<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Windows Metafile Crib Sheet</title>
	<atom:link href="http://techblog.touchbasic.com/html/windows-metafile-crib-sheet/feed/" rel="self" type="application/rss+xml" />
	<link>http://techblog.touchbasic.com/html/windows-metafile-crib-sheet/</link>
	<description>Techblog is collection of articles covering a wide variety of tech related topics including: Linux, Microsoft, Google, web development, web design, open source, wordpress, security, and more.</description>
	<lastBuildDate>Sun, 29 Jan 2012 02:25:58 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: admin</title>
		<link>http://techblog.touchbasic.com/html/windows-metafile-crib-sheet/comment-page-1/#comment-339</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Sun, 08 Jan 2006 20:53:34 +0000</pubDate>
		<guid isPermaLink="false">http://techblog.touchbasic.com/html/?p=160#comment-339</guid>
		<description>well, then..

i guess there is no consistency across this type of issue either. my experience (and this would make sense from microsoft&#039;s perspective) has generally been, no validaton = no updates (after a certain point).

the only other things i can think of are:

- maybe windows update is messed up on your system and reporting no updates when there are still updates (i&#039;ve seen this before, a bug in some old update causes inaccurate reading of new updates resulting in always seeming up to day. the only solution i could think of at the time was to confirm each update was applied by comparing in &quot;add/remove programs&quot; and the non-express windows update page)

- different builds of windows xp, and xp service pack 2 itself, seem to have different criteria for receiving updates (some machines with sp2 installed still required 20+ updates while others need only 2-3 updates)

- for some systems (although i&#039;ve only seen this with xp sp1 and earlier versions of windows) if you don&#039;t manually go to the WU homepage and install Windows Update v6 (the new windows update agent/client) you&#039;ll get &quot;no new updates to install&quot; every time.

that being said, patches and updates can be manually downloaded and installed without validating and maybe certain security patches (ie: WMF) do still get installed via WU. just not always. feel safe yet?</description>
		<content:encoded><![CDATA[<p>well, then..</p>
<p>i guess there is no consistency across this type of issue either. my experience (and this would make sense from microsoft&#8217;s perspective) has generally been, no validaton = no updates (after a certain point).</p>
<p>the only other things i can think of are:</p>
<p>- maybe windows update is messed up on your system and reporting no updates when there are still updates (i&#8217;ve seen this before, a bug in some old update causes inaccurate reading of new updates resulting in always seeming up to day. the only solution i could think of at the time was to confirm each update was applied by comparing in &#8220;add/remove programs&#8221; and the non-express windows update page)</p>
<p>- different builds of windows xp, and xp service pack 2 itself, seem to have different criteria for receiving updates (some machines with sp2 installed still required 20+ updates while others need only 2-3 updates)</p>
<p>- for some systems (although i&#8217;ve only seen this with xp sp1 and earlier versions of windows) if you don&#8217;t manually go to the WU homepage and install Windows Update v6 (the new windows update agent/client) you&#8217;ll get &#8220;no new updates to install&#8221; every time.</p>
<p>that being said, patches and updates can be manually downloaded and installed without validating and maybe certain security patches (ie: WMF) do still get installed via WU. just not always. feel safe yet?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: babaganoosh</title>
		<link>http://techblog.touchbasic.com/html/windows-metafile-crib-sheet/comment-page-1/#comment-337</link>
		<dc:creator>babaganoosh</dc:creator>
		<pubDate>Sun, 08 Jan 2006 17:38:04 +0000</pubDate>
		<guid isPermaLink="false">http://techblog.touchbasic.com/html/?p=160#comment-337</guid>
		<description>on a machine that wasn&#039;t validated and did have auto updates turned on and this machine stays on all the time, when I manually validated and then did a windows update, a) there were no patches it wanted to apply, and b) there was a $ntuninstall912929 folder from the earlier in the day in the windows directory (meaning it had applied the latest patch and (all?0 others before that one?!  all before being validated?  So under the right conditions, auto update does work without being validated first?</description>
		<content:encoded><![CDATA[<p>on a machine that wasn&#8217;t validated and did have auto updates turned on and this machine stays on all the time, when I manually validated and then did a windows update, a) there were no patches it wanted to apply, and b) there was a $ntuninstall912929 folder from the earlier in the day in the windows directory (meaning it had applied the latest patch and (all?0 others before that one?!  all before being validated?  So under the right conditions, auto update does work without being validated first?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: admin</title>
		<link>http://techblog.touchbasic.com/html/windows-metafile-crib-sheet/comment-page-1/#comment-335</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Sun, 08 Jan 2006 05:56:45 +0000</pubDate>
		<guid isPermaLink="false">http://techblog.touchbasic.com/html/?p=160#comment-335</guid>
		<description>not sure if i&#039;m following you on that last one..

