Automatic Updates security concern

Automatic Updates security concern

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Automatic Updates security concern rusga 11-29-2007
Posted by rusga on November 29, 2007, 11:44 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi,

Is there any way of setting the AU repository so it never uses https (tcp
443) and only uses http (tcp 80)?
Or, it uses only admin allowed update servers?

This might be a bit strange, but on a highly security strict LAN with
content filtering proxy (as in this case), this imposes a security risk
since https doesn't permit content parsing. Meaning that tcp 443 rules
*must* be set at the routers/firewalls and so, default configured http
clients (browsers on out-of-the box installs for instance) end up rendering
content that they weren't suposed to.

Thank you,
rusga



Posted by Roger Abell [MVP] on November 30, 2007, 3:20 am
If you were  Registered and logged in, you could reply and use other advanced thread options
If you run WSUS then you can use group policy to configure
your machines' autoupdate client to use only your WSUS
servers. If those servers are not configured to support SSL
on tcp 443 then the update clients will be forced to use tcp
80 (in policy you would point them to http://yourWsus not
to https://yourWsus)

> Hi,
>
> Is there any way of setting the AU repository so it never uses https (tcp
> 443) and only uses http (tcp 80)?
> Or, it uses only admin allowed update servers?
>
> This might be a bit strange, but on a highly security strict LAN with
> content filtering proxy (as in this case), this imposes a security risk
> since https doesn't permit content parsing. Meaning that tcp 443 rules
> *must* be set at the routers/firewalls and so, default configured http
> clients (browsers on out-of-the box installs for instance) end up
> rendering
> content that they weren't suposed to.
>
> Thank you,
> rusga
>
>



Posted by rusga on December 6, 2007, 6:11 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Roger, sorry for the lag and thanks for the reply.

Had to find time to read about what a WSUS server is ;-)

Is that the only way to do it? No registry hacks?

Seems a bit of an administrative overload and target prone for poisoning a
whole LAN.

Also, isn't that a way of bypassing MS's responsability on clean update
sources?

Thank you,
rusga

> If you run WSUS then you can use group policy to configure
> your machines' autoupdate client to use only your WSUS
> servers. If those servers are not configured to support SSL
> on tcp 443 then the update clients will be forced to use tcp
> 80 (in policy you would point them to http://yourWsus not
> to https://yourWsus)
>
> > Hi,
> >
> > Is there any way of setting the AU repository so it never uses https
(tcp
> > 443) and only uses http (tcp 80)?
> > Or, it uses only admin allowed update servers?
> >
> > This might be a bit strange, but on a highly security strict LAN with
> > content filtering proxy (as in this case), this imposes a security risk
> > since https doesn't permit content parsing. Meaning that tcp 443 rules
> > *must* be set at the routers/firewalls and so, default configured http
> > clients (browsers on out-of-the box installs for instance) end up
> > rendering
> > content that they weren't suposed to.
> >
> > Thank you,
> > rusga
> >
> >
>
>



Similar ThreadsPosted
Automatic XP Updates August 27, 2006, 6:21 pm
Automatic Updates April 17, 2007, 7:32 am
Re: Automatic updates November 5, 2008, 7:29 am
Automatic Updates greyed out January 29, 2006, 12:45 pm
Problems with Automatic Updates May 24, 2007, 1:00 pm
WinXPSP2 IE 7 Security Zones - security concern November 29, 2007, 12:28 am
Automatic Security Update March 19, 2006, 9:07 am
Security settings on the Terminal Server prevent automatic logon September 12, 2005, 3:18 am
Parental Concern April 4, 2006, 1:51 pm
Concern about Outlook S/Mime encryption and smartcards November 20, 2007, 9:44 am

The site map in XML format XML site map

Contact Us | Privacy Policy