September 2007 - Posts

Microsoft Security Bulletin Re-Release - 27th September

 

Summary
The following bulletin has undergone a major revision increment.
Please see the appropriate bulletin for more details.
  * MS07-042 - Critical


Bulletin Information:
* MS07-042 - Critical
- http://www.microsoft.com/technet/security/bulletin/ms07-042.mspx
- Reason for Revision: Bulletin Updated: Added Microsoft Office
    Compatibility Pack for Word, Excel, and PowerPoint 2007 File
    Formats and Microsoft Expression Web as affected products.
    The Bulletin has also been updated to inform customers that a
    potential reliability issue exists in applications that have
    installed Microsoft XML Core Services 4.0 on Windows Vista,
    which can be addressed by applying the download available in
    Microsoft Knowledge Base Article 941833. 
- Originally posted: August 14, 2007
- Updated: September 27, 2007
- Bulletin Severity Rating: Critical
- Version: 2.0

Posted by Cliff | with no comments

Gradually getting online again...

Well in case you're wondering I've been having a nightmare of late. For some weird and wacky reason I got delivered a patch a couple of weeks ago ironically via SMS. It was something to do with the MSI Installer (I think), and I was prompted that I'd need to reboot within 24 hours for it to complete.

Later that night I shutdown my machine and powered it on the following morning which is when the fun began because as soon as the machine attempted to access the network it blue screened.

I tried uninstalling the patch but no joy. Turning off ZoneAlarm helped but in the end unfortunately it came down to a complete PC rebuild. So I've had the joy of data backups, rebuild, and reload to go through and I'm far from done yet.

Oh the joys of technology and as per usual  no-one can explain why this happened. Apparently I'm the only reported case of this but there again I am special, I leave you to decide in which way ;-)

Posted by Cliff | with no comments
Filed under: ,

Windows Server 2008 News

Thought I'd pass this on:

"In an effort to keep you up-to-date on news related to the Windows platform, I wanted to let you know that Microsoft has reached another milestone with the Release Candidate (RC0), of the Windows Server 2008 operating system, which is now available for download. With this release, Microsoft’s industry partners and customers can download and experience not only the most versatile and reliable Windows platform yet, but also a Community Technology Preview (CTP) of Windows Server virtualization. For more information, please see our PressPass feature http://www.microsoft.com/presspass/features/2007/sep07/09-24windowserverrc0.mspx .

Microsoft has also announced the release of Windows Vista SP1 Beta 1 to a select group of approximately 12K testers.  This release focuses on addressing specific reliability and performance issues, supporting new types of hardware, and adding support for several emerging standards.  SP1 also addresses some management, deployment, and support challenges.  In addition to Windows Vista SP1, we are also announcing that last week Windows XP SP3 beta was released to select OEMs, ENT and ISV testers."

Posted by Cliff | with no comments

Only download your patches directly from Microsoft...

Those clever (and whatever other names you want to call them), hackers have come up with another new way of downloading Trojans to your machines.

Simple, just send out an email that contains Microsoft Patches BUT with a Trojan embedded. So you think you're getting the real deal when in fact you're getting more than you bargained for.

My advice? Use Windows Update or if you have to manually download a patch PLEASE do so ONLY from the MS website.

Posted by Cliff | with no comments

Changes are afoot...

Well things are changing on the WMUG web site. We've just completed the upgrade to Community Server 2007 which gives us a great number of benefits which you'll soon see.

By the way we're VERY close to announcing our first meeting, just a few more i's to dot and t's to cross - keep yours eyes open.

Posted by Cliff | with no comments
Filed under: ,

New KB Articles At Microsoft 23 Sep 2007 - Weekly Summary


SQL Server 2005

938912 FIX: In a maintenance plan, the databases that you selected are no longer selected when you edit a Back Up Database task in SQL Server 2005 Service Pack 2

938697 FIX: Error message when you run a query that references a temporary table in SQL Server 2005: "Internal error. Buffer provided to read column value is too small. Run DBCC CHECKDB to check for any corruption"

938911 FIX: Event ID: 21421 occurs when you use the Microsoft Operations Manager 2005 agent to monitor a clustered instance of SQL Server 2005 in a clustered environment