are we talking about automatic updates or manually applying patches?</description>
		<content:encoded><![CDATA[<p>not sure if i&#8217;m following you on that last one..</p>
<p>are we talking about automatic updates or manually applying patches?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: babaganoosh</title>
		<link>http://techblog.touchbasic.com/html/windows-metafile-crib-sheet/comment-page-1/#comment-334</link>
		<dc:creator>babaganoosh</dc:creator>
		<pubDate>Sun, 08 Jan 2006 03:49:45 +0000</pubDate>
		<guid isPermaLink="false">http://techblog.touchbasic.com/html/?p=160#comment-334</guid>
		<description>I just looked at a Win XP SP2 machine that hadn&#039;t been validated.  It had a folder from this AM in windows  which talked of the 912919 patch.  I validated it and did express updates.  It said there were none.  looking in the update history, I see the most recent patch that was installled was 912919 - so yeah, they may download but not install, and the PC may not be on at night. but when those issues are handled correctly, a machine that hasn&#039;t been validated seems to do OK with patches?</description>
		<content:encoded><![CDATA[<p>I just looked at a Win XP SP2 machine that hadn&#8217;t been validated.  It had a folder from this AM in windows  which talked of the 912919 patch.  I validated it and did express updates.  It said there were none.  looking in the update history, I see the most recent patch that was installled was 912919 &#8211; so yeah, they may download but not install, and the PC may not be on at night. but when those issues are handled correctly, a machine that hasn&#8217;t been validated seems to do OK with patches?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: babaganoosh</title>
		<link>http://techblog.touchbasic.com/html/windows-metafile-crib-sheet/comment-page-1/#comment-330</link>
		<dc:creator>babaganoosh</dc:creator>
		<pubDate>Sat, 07 Jan 2006 19:56:32 +0000</pubDate>
		<guid isPermaLink="false">http://techblog.touchbasic.com/html/?p=160#comment-330</guid>
		<description>wow     : (</description>
		<content:encoded><![CDATA[<p>wow     : (</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: admin</title>
		<link>http://techblog.touchbasic.com/html/windows-metafile-crib-sheet/comment-page-1/#comment-329</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Sat, 07 Jan 2006 18:04:39 +0000</pubDate>
		<guid isPermaLink="false">http://techblog.touchbasic.com/html/?p=160#comment-329</guid>
		<description>hi baba,

sounds to me like you&#039;ve cut right to the heart of the matter here..

security is about more than getting that zero-day patch that everyone&#039;s talking about and applying it before the sky falls on your head.

the fact of the matter is (and i have seen this personally on dozens of windows machines):

1. tons of people have auto updates &quot;on&quot; but set to download and not install. (great, but they never click install)
2. i have seen machines with &quot;download and install&quot; set but at a crazy time like 3am (the machine is turned off and thus updates are never applied)
3. without validating windows xp you&#039;re not getting any updates. nothing.
4. even after validating, if you don&#039;t manually go to WU Site and download the New Version of the Windows Update Client, you&#039;re not getting any updates past a certain point (the old client doesn&#039;t find new updates).

so, to make a long story short (or offer a straight answer):

-the people in your scenario will not be getting any updates from microsoft not tonight or tomorrow or ever.

and

-yes, you&#039;d think that microsoft would promote the importance of validating windows xp a little more (at least as an aspect of ensuring greater overall security) but then again, they also tried to keep the WMF thing as low profile as possible by holding off a few days for testing before releasing a patch to the public.

at the very least, Microsoft needs to smooth out the whole update process. it&#039;s just screwy, broken, and way too complicated. maybe they need to give everyone a lesson on how to &quot;manually&quot; use their &quot;automatic&quot; updates and all the quirks that surround it.. [ apply sarcastic patch here ]</description>
		<content:encoded><![CDATA[<p>hi baba,</p>
<p>sounds to me like you&#8217;ve cut right to the heart of the matter here..</p>
<p>security is about more than getting that zero-day patch that everyone&#8217;s talking about and applying it before the sky falls on your head.</p>
<p>the fact of the matter is (and i have seen this personally on dozens of windows machines):</p>
<p>1. tons of people have auto updates &#8220;on&#8221; but set to download and not install. (great, but they never click install)<br />
2. i have seen machines with &#8220;download and install&#8221; set but at a crazy time like 3am (the machine is turned off and thus updates are never applied)<br />
3. without validating windows xp you&#8217;re not getting any updates. nothing.<br />
4. even after validating, if you don&#8217;t manually go to WU Site and download the New Version of the Windows Update Client, you&#8217;re not getting any updates past a certain point (the old client doesn&#8217;t find new updates).</p>
<p>so, to make a long story short (or offer a straight answer):</p>
<p>-the people in your scenario will not be getting any updates from microsoft not tonight or tomorrow or ever.</p>
<p>and</p>
<p>-yes, you&#8217;d think that microsoft would promote the importance of validating windows xp a little more (at least as an aspect of ensuring greater overall security) but then again, they also tried to keep the WMF thing as low profile as possible by holding off a few days for testing before releasing a patch to the public.</p>
<p>at the very least, Microsoft needs to smooth out the whole update process. it&#8217;s just screwy, broken, and way too complicated. maybe they need to give everyone a lesson on how to &#8220;manually&#8221; use their &#8220;automatic&#8221; updates and all the quirks that surround it.. [ apply sarcastic patch here ]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: babaganoosh</title>
		<link>http://techblog.touchbasic.com/html/windows-metafile-crib-sheet/comment-page-1/#comment-327</link>
		<dc:creator>babaganoosh</dc:creator>
		<pubDate>Sat, 07 Jan 2006 13:34:01 +0000</pubDate>
		<guid isPermaLink="false">http://techblog.touchbasic.com/html/?p=160#comment-327</guid>
		<description>I have yet to find someone that can give me a straigt answer on this:

Most non-techies haven&#039;t gone through the genuine software validation.  But lets assume they have SP2 and automatic updates are turned on...  what are they missing by not doing the validation and manually updating?

