Rocksolid Light

Welcome to RetroBBS

mail  files  register  newsreader  groups  login

Message-ID:  

Beeping is cute, if you are in the office ;) -- Alan Cox


computers / alt.windows7.general / PrintNightmare: Update your PC immediately

SubjectAuthor
* PrintNightmare: Update your PC immediatelyMichael Trew
+* Re: PrintNightmare: Update your PC immediatelyJo-Anne
|+* Re: PrintNightmare: Update your PC immediatelyPaul
||+- Re: PrintNightmare: Update your PC immediatelyJ. P. Gilliver (John)
||+- Re: PrintNightmare: Update your PC immediatelyFrank Slootweg
||`* Re: PrintNightmare: Update your PC immediatelyStan Brown
|| `* Re: PrintNightmare: Update your PC immediatelyWolffan
||  `- Re: PrintNightmare: Update your PC immediatelyStan Brown
|+* Re: PrintNightmare: Update your PC immediatelyVanguardLH
||`* Re: PrintNightmare: Update your PC immediatelyJ. P. Gilliver (John)
|| +* Re: PrintNightmare: Update your PC immediatelyPaul
|| |`- Re: PrintNightmare: Update your PC immediatelyFrank Slootweg
|| +* Re: PrintNightmare: Update your PC immediatelyVanguardLH
|| |`* Re: PrintNightmare: Update your PC immediatelyJ. P. Gilliver (John)
|| | `* Re: PrintNightmare: Update your PC immediatelyVanguardLH
|| |  `* Re: PrintNightmare: Update your PC immediatelyJ. P. Gilliver (John)
|| |   `- Re: PrintNightmare: Update your PC immediatelyFrank Slootweg
|| `- Re: PrintNightmare: Update your PC immediatelyMayayana
|`* Re: PrintNightmare: Update your PC immediatelyMerle
| `* Re: PrintNightmare: Update your PC immediatelyJ. P. Gilliver (John)
|  +- Re: PrintNightmare: Update your PC immediatelyMerle
|  `* Re: PrintNightmare: Update your PC immediatelyPaul
|   +* Re: PrintNightmare: Update your PC immediatelyPeterC
|   |`* Re: PrintNightmare: Update your PC immediatelyPaul
|   | `- Re: PrintNightmare: Update your PC immediatelyPeterC
|   `* Re: PrintNightmare: Update your PC immediatelyJ. P. Gilliver (John)
|    `* Re: PrintNightmare: Update your PC immediatelyPaul
|     `- Re: PrintNightmare: Update your PC immediatelyJ. P. Gilliver (John)
+* Re: PrintNightmare: Update your PC immediatelyMayayana
|+* Re: PrintNightmare: Update your PC immediatelyFrank Slootweg
||+* Re: PrintNightmare: Update your PC immediatelyMayayana
|||`- Re: PrintNightmare: Update your PC immediatelyPaul
||+* Re: PrintNightmare: Update your PC immediatelyStan Brown
|||`* Re: PrintNightmare: Update your PC immediatelyFrank Slootweg
||| `* Re: PrintNightmare: Update your PC immediatelyPaul
|||  `* Re: PrintNightmare: Update your PC immediatelyFrank Slootweg
|||   `- Re: PrintNightmare: Update your PC immediatelyChar Jackson
||`* Re: PrintNightmare: Update your PC immediatelyJ. P. Gilliver (John)
|| `- Re: PrintNightmare: Update your PC immediatelyJava Jive
|`- Re: PrintNightmare: Update your PC immediatelyStan Brown
+* Re: PrintNightmare: Update your PC immediatelyDavid E. Ross
|+* Re: PrintNightmare: Update your PC immediatelyPaul
||`* Re: PrintNightmare: Update your PC immediatelygfretwell
|| `* Re: PrintNightmare: Update your PC immediatelyPaul
||  `* Re: PrintNightmare: Update your PC immediatelygfretwell
||   `- Re: PrintNightmare: Update your PC immediatelyStan Brown
|+* Re: PrintNightmare: Update your PC immediatelyDavid E. Ross
||`* Re: PrintNightmare: Update your PC immediatelyPaul
|| `- Re: PrintNightmare: Update your PC immediatelyJ. P. Gilliver (John)
|`- Re: PrintNightmare: Update your PC immediatelyFrank Slootweg
`* Re: PrintNightmare: Update your PC immediatelySailfish
 `* Re: PrintNightmare: Update your PC immediatelySailfish
  +* Re: PrintNightmare: Update your PC immediatelyStan Brown
  |+- Re: PrintNightmare: Update your PC immediatelySailfish
  |`- Re: PrintNightmare: Update your PC immediatelyFrank Slootweg
  `- Re: PrintNightmare: Update your PC immediatelySailfish