938913 FIX: Error message when you run a maintenance plan that contains a Back Up Database task in Microsoft SQL Server 2005 Service Pack 2: "0x80004003: Object reference not set to an instance of an object"


Systems Management Server 2.0

941462 On a computer that has Microsoft System Center Configuration Manager 2007, Microsoft Systems Management Server 2003, or Microsoft Systems Management Server 2.0 installed, a layered window is not displayed in the remote client session


Systems Management Server 2003

941461 How to manually determine the license and sale origin channel information for a software product when the Asset Intelligence reports in SMS 2003 with Service Pack 3 do not report the correct channel information

939872 Reports that use the v_Add_Remove_Programs view stop responding and cause high CPU use in SMS 2003 SP3

937330 Users may unintentionally start the installation process and lose data after you deploy an SMS 2003 OSD image to client computers

938504 Error message when you try to run the DMInstaller_CE4.2_ARM.exe file on a Windows CE 4.2-based device: "DMInstaller_ce4.2_arm is not a valid Windows CE application"

New KB Articles At Microsoft 16 Sep 2007 - Weekly Summary


Operations Manager (MOM) 2005

933616 When many alerts occur at the same time, Notification Workflow Solution Accelerator version 2.1 does not send notifications in MOM 2005

Microsoft Security Bulletin Summary for September 2007

1 Critical and 3 Important patches this month:

Critical Security Bulletins
MS07-051 - Vulnerability in Microsoft Agent Could Allow Remote Code
Execution (938827)
  - Affected Software:
    - Microsoft Windows 2000 Service Pack 4
    - Impact: Remote Code Execution
    - Version Number: 1.0

Important Security Bulletins
MS07-052 - Vulnerability in Crystal Reports for Visual Studio Could
Allow Remote Code Execution (941522)
  - Affected Software:
    - Visual Studio .NET 2002 Service Pack 1 (KB937057)
    - Visual Studio .NET 2003(KB937058)
    - Visual Studio .NET 2003 Service Pack 1 (KB937059)
    - Visual Studio 2005 (KB937060)
    - Visual Studio 2005 Service Pack 1 (KB937061)
    - Impact: Remote Code Execution
    - Version Number: 1.0

MS07-053 - Vulnerability in Windows Services for UNIX Could Allow
Elevation of Privilege (939778)
  - Affected Software:
    - Windows Services for UNIX 3.0 on Windows 2000 Service Pack 4
    - Windows Services for UNIX 3.5 on Windows 2000 Service Pack 4
    - Windows Services for UNIX 3.0 on Windows XP Service Pack 2
    - Windows Services for UNIX 3.5 on Windows XP Service Pack 2
    - Windows Services for UNIX 3.0 on Windows Server 2003 Service
      Pack 1 and Windows Server 2003 Service Pack 2
    - Windows Services for UNIX 3.5 on Windows Server 2003 Service
      Pack 1 and Windows Server 2003 Service Pack 2
    - Subsystem for UNIX-based Applications on Windows Server 2003
      Service Pack 1 and Windows Server 2003 Service Pack 2
    - Subsystem for UNIX-based Applications on Windows Server 2003
      x64 Edition and Windows Server 2003 x64 Edition Service Pack 2
    - Subsystem for UNIX-based Applications on Windows Vista
    - Subsystem for UNIX-based Applications on Windows Vista x64
      Edition
    - Impact: Elevation of Privilege
    - Version Number: 1.0

MS07-054 - Vulnerability in MSN Messenger and Windows Live Messenger
Could Allow Remote Code Execution (942099)
  - Affected Software:
    - MSN Messenger 6.2
    - MSN Messenger 7.0
    - MSN Messenger 7.5
    - Windows Live Messenger 8.0
    - Impact: Remote Code Execution
    - Version Number: 1.0

Posted by Cliff | with no comments

Microsoft Security Bulletin Minor Revisions - 12th September

Summary
The following bulletins have undergone a minor revision increment.
Please see the appropriate bulletin for more details.
  * MS07-054 - Important
  * MS07-051 - Critical


