Home > Windows Security Tips > Patch Management Tips > MBSA: Revisiting an old friend
Windows Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

PATCH MANAGEMENT TIPS

MBSA: Revisiting an old friend


Laura E. Hunter, Contributer
09.22.2004
Rating: -4.43- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


I've noticed over the years that there's a really funny trend when it comes to Microsoft add-ons and utilities: the most useful members of the bunch tend to be [a] free, and [b] entirely under-utilized because nobody realizes that they're there. With the release of a new version of the Microsoft Baseline Security Analyzer (MBSA), it's a good time to introduce this neat little tool to those of you who aren't familiar with it, and perhaps re-introduce it to those of you who've relegated it to a closet.

MBSA is a free utility that allows you to scan anywhere from one to 10,000 computers for patch levels and various potential security "gotchas." (Unlike Windows Update, though, it does not automatically download any missing patches that it finds.) The utility runs on any machine running Windows 2000 or better, and has been localized for English, German, Japanese and French.

In addition to providing support for XP SP2, the new version of MBSA (1.2.1) has greatly improved the "help" function that provides detailed information about the issues it finds. No really, I mean it. Rather than being the stereotypical "no-help" help system, the new MBSA actually offers useful and clearly written guidance concerning where to find security patches and how to correct potential security issues. MBSA can scan for updates for Windows, SQL, IIS, Office, Exchange 2003, Content Management Server and a number of other Microsoft products. The newest version will also perform a configuration check on your Windows Firewall/ICF configuration and your Windows Update settings.

And MBSA will scan for some of the most common -- and dangerous -- security misconfigurations on Windows machines, including:

  • Unnecessary services running on workstations, such as IIS, SMTP or Telnet server.
  • Is the Guest account disabled?
  • Do local user accounts have strong passwords?
  • Are Internet Explorer security zones configured correctly?
  • On IIS servers, are the IIS sample applications installed? (Microsoft recommends against this on a production server.)
  • On SQL servers, does the all-powerful "sa" account have a strong password?

The one possible shortcoming to MBSA -- and the reason why I didn't use it all that extensively initially -- is that the MBSA GUI produces a single XML file for each machine that it scans. So if you have a large domain, it would seem that you're forced to sit and click "show next report" until your mouse fingers threaten to sue for carpal tunnel.

However, MBSA also has a command-line component that can be incorporated into any number of scripting solutions. In fact, you'll find several sample scripts on Microsoft's Web site that perform a number of tasks, including my favorite: creating a summary report from an entire MBSA scan. These scripts are freely available for download, and can be customized to suit your environment. This level of flexibility makes MBSA a useful utility in any Windows administrator's tool belt.

Laura E. Hunter is a Microsoft MVP and SearchWin2000.com site expert.


Rate this Tip
To rate tips, you must be a member of SearchWindowsSecurity.com.
Register now to start rating these tips. Log in if you are already a member.


Submit a Tip




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Patch Management Tips
How to install Windows Server 2003 patches when offline
Remote management for Windows system upgrades
How do I properly configure WSUS?
Have my Windows patches actually been installed?
Importance of managing unpatched third-party software
Critical September patch could hit Windows 2000 SP4 systems
What's hot in Microsoft security: Critical patches
Patch management; Windows Update for network security
Internet Explorer in Patch Tuesday limelight for August
One patch for Active Directory is a doozy

Patch Maintenance
DHCP Client Service error affects network security
Microsoft will release three critical patches in May
Critical patches for IE and Office released
Microsoft releases April trove of patches
PatchLink Update 6.4
What's hot in Microsoft Windows security
Importance of managing unpatched third-party software
Microsoft patch management policy
Microsoft patch maintenance and post-patch security
Patch management and Windows Update aid in network setup

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersIT DownloadsBlogs
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2004 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts