a description of this job here Pushing Patches 2 x Complete Copy file Success C Program Files Ecora Patch Manager 3 0 bin pushinstaller_main exe Copy file Success C Program Files Ecora Patch Manager 3 0 bin gchain exe Create file Success ecoraPM_2003 11 10_9 39 html Schedule rescan of system s Create directory Success WZO0LANDERdmin T emp Ecora 0 Repo move Success q828750 exe Create file Success model xml Schedule task Success ecoraPM_2003 11 10_9 39 ZOOLANDER Successfully transfered files and scheduled job oa J Enable rescan scheduling Rescan systems 15 minutes after installation ME Credentials for local system Le system from where Password the scan will initiate E E Verify Successful Patch Deployment Scan the test group again Once complete click on the Hosts tab Locate the host you selected to update with 828750 Click on the All button to show all patches installed missing warnings Click on the IE tab in the upper right pane to show IE patches Verify that the Ta Ecora Patches lal x host you File Edit View Tools License Help ee oD E El pa updated shows 3 Test Systems patch 828750 Schedu Aler FRepostory Fresh Update X ecora
14. Y 828105 i ECORAQA Y 824141 gp 824146 825119 P POE File Edit view Tools License Help E P 826232 i P 828035 Explanation of analysis N A Click here to retrieve the Microsoft KnowledgeBase Article i a P Click here to download this patch now i ie B Windows Service Packs Ey E E Wed Nov 515 17 32 2003 My Notes Article HS03 040 3 0 828750 Y O Ecora Software Corporation 9 2x E The following patches are not download 3 Note If the patch is not already downloaded perform Patch th ese steps Q828750 exe Not Downloaded a Click Download to download patches selected for push b In the repository dialog select the patch and choose Download Now vs scheduling for later E c Click OK d Once the patch has lol xi successfully downloaded Repostoy WWRITERDEBYepo al E click Close ES ES ES Size KB 0828750 exe Not Downloaded English windows 2152 gG2Byj1ACcQ LKB2Y9ShXGQ ENU 5 In the Push dialog box veri fy tha t 0828750 Exe Not Downloaded English windows 2275 TERRA i the host and patch are correct 5 6 Ena ble the Execute Patch Description Cumulative Patch for Internet Explorer 828750 I mmediately option to install now vs scheduling for later 7 Enter a job description Click Push Click OK to accept the job global settings without any overrides 10 Once the push has finished click OK S A
15. educe your infrastructure s risk and to proactively maintain security on an ongoing basis Customer Support Ecora Sales representatives are available to answer your questions about product features and pricing at 1 877 923 2672 or email sales ecora com Ecora technical support representatives are available to help resolve any technical issues at 1 877 923 2672 ext 771 or email Support ecora com Don t forget to read the User Manual available in fully hyperlinked format in the online help system as well as in printable PDF format at http www ecora com ecora um patchmanager 5 0 user_manual patchmanager5 0 pdf Ecora Software Corporation 19
16. expand Click on the Products tab in the left pane to see summary information about the configurations in your environment such as IE versions and service packs This view helps you enforce version consistency and therefore performance security and compliance across the entire enterprise We are looking for a specific patch so click on the Patches tab Click on the All button for all information installed and missing patches and service packs Click on the plus sign s in the left pane to expand the tree for Windows Patches For the sake of this evaluation we ll look for patch 828750 MS03 040 a 10 x Es Ecora Patch Manager File Edit View Tools License Help E E Ez 2 kul E bel Bl te Te Te Center is tems Schedule Alerts Repository Push Update What s This e C ord a E ae Nov 6 11 2003 E E Wed Nov 5 15 17 32 2003 amp HH All Systems B test By ECORAQAWOSTON 33 ECORAGA DENVER BE CORAQA NEWYORK Bay ECORAGA PORTLAND ECORAGA SEATTLE ly ECORAGA TELLURIDE Media Player Tf eT e 309521 MS01 054 Q309521_x86 exe 4 MEDIUM OS msja MEDIUM OS 0817606_WXP_S5P2_x8b exe w Missing Service Pack IE Internet Explorer 6 SP1 windows XP Service Pack 1 0323172 WXP_SP1_x86 exe 0324380_WXP_SP1_x86 exe F Missing Patch 816093 MS03 011 817606 MS03 024 Service Service Pal Xx Missing Patch Service Service Pal 323172 MS502 048 324380 MS02 051 el 09 nar n Mis