Pages:123
PrintNightmare: Update your PC immediately

<scivkt$hd4$2@dont-email.me>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1911&group=alt.windows7.general#1911

  copy link   Newsgroups: alt.windows7.general
Path: i2pn2.org!i2pn.org!eternal-september.org!reader02.eternal-september.org!.POSTED!not-for-mail
From: mt999999@ymail.com (Michael Trew)
Newsgroups: alt.windows7.general
Subject: PrintNightmare: Update your PC immediately
Date: Mon, 12 Jul 2021 23:00:46 -0400
Organization: A noiseless patient Spider
Lines: 37
Message-ID: <scivkt$hd4$2@dont-email.me>
Mime-Version: 1.0
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Tue, 13 Jul 2021 03:00:45 -0000 (UTC)
Injection-Info: reader02.eternal-september.org; posting-host="6015105dccdd92302bcc69863bee9cae";
logging-data="17828"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/WKVFVDuIB3fPQQYkcws6G"
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.28) Gecko/20120306 Thunderbird/3.1.20
Cancel-Lock: sha1:YA6IfXZdCafM9zDS7z8DXbVkEAs=
 by: Michael Trew - Tue, 13 Jul 2021 03:00 UTC

Microsoft issues urgent security warning: Update your PC immediately

Microsoft is urging Windows users to immediately install an update
after security researchers found a serious vulnerability in the
operating system.

The security flaw, known as PrintNightmare, affects the Windows Print
Spooler service. Researchers at cybersecurity company Sangfor
accidentally published a how-to guide for exploiting it.

The researchers tweeted in late May that they had found
vulnerabilities in Print Spooler, which allows multiple users to
access a printer. They published a proof-of-concept online by mistake
and subsequently deleted it - but not before it was published
elsewhere online, including developer site GitHub.

Microsoft warned that hackers that exploit the vulnerability could
install programs, view and delete data or even create new user
accounts with full user rights. That gives hackers enough command and
control of your PC to do some serious damage.

Windows 10 is not the only version affected -- Windows 7, which
Microsoft has ended support for last year, is also subject to the
vulnerability.

Despite announcing that it would no longer issue updates for Windows
7, Microsoft issued a patch for its 12-year-old operating system,
underscoring the severity of the PrintNightmare flaw. Updates for
Windows Server 2016, Windows 10, version 1607, and Windows Server 2012
are "expected soon," it said.

"We recommend that you install these updates immediately," the company
said.

<https://www.ksl.com/article/50203184/microsoft-issues-urgent-security-warning-update-your-pc-immediately>

Re: PrintNightmare: Update your PC immediately

<scjbfo$a2k$1@dont-email.me>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1914&group=alt.windows7.general#1914

