Jump to content

Recommended Posts

Posted

Hi,

 

I would like to know some opinions on updates as I'm unsure of the best route to take.

 

I was wondering on the issue of applying critical/patches updates on servers. Previously I've had a couple of issues where an update has caused a server to crash and not recover without extensive repair work.

 

Currently I have several servers (2003) ticking along nicely but there is a fair amount of updates to put on if I decide to do so.

I feel its a kind of 'if it ain't broke don't fix it' policy as everything is working so well.

Crazy really that you have to think twice about applying updates in case it causes problems you didn't have in the first place.

 

Regards

Posted

Great sympathy, I'm in the same boat with a vanilla Win 2K server which hugely crashed twice a couple of years ago post applying critical updates. This took some getting back from and it was the considerable help of a colleague that eventually set us sailing again.

 

Since then I have been almost frightened to apply updates to the beast. However, l had to to attempt the Sophos update in the Easter break, all went well with the MS updates but the Sophos EM refused to apply. Life ain't easy is it!

Posted

I follow the same system as ChrisH - they are downloaded and sit there until I have the time to install them - usually during holidays.

 

The thing with updates is, if they are patching security holes, we are legally obligated to install them on any machine which holds data covered by the data protection act, as failing to do so would be failing to ensure the security of the data.

Posted
The thing with updates is, if they are patching security holes, we are legally obligated to install them on any machine which holds data covered by the data protection act, as failing to do so would be failing to ensure the security of the data.

 

That's an interesting way to spin it? Are you 100% about it? Because if so, I have a problem..

Posted
Just recently up here in the north CLEO's IIS for dishing out the latest Sophos virus definitions was brought down by applying an update.
Posted
I am pretty sure - think of it this way, you store the kids information in a filing cabinet, and you know that if you kick the thing in a certain way on that model, the cabinet just unlocks - and this is a known problem that everyone knows. This would be a violation if it weren't fixed in some way as you wouldn't be taking reasonable precautions to prevent access to that information.
Posted

Unless information is stored in a filling cabinet in a specific manner that allows someone looking for information to be able to go directly to the relevant section without rifling through other papers first then it's not covered under the DPA anyway.

 

Ben

Posted
We also let them download and then install them when needed. However, I did complete some updates the other day, had issues with RIS and VPN afterwards!!!
Posted
Unless information is stored in a filling cabinet in a specific manner that allows someone looking for information to be able to go directly to the relevant section without rifling through other papers first then it's not covered under the DPA anyway.

 

It was an example... I know it isn't specifically covered by the DPA but it is covered by the responsibility to keep things safe. Regardless of our legal responsibilities, we have a responsibility to protect the children in school.

Posted

Only install updates during Easter, Xmas or Summer Hols. That way if there is a problem I have some time to try and resolve it !!

Workstations get them as and when - easier to fix if there is a problem.

I have not had a problem with any MS updates but a few Sophos - [ cough cough ] Sigs have caused BSOD on workstations which I was not very impressed about....

Touch wood, SP2 for Sever 2003 I have just installed have not caused any problems - there is still time though !!

Posted
Only install updates during Easter, Xmas or Summer Hols. That way if there is a problem I have some time to try and resolve it !!

Workstations get them as and when - easier to fix if there is a problem.

I have not had a problem with any MS updates but a few Sophos - [ cough cough ] Sigs have caused BSOD on workstations which I was not very impressed about....

Touch wood, SP2 for Sever 2003 I have just installed have not caused any problems - there is still time though !!

 

I'm certain you're going to discover some SP2 problems! I did! :p

Posted
hehe, hopefully you will be 'OK' then! I do wish I had left the updates until the holiday though. I do like that idea suggested above. I think it's something I may implement here! :)
Posted
Only install updates during Easter, Xmas or Summer Hols. That way if there is a problem I have some time to try and resolve it !!

Workstations get them as and when - easier to fix if there is a problem.

I have not had a problem with any MS updates but a few Sophos - [ cough cough ] Sigs have caused BSOD on workstations which I was not very impressed about....

Touch wood, SP2 for Sever 2003 I have just installed have not caused any problems - there is still time though !!

 

Thats the way i do it, unless its somthing major like blaster. Sometimes i really hate doing it, as SP1 for XP made XP error when deleting files of network drives, had to get a hotfix of MS for that, SP2 caused the Applying your personal settings to hang for about 20 seconds, took months for MS to do somthing about that, so another hotfix to apply.

Posted

Patches here are set to download and prompt on servers.

I usually leave it until Friday, and keep an eye on various mailing lists and websites during the week to see if there are problems. If there are none, I install them.

Servers reboot in a staggered fashion over the weekend automatically.

Posted
Patches here are set to download and prompt on servers.

I usually leave it until Friday, and keep an eye on various mailing lists and websites during the week to see if there are problems. If there are none, I install them.

Servers reboot in a staggered fashion over the weekend automatically.

 

I'd be interested in knowing the mailing lists and websites you use? Would definitely help in tracking any likely issues! :)

Posted

There has to be a degree of risk assessment. Do you have to have the latest IE patch if you don't use a server for web browsing. Vulnerabilities affecting services connected to open ports are another matter.

 

@Geoff what do you do in a zero day scenario? Do you just patch an d pray or still wait and see, hoping IDS will see you right?

 

Would be nice to hear from Ric_ & Cybernerd on how they do things on terminal servers. Here you have end-user applications e.g. web browsers and a single point of failure. Do you segregate server access based on whether the user is a staff or student?

Posted
There has to be a degree of risk assessment. Do you have to have the latest IE patch if you don't use a server for web browsing. Vulnerabilities affecting services connected to open ports are another matter.

 

I usually look at the ISC diary posting for an overview of how critical things are. For example, here's Julys assessment.

 

http://isc.sans.org/diary.html?storyid=3120

 

what do you do in a zero day scenario? Do you just patch an d pray or still wait and see, hoping IDS will see you right?

 

Given the speed at which MS reacts to 0day exploits. I have no choice. I have to rely on my IDS/Firewall/NAC/AV.

Posted
Hi,

 

I would like to know some opinions on updates as I'm unsure of the best route to take.

 

I was wondering on the issue of applying critical/patches updates on servers. Previously I've had a couple of issues where an update has caused a server to crash and not recover without extensive repair work.

 

Currently I have several servers (2003) ticking along nicely but there is a fair amount of updates to put on if I decide to do so.

I feel its a kind of 'if it ain't broke don't fix it' policy as everything is working so well.

Crazy really that you have to think twice about applying updates in case it causes problems you didn't have in the first place.

 

Regards

 

The number one rule is to always have a backup before you make any updates or changes.At least then you can go ahead and make the updates and know that if it nacks up you can revert back to the backup. I always read what the update is for before i go ahead with applying it.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...