17. h Manager to support any applications and patches you define Wake on LAN Ensure the broadest and most accurate security analysis by having Patch Manager start offline systems prior to starting a scan Cross platform support Support for Sun Solaris Windows NT 2000 XP Pro 2003 MS SQL Server MSDE Exchange 5 5 amp 2000 Office 2000 XP Windows Media Player IE IIS MDAC WINZip MS XML Adobe Acrobat Optional Agent Reduce network utilization scans performed locally improve support for laptops other sporadically connected devices and hardened hosts with no remote registry or file sharing requirements Reporting Center Review comprehensive ready made reports that provide details from a managerial to technical level accessible centrally or web based Sure Scan Ensures accurate analysis of missing patches in your environment by dynamically updating its database to include the most current patch information Patch Manager uses both registry and file integrity checks to analyze your systems 3 D Patch Views Quickly see what critical patches are missing and or installed in your environment by host application or patch in sortable displays Patch Rollback Automate removing a selected patch if conflicts develop due to a patch installation Alerting Alert on multiple events including new patch databases new patches for a specific OS or application patches missing or failed patch installation Repository Ma
18. ing Center Microsoft Internet Explorer Automatically document analyze and fortify your IT infrastructure Ecora Patch Manager helps secure your systems from vulnerabilities but that s ont half the battle Are you regularly tracking system configuration changes Do you have current documentation to enable rapid system recovery How about a detailed audit trail to satisfy IT auditors If not click here to learn more about Ecora s automated solutions for reducing risks to the IT infrastructure and your company s bottom line E EDDRAQ A fadminttrator apart Repara DOC hemnet ECORAGA ALBANY Missing Inbemet Explorer E 01 Patchar FO 3 out of 1 patchar metad Missing Internet Informator Services a0 Patches 100 0 cut of 2 patches irstaled Missing Windows 2000 Server Patches ET 17 out of 34 patches installed Mircing Windows Media Player 6 4 For windows 2000 Patches 204 4 out of E patchec inctaled E ORAQA BOSTON 1 Mercina Tebennat Explorer 5 01 Patchar 50 3 1 put of 2 parher instabed Messina SOL Server 2000 Patches 505 3 out of 6 patches installed A a e a a le ee 0 mm ici ee Missing Windows 2000 Server Patches 33 4 cut of 6 patches installed Missing Mind Media Player ib For l nder PORT Eabha CPR E cut of E patches installed BOUR AA BUNNSYERRS Mercina Internet xplorar E Jahas 16 G out of ane natal Missing Microsoft SOL Server 2000 Desktop
19. introduces you to the tip of the iceberg in automating scheduled scans and using Ecora s proactive alerting capabilities Alerts are a method of notification based on a trigger you define AAN EA Interval 10 is minutes 1 Choose File Settings and click on the SNMP Alerts Alerting tab O Enable SNMP Manager 2 In the Alerting area click in the Enable Port 182 3 ch eckbox Email SMTP Alerts V Enable 3 Accept the 10 minute interval for how often the pp software checks for the conditions you define Pott 25 5 i f Max attachment size 10240 KB 4 Inthe Email SMTP Alerts area click in the A areGecoracon UlLlLll Enable checkbox to enable alerts via email 5 Enter the SMTP Server name Port number and the Maximum Attachment Size reports can get large The SMTP Server is generally your mail server such as mail companyname com 6 Click OK Set an Alert Basics We ll create an alert for too many SNMP Alert Basics mM iSSI n o patch es Name JE valuation Test Alert O Windows Event Log Alert Notify me by email 1 Choose Edit Alerts Triggers from the menu Description 2 Click on the Alerting tab 3 Click New 4 Select Email Alert and click OK 5 On the Basics tab enter a Name such as Evaluation Test Alert E and Description for the alert e A 1 a 1 gt 6 On the Email tab enter your email address in the To O field and enter a reminder
20. lapse the tree i Fl windows erver 4 5 g CI ick In the checkbox for each F dor a cle 1 0 Erte Edition Wi n d OWS O S ve rs O n E Windows NT Server 4 0 Terminal Server Edition E Windows NT Workstation 4 0 E Windows Server 2003 for Small Business Server 6 Click on the Applications tab E Windows Server 2003 Datacenter Edition E Windows Server 2003 Enterprise Edition E Windows Server 2003 Standard Edition Click in the Display All checkbox E Windows Server 2003 Web Edition Windows lt P Professional 8 Click in the checkbox for the relevant version s of Internet Explorer such as version 6 0 9 Click on the Patches tab P Tip If desired click and drag the Platforms Applications column heading dividers to resize the a elect the software application s you wish to include for this colu mM NS x FrontPage 2000 id FrontPage 2002 a pat with the application s you select will be affected 10 Click on plus signs to expand the tree ete eon en se the plus and minus icons to expand or collapse the tree by application to see patches In this a eet Este 50 fo Windows Server 2003 case leave all patches set to Ignore RR RR cados so the policy applies regardless of A ES er installed status You could choose to have a policy apply ONLY if a given patch was installed or not installed Systems are displayed in Policy view only if they meet the selected criteria Ecora Software Corporation 12 1
