GTSC Security Response Team Microsoft Asia Limited ( ) 2
Agenda 3 No Yes or 4
OS etc HFNetChk Microsoft Baseline Security Analyzer (MBSA) 5 HFNetChk shavlik HFNetChk 6
HFNetChk HFNetChk XML DB XML DB http://download.microsoft microsoft.com/download/ xml/security/1.0/nt5/ja/mssecure mssecure.cab 7 Microsoft Baseline Security Analyzer 1.1 MBSA SUS HFNetChk 8
HFNetChk MBSA HFNetChk XML DB MBSA GUI SUS 9 Microsoft Security DB ( ) Security Report IIS SQL Exchange Windows, IE, Office, Media Player 10
SUS SUS SUS Security Report IIS OS, IE SUS 11 HFNetChk and MBSA 12
13 or or No No Yes Yes 14 US US - (Security Bulletin) Security Bulletin) - (FAQ) FAQ) (KB) KB) 0 day day 2 days days 7 days days Security Security Bulletin Bulletin + FAQ FAQ KB KB FAQ FAQ KB KB
- 1 1. 2. 3. 15-2 4. 16
17-3 5. 5. (KB) KB) ( ) Internet Explorer Internet Explorer Windows Windows (325192) (325192) http://support. http://support.microsoft microsoft.com/default..com/default.aspx aspx?scid scid=kb; =kb;ja ja;325192 ;325192 6. 6. http://www. microsoft.com/.com/japan japan/technet technet/security /security /current.asp /current.asp 18 Bugtraq Bugtraq CERT/CC CERT/CC IPA/ISEC IPA/ISEC JPCERT/CC JPCERT/CC Virus Virus
19 or or No No Yes Yes 20
microsoft.com/.com/japan/security/sicinfo.asp :0120-69 69-0196 : 9:30 12:00/13:0019:00 21 - MS02-069 069 Microsoft VM (810030) Microsoft VM 22
23 24 or or No No Yes Yes
Win 9x Windows Update System Management Server (SMS) Microsoft Software Update Services (SUS) 25 Software Update Services SUS Windows Update Windows 2000 Server SP2 Internet Explorer 5.5 26
SUS Ver2.2 Windows 2000 SP3 Windows XP SP1 27 Software Update Services SP1 Server Windows 2000 Small Business Server IIS Lockdown [ ] Client 28
Windows Update Internet Intranet SUS 29 Windows Update Internet Intranet B A SUS SUS 30
Security Update Service 31 32
33 34
Appendix Microsoft Security microsoft.com/.com/japan/security/ TechNet Security microsoft.com/.com/japan/technet/security/ Windows 2000 Server microsoft.com/.com/japan/technet/security/prodtech/win dows/windows2000/staysecure staysecure/default.asp Best Practices for Applying Service Packs, Hotfixes and Security Patches microsoft.com/.com/technet/security/bestprac/bpsp.asp Windows 2000 Server microsoft.com/.com/japan/technet/security/tools/chklist/ w2ksvrcl.asp : Windows 2000 Common Criteria (( ) microsoft.com/.com/japan/technet/security/issues/w2kcc wp.asp Windows 2000 microsoft.com/.com/japan/technet/security/issues/w2kcc adm/default.asp 17 microsoft.com/.com/japan/technet/security/current.asp 35 Appendix Internet Explorer Windows (325192) 17 http://support.microsoft microsoft.com/default..com/default.aspx?scid=kb;ja;325192 Microsoft Baseline Security Analyzer 1.1 MBSA 8 microsoft.com/.com/japan/technet/security/tools/tools/m bsahome.asp HfNetChk 6 microsoft.com/.com/japan/technet/security/tools/tools/hf netchk.asp Software Update Services SUS 27 microsoft.com/.com/japan/windows2000/windowsupdate/ sus/ 14 microsoft.com/.com/japan/technet/security/bulletin/notify.asp HFNetChk ( 7 36) microsoft.com/downloads/details..com/downloads/details.aspx?displaylang =en&familyid FamilyID=9989D151-5C55-4BD3-A9D2-B95A15C73E92 36
TechNet Windows 2000 Server Exchange 2000 Server CD 37