Bulletin Information:
* MS07-054 - Important
  - http://www.microsoft.com/technet/security/bulletin/ms07-054.mspx
  - Reason for Revision: Download center links added to Affected
    Software table for upgrading to Windows Live Messenger 8.1 
  - Originally posted: September 11, 2007
  - Updated: September 12, 2007
  - Bulletin Severity Rating: Important
  - Version: 1.1
* MS07-051 - Critical
  - http://www.microsoft.com/technet/security/bulletin/ms07-051.mspx
  - Reason for Revision: Bulletin updated to include FAQ as to why
    up-level platforms are not affected by this vulnerability. 
  - Originally posted: September 11, 2007
  - Updated: September 12, 2007
  - Bulletin Severity Rating: Critical
  - Version: 1.1

Posted by Cliff | with no comments

New KB Articles At Microsoft 9 Sep 2007 - Weekly Summary


SQL Server 2000

941825 You cannot upgrade the named instance of SQL Server 2000 Desktop Engine Service Pack 3a that is installed together with Application Center 2000 Service Pack 2 to SQL Server 2000 SP4


SQL Server 2005

912914 How to use a stored procedure to monitor traces in SQL Server 2005

941823 Some or all SQL Server 2005 services are not listed in SQL Server Configuration Manager, or you receive a "No SQL Server 2005 components were found" error message when you perform operations in SQL Server 2005 Surface Area Configuration

941152 Error message when you run a distributed query against a loopback linked server in SQL Server 2005: "Transaction context in use by another session" or "MS DTC has cancelled the distributed transaction"

Posted by Cliff | with no comments

SMS 2003: Rebuilt Hierarchy not showing in the SMS Admin Console

If you've rebuilt your SMS Hierarchy using the Site Repair Wizard but it isn't reflected in the SMS Admin Console it could be because you didn't specify the Site Addressing information... [Go to article]

Posted by Cliff | with no comments

Blow your own trumpet...

... as no-one will do it for you as the saying goes.

Well here goes. Out of the blue a few weeks ago I got an email from Steve Lamb who is the UK Microsoft Evangelist responsible for Management. Steve wanted to come to see me to record a podcast talking about me, my views on Management, FAQShop and of course ConfigMgr 2007.

I have to be honest that I was a bit reluctant at first as a) I'd never done anything like this before and b) I didn't know if anyone would be interested in hearing me talk but Steve put my mind at rest and we went ahead and did the recording.

So if any of you are suffering from insomnia hopefully this WON'T help - let me know either way:

TechNet Conversations Podcast Show with Cliff Hobbs talking Management

Like I say in the podcast I'm still on lookout for a web developer to help me with the next version of the site so if you or anyone you know is up to the job get in touch.

ConfigMgr Site Map Updated

I've been busy updating the Microsoft System Center Configuration Manager 2007 Site Map with a ton of new content and links. Feel free to drop by and check it out.

You'll also start to see ConfigMgr-related articles appearing on the site so watch this space...

Posted by Cliff | with no comments

New KB Articles At Microsoft 2 Sep 2007 - Weekly Summary


Operations Manager (MOM) 2005

936161 The MOM service may crash in discovery in MOM 2005


SQL Server 2005

940943 FIX: The performance of a query that performs an insert operation or an update operation is much slower in SQL Server 2005 SP2 than in earlier versions of SQL Server 2005

939564 FIX: You receive an incorrect result when you use a SQL Native Client provider to read the data on the client computer in SQL Server 2005

941151 How to enable the SQL Server 2005 Integration Services process to generate a dump file when the process experiences exceptions

940371 FIX: Error message when you run a query that selects many columns and that joins many tables in SQL Server 2005 Service Pack 2: "The query processor could not produce a query plan"

941184 FIX: An application that is included in SQL Server 2005 may stop responding when you specify a network protocol that is not valid in the application

940948 FIX: Error message when you use Database Engine Tuning Advisor to tune a database in SQL Server 2005 Service Pack 2: "An unhandled win32 exception occurred in dtaengine90.exe [4308]"

940376 FIX: Error message when you use the Bcp.exe utility together with the queryout option in Microsoft SQL Server 2005: “BCP host-files must contain at least one column”


Systems Management Server 2003

940619 After you install Systems Management Server 2003 Service Pack 3, the Client Configuration Manager may return incorrect error codes when a remote client computer is unreachable

940122 How to use the Microsoft Group Policy Diagnostic Best Practice Analyzer (GPDBPA) tool to collect and to analyze data