Everyone says to go to WU and get this patch.  If non-techs don&#039;t read this blog and elsewhere, but again, have SP2 and automatic updates, would they get the patch tonight or tomorrow night?  and what else from the express list of updates would they be missing by not manually updating / walking through the validation?

I would think if they are msising anything, MSFT should be really promoting the validation and telling people the HAVE to do it to keep their machine safe?  Thanks!</description>
		<content:encoded><![CDATA[<p>I have yet to find someone that can give me a straigt answer on this:</p>
<p>Most non-techies haven&#8217;t gone through the genuine software validation.  But lets assume they have SP2 and automatic updates are turned on&#8230;  what are they missing by not doing the validation and manually updating?</p>
<p>Everyone says to go to WU and get this patch.  If non-techs don&#8217;t read this blog and elsewhere, but again, have SP2 and automatic updates, would they get the patch tonight or tomorrow night?  and what else from the express list of updates would they be missing by not manually updating / walking through the validation?</p>
<p>I would think if they are msising anything, MSFT should be really promoting the validation and telling people the HAVE to do it to keep their machine safe?  Thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: admin</title>
		<link>http://techblog.touchbasic.com/html/windows-metafile-crib-sheet/comment-page-1/#comment-326</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Sat, 07 Jan 2006 02:02:31 +0000</pubDate>
		<guid isPermaLink="false">http://techblog.touchbasic.com/html/?p=160#comment-326</guid>
		<description>Eric,

i&#039;m going to assume you&#039;re refering to the patch issued by Microsoft. 

i&#039;d be interested to know how the second trial run goes. though i&#039;m not sure why you&#039;re machine was infected.. if you got the patch direct from Windows Update.</description>
		<content:encoded><![CDATA[<p>Eric,</p>
<p>i&#8217;m going to assume you&#8217;re refering to the patch issued by Microsoft. </p>
<p>i&#8217;d be interested to know how the second trial run goes. though i&#8217;m not sure why you&#8217;re machine was infected.. if you got the patch direct from Windows Update.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eric</title>
		<link>http://techblog.touchbasic.com/html/windows-metafile-crib-sheet/comment-page-1/#comment-325</link>
		<dc:creator>Eric</dc:creator>
		<pubDate>Sat, 07 Jan 2006 01:23:39 +0000</pubDate>
		<guid isPermaLink="false">http://techblog.touchbasic.com/html/?p=160#comment-325</guid>
		<description>I installed the patch and it caused a kernel panic after booted into windows, it seems the patch installs a system service.  This servic actually appears to do some type of scan since the I/O activity of it is somewhat high, for me it caused a kernel panic every single reboot and caused an infinite loop that I could only resolve by uninstalling the patch.  I was infected with this exploit which BiteDefender 9 found on a scan, it is possible that the path does not operate correctly.  Windows update just downloaded it again, im going to run it again and see what happens.  Perhaps I got an early version and there has been a silent revision.  Wishful thanking I guess!!</description>
		<content:encoded><![CDATA[<p>I installed the patch and it caused a kernel panic after booted into windows, it seems the patch installs a system service.  This servic actually appears to do some type of scan since the I/O activity of it is somewhat high, for me it caused a kernel panic every single reboot and caused an infinite loop that I could only resolve by uninstalling the patch.  I was infected with this exploit which BiteDefender 9 found on a scan, it is possible that the path does not operate correctly.  Windows update just downloaded it again, im going to run it again and see what happens.  Perhaps I got an early version and there has been a silent revision.  Wishful thanking I guess!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: admin</title>
		<link>http://techblog.touchbasic.com/html/windows-metafile-crib-sheet/comment-page-1/#comment-324</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Fri, 06 Jan 2006 22:33:15 +0000</pubDate>
		<guid isPermaLink="false">http://techblog.touchbasic.com/html/?p=160#comment-324</guid>
		<description>Ward,

which patch did you install?

- Microsoft Official Update
- Ilfak Guilfanov version1.4
- SANS .msi installer
- ESET version1.1</description>
		<content:encoded><![CDATA[<p>Ward,</p>
<p>which patch did you install?</p>
<p>- Microsoft Official Update<br />
- Ilfak Guilfanov version1.4<br />
- SANS .msi installer<br />
- ESET version1.1</p>
]]></content:encoded>
	</item>
</channel>
</rss>