21. le scheduled analysis Oj Daly 5 Choose Daily Weekly or Monthly for C Weekly On Thusa E the frequency of automatic analysis C Monthly 6 Set the start date day and or time for recurring scans Sure Scan i 7 Click OK O Ecora Software Corporation 17 Use the Online Reporting Center The reporting center is a website interface created by Ecora to provide an intuitive way to query the Patch Manager database The URL can be accessible to anyone in an environment who can access the share on which you installed the reporting center ClOs or auditors can see a report of Policy Compliance across all systems IT staff might be interested in the Patch History of a machine 1 Click on the Reports button to access the online reporting center installed on an IIS server during setup 2 If prompted enter your login and password and click OK 3 Select the Missing Patches report from the drop down list 4 Click in the checkbox for the test group Click Go 6 Browse the resulting report Verify that there are no instances of the IE patch 828750 missing 7 Change the report to Pushed Patches and the group to All Systems Click Go Browse the resulting report for IE patch 828750 installed on test group systems Y Reporting Lenter ierosaft Internet teplorer Ele gdt jew Favores Tool Hel Onaga dn 00 28 33 COTA Reporting Cantor sommarn o E E 3 Report
22. nager Automatically schedule patch downloads to repositories in your enterprise so patches are always readily available for immediate deployment International Language Support Supports international versions of Microsoft and Sun operating systems including Danish Dutch French Finnish German Italian Japanese Norwegian Portuguese Spanish Swedish and United Kingdom O Ecora Software Corporation 3 I nstall the Software This Evaluation Guide assumes that you have successfully downloaded installed and configured Ecora Patch Manager Df you have not please refer to the Start up Guide located on Ecora s Support webpage http www ecora com ecora um patchmanager 5 0 startup_quide patchmanager5 0 paf You should be here J I I j de i 1 275 Ti T E q gt qero a Chick the SCAN button to automatically start asalyring pour network for missing and installed petches for your mis ston critical applications and operating systenars Automatically document analyze and fortify your IT infrastructure Evora Patch Manager helps secure your systeme from vyulnerabdibes but that s only half the battle a Are pou regulary tracking system configuration changes a Da row have current d oumentabon to enable rapid system recovery Hga about a detailed sudit trail to satisfy IT suditors if not click here te learn more about Ecora s automated solutions for reducing risks to the IT infrastructure
23. r i Exchange Server 2003 i LJ Exchange Server 5 5 i LJ FrontPage 2000 i FrontPage 2002 i CJ FrontPage 2003 i BA Internet Explorer 5 01 Internet Explorer 5 5 FE Internet Explorer 6 pa FE Internet Explorer 6 0 for Windows Server 2003 i E Internet Information Server 4 0 i J Internet Information Services 5 0 i J Internet Information Services 5 1 iT Internet Information Services 6 0 h C MDAC 2 5 5 ave Fes HV ons JV EBM sp KBM Windaws2000sp s En cal E An AC m a 22 n the right pane locate and select the patch es to analyze For this evaluation leave all selected 23 Click Finish to begin scanning systems for patches 24 Enter a Scan Description and click OK O Ecora Software Corporation 7 31xi Review Scan Results L Once scanning is complete notice that the left window pane contains three tabs that allow you to choose how to organize the results Click on the Hosts tab Click on the plus sign s in the left pane to expand the tree for one of the hosts and select a host to see the results for that system in the right panes Click on the Missing button to see information about patches and service packs that need to be installed to bring the system up to the latest security fixes As you select items in the upper right pane notice that the lower pane contains details such as test notes vendor articles and informational links Click on a plus sign to
24. sing Service Pack os s ES Missing Patch os ES Missing Patch os Severity 4 MEDIUM The victim would need to visit a website under the attacker s control or receive an HTML e mail from the attacker Automatic exploitation by an HTML e mail would be blocked by Outlook Express 6 0 and Outlook 2000 in their default configurations and by Outlook 98 and 2000 if used in conjunction with the Outlook Email Security Update al Article MS03 011 nd 3 0 ECORAQA DENVER Es bcora Patch Manager Ble Edit View Tools License Help E E E E te Test Certer Sustem Schedu Bal Installed Missing TE Polisy Pioducts E E Thu Oct 23 11 09 20 2003 E windows Products g 2 Exchange E 9 IIS E Internet Cxsloier i E Internet Explore 5 31 Irternet Exblo er 5 01 Gold bo j Itarnel Explue 5 91 Ir temel Exolu e 5 01 lt P1 j E Intemet Explore 5 5 Internet Exporer 55 SP2 po l Intanet Explue 6 Irtemel E xalo 5 Cult A Internet Explore 6 E z e Internet Explore 6 3 for windows Serel 2003 windows E Repository Bel 8 Updas What s Tais ecord Internet Explorer 6 Internet Explorer 6 SP1 Results ESORACIA ESORADA con 404 WH2CA4D0WS3W P1 WHW PPM YHPrI 3 0 Interret Explorer 5 Internet Explorer 6 lt P1 T Ecora Patch Manager File Edit view E License Help E I ES E a El hedule A EE Missing LE Policy Patches Bel ol el Update what s This ecora
