As of this patch day (Nov 2007) the agent-less security patch scanner, basically hfnetchk under the name of MBSA 1.2.1 is now dead and there is no direct replacement from Microsoft, They do recommend one of our products to help out but its not a full solution by itself. MBSA 1.2.1 was the most widely used agent-less patch scanner ever released, and for good reason - it quickly helped people secure networks.
(As a disclosure or marketing notification, depending on your perspective: Shavlik Tech continues to provide a state-of-the-art agent-less security patch command line scanner based on hfnetchk and mbsa 1.2.1, we wrote both of them with and for Microsoft. Be aware that this is the only one available in the security markets with current patch support and true agent-less support, many vendors are using the word agent-less when they require agents, or they only run locally meaning they cannot be used to scan networks -- possibly a slight failure in truth in advertising but that is for you to decide. More info is at http://www.shavlik.com/netchk_analyzer.aspx).
What does this mean? first - you need to stop using MBSA 1.2.1 at once, its dead, pull it from your scripts, remove it from your tool kits. Use our products or other products but do not use MBSA 1.2.1. If you go with just the free WSUS be aware that it does not even support all of Microsoft's products, much-less other products like itunes, real-player etc that have security patches, and WSUS only works on computers that are running WSUS, there is no more agent-less scanning from Microsoft unless you use the product Microsoft recommends, which is of course our product to close the gap. You may be happy knowing WSUS says you are secure, but the bad guys are even more happy because they will use agent-less scanners to find the missing patches on your network, and finding a machine w/o a WSUS agent is easy to do, and finding one with a WSUS agent that is not doing full patching is also easy to do.
As a short history we wrote MBSA for Microsoft so many years ago now, with a core value of agent-less and deep, full product scanning, something now missing in the free products from Microsoft. 1000s of companies use (or used it) MBSA 1.2.1 to secure millions of computers. They did this because agent-less scanners find all the computers on your networks then do deep scans looking for all products, not just a few.
Why do I care so much about an old, somewhat out dated free product? Of course my preference is people buy our products and the death of MBSA 1.2.1 helps us there, but for those that do not buy from us, or someone else, it was nice knowing MBSA 1.2.1 was out there working away. Another concern I have is that no one seems to realize what the death of MBSA 1.2.1 means, yes, you can buy our products and others, but it also means there is no more free agent-less patch scanners from Microsoft, a big reason companies are now able to patch, and to double check they are doing a good job at it. It also may mean people will become less patched, and less secure and not know it because they do not have a way to double check things in a reliably way, and worse they will run MBSA 2.0 and get less information than MBSA 1.2.1 + MBSA 2.0 + Enterprise Update Scan Tool (the old way) gave.
MBSA 1.2.1 Obit examples: there are more examples, these are just two I quickly copied into this post
(http://www.microsoft.com/technet/security/bulletin/ms07-049.mspx)
MBSA 1.2.1 does not support detection for this security update. The Enterprise Update Scan Tool does (MARK: I do not think this scans beyond the machine its running on so be ware), and is what customers can use instead of MBSA 1.2.1. For download links and more information about the version of EST that is being released this month, see Microsoft Knowledge Base Article 894193. SMS customers should also see the heading, Systems Management Server, for more information about SMS and EST.
The following table provides the MBSA and EST detection summary for this security update.
Microsoft Virtual PC 2004 |
No |
Yes |
Yes |
Microsoft Virtual Server 2005 |
No |
Yes |
Yes |
Microsoft Virtual Server 2005 R2 |
No |
Yes |
Yes |
Microsoft Virtual PC for Mac Version 6.1 |
No |
No |
No |
Microsoft Virtual PC for Mac Version 7 |
No |
No |
No |
icrosoft Baseline Security Analyzer
Microsoft Baseline Security Analyzer (MBSA) allows administrators to scan local and remote systems for missing security updates as well as common security misconfigurations. For more information about MBSA, visit Microsoft Baseline Security Analyzer.
The following table provides the MBSA (MARK: no MBSA 1.2.1 support) detection summary for this security update.
Windows XP Service Pack 2 |
Yes |
Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2 |
Yes |
Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2 |
Yes |
Windows Server 2003 x64 Edition and Windows 2003 Server x64 Edition Service Pack 2 |
Yes |
Windows Server 2003 with SP1 for Itanium based systems and Windows Server 2003 with SP2 for Itanium based systems |
Yes |