More information on Microsoft's DNS and WINS patches
Microsoft has responded to criticism that the fixes for DNS and WINS released last Patch Tuesday as MS09-008, were ineffective. One security researcher complained that already inserted WPAD (Web Proxy Auto Discovery) entries were not removed or blocked. In a blog entry, MSRC Program Manager Maarten Van Horenbeck, said that this was intentional, as Microsoft only creates security updates to protect a system against future attacks and does not aim to undo any attack "that has taken place in the past".
He then goes on to show how WPAD entries can be verified using the MMC DNS snap-in. Microsoft's expert also expands on the background to the other vulnerabilities that the patch fixes.
- Patch Tuesday: Windows 3, Excel 0, a report from The H.
- MS09-008: DNS and WINS Server Security Update in More Detail from Microsoft.