25. tin MS03 040 asp http www ciac orqg ciac bulletins o 002 shtml 10 Click on patch 828750 The right pane should display a list of machines scanned as well as their status regarding 828750 Look for the icons to indicate the status Patch was detected as installed x Patch was not detected as installed 11 Click on the Missing button to filter out machines with the patch installed The result is a list of machines that need to have 828750 installed Y Tip Should you have no machines needing this patch CONGRATULATIONS Pick another patch use the lower right pane for information about each and follow the remaining instructions Install a Patch T CAUTION It is strongly recommended for this trial and as a general practice that all patches be tested before deployment in the production environment Particularly in environments with custom software or mission critical applications it is not worth risking potential conflicts or adverse reactions with an untested patch Identify a system on which to install patch 828750 Locate the checkbox in the Push column Click in the Push checkbox to enable patch installation of 828750 for the host Click on the Push button in the toolbar Be Es Ecora Patch Manager x z i Es e LN El be ial Test Center Alerts it Push 5 A Schedule Repository Update What s This e C ora Results i A 823718 1 Status Domain Name TE 823980 f Missing Patch ECORADA
26. ton to enter credentials with administrative access 8 Click on the Schedule Systems Selection Ax ta b Select Systemes Groups Available Systeme in group testgraup 9 Click New to create a Windows 25 Unix 0 schedule a System NTDomain OS Tes 10 Set the task to run daily at 2 00 AM so you ll have BOSTON ECORAGA windows 2000 2 AAA P a scan to review in the k fta mornings 11 Click Apply 12 Click OK Groupi bject 13 Click Close TY Tip Tomorrow morning choose File Open to load the scheduled scan Be sure to click on the Policy view 2x ax button to see the results of yO ur scan En CAWINDOMWS Tasks E valuation Scan job fi At 2 00 AM every day starting 10 27 2003 with your New Delete pol ICY a ppl ied f 3 0 bin EcoraPatchkmanager exe b Evaluation Scan Schedule Task Start time Browse Daily 200 AM Stark in Schedule Task Daily Comments Task scheduled by Ecora Software A Every fi A day s Aun as eco RAsadmir Set password Task Schedule Settinge Task Schedule Settinge a J Enabled scheduled task runs at specified time W Show multiple schedules Cancel Apply OK Cancel Apply Schedule Agent Scans Let s schedule recurring scans for the agents if you deployed any EL Agent MAN Consola Up To Dale Latest Agent Person fi 01 173 E 260CICHILD am a hinna lUpToDate 2005
27. trator name local account In the second case Patch d ro p d own ist an d cl ick O K Manager converts the User name to Password System User name format 14 Select the new test group in the as upper pane and click on the Properties button 15 Click on the Windows Systems tab 16 Enter a Username in domain user format and Password and click OK 17 Click OK to close systems management En Systems Management Y 21 x Manage Systems Groups 1 Si test group for the Patch Manac Delete Properties 18 Select the test group Deploy Agents Windows 2 Unix 0 Search IP address UserName 0S m Discover DOLFIN ALBION 192 168 55 12 XP SHERIFF ALBION 192 168 55 1 03 Se Properties Deploy Agent Close Ix a TI O Ecora Software Corporation 6 19 Click on the Select Products and Patches tab 20 Click in the checkbox to enable Use Selective Scan to limit analysis to specific products or patches 21 Use the tree in the left pane to locate and select only I nternet Explorer all versions under Applications to analyze Ex Scan Wizard System Selection Select Systems Select Products and Patches Use selective scan Products ed i L aM All Operating Systems Applications i C NET Framework 1 0 i E NET Framework 1 1 i LJ Access 2000 i LJ Access 2002 i Access 2003 i C Direct 7 0 ic Exchange 2000 Enterprise Server z CJ Exchange 2000 Serve
Download Pdf Manuals
Related Search
Related Contents
Fujitsu ESPRIMO VFY:E7935PF021ES PC Snapper EP2167517BV, ERP2167517BV Lawn Mower User Manual Radio Shack 16-3009 User's Manual P5AD2 Deluxe specifications summary HP Officejet Pro 8620 e 取扱説明書 ご使用前に必ずご確認ください Generac Power Systems 004701-0 Portable Generator User Manual Copyright © All rights reserved.
Failed to retrieve file