  copy link   Newsgroups: alt.windows7.general
Path: i2pn2.org!i2pn.org!eternal-september.org!reader02.eternal-september.org!.POSTED!not-for-mail
From: Jo-Anne@nowhere.com (Jo-Anne)
Newsgroups: alt.windows7.general
Subject: Re: PrintNightmare: Update your PC immediately
Date: Tue, 13 Jul 2021 01:22:46 -0500
Organization: A noiseless patient Spider
Lines: 44
Message-ID: <scjbfo$a2k$1@dont-email.me>
References: <scivkt$hd4$2@dont-email.me>
Mime-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Tue, 13 Jul 2021 06:22:48 -0000 (UTC)
Injection-Info: reader02.eternal-september.org; posting-host="fff83035173e0a50a02f0de6bdc88b08";
logging-data="10324"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX19B0M+4ziRKeeqGWm9f9Zn3"
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:31.0) Gecko/20100101 Thunderbird/31.5.0
Cancel-Lock: sha1:DvHCyQNvgRUwm7n7wKq1FGtipdQ=
In-Reply-To: <scivkt$hd4$2@dont-email.me>
 by: Jo-Anne - Tue, 13 Jul 2021 06:22 UTC

On 7/12/2021 10:00 PM, Michael Trew wrote:
> Microsoft issues urgent security warning: Update your PC immediately
>
>
> Microsoft is urging Windows users to immediately install an update
> after security researchers found a serious vulnerability in the
> operating system.
>
> The security flaw, known as PrintNightmare, affects the Windows Print
> Spooler service. Researchers at cybersecurity company Sangfor
> accidentally published a how-to guide for exploiting it.
>
> The researchers tweeted in late May that they had found
> vulnerabilities in Print Spooler, which allows multiple users to
> access a printer. They published a proof-of-concept online by mistake
> and subsequently deleted it - but not before it was published
> elsewhere online, including developer site GitHub.
>
> Microsoft warned that hackers that exploit the vulnerability could
> install programs, view and delete data or even create new user
> accounts with full user rights. That gives hackers enough command and
> control of your PC to do some serious damage.
>
> Windows 10 is not the only version affected -- Windows 7, which
> Microsoft has ended support for last year, is also subject to the
> vulnerability.
>
> Despite announcing that it would no longer issue updates for Windows
> 7, Microsoft issued a patch for its 12-year-old operating system,
> underscoring the severity of the PrintNightmare flaw. Updates for
> Windows Server 2016, Windows 10, version 1607, and Windows Server 2012
> are "expected soon," it said.
>
> "We recommend that you install these updates immediately," the company
> said.
>
> <https://www.ksl.com/article/50203184/microsoft-issues-urgent-security-warning-update-your-pc-immediately>
>
>
Any idea of where the update is for Windows 7? The article doesn't seem
to say.

--
Jo-Anne

Re: PrintNightmare: Update your PC immediately

<scjhj1$b72$1@dont-email.me>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1916&group=alt.windows7.general#1916

  copy link   Newsgroups: alt.windows7.general
Path: i2pn2.org!i2pn.org!eternal-september.org!reader02.eternal-september.org!.POSTED!not-for-mail
From: nospam@needed.invalid (Paul)
Newsgroups: alt.windows7.general
Subject: Re: PrintNightmare: Update your PC immediately
Date: Tue, 13 Jul 2021 04:06:56 -0400
Organization: A noiseless patient Spider
Lines: 62
Message-ID: <scjhj1$b72$1@dont-email.me>
References: <scivkt$hd4$2@dont-email.me> <scjbfo$a2k$1@dont-email.me>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Tue, 13 Jul 2021 08:06:57 -0000 (UTC)
Injection-Info: reader02.eternal-september.org; posting-host="5ae4f633c68c34114968e5e9147ab2fc";
logging-data="11490"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX19Ow9eOKXndLQ+QMCNupbPVA8wp6xCXj3Q="
User-Agent: Ratcatcher/2.0.0.25 (Windows/20130802)
Cancel-Lock: sha1:In5bdR+gVyC2VUFd5VA19QuQNNk=
In-Reply-To: <scjbfo$a2k$1@dont-email.me>
 by: Paul - Tue, 13 Jul 2021 08:06 UTC

Jo-Anne wrote:

>> "We recommend that you install these updates immediately," the company
>> said.
>>
>> <https://www.ksl.com/article/50203184/microsoft-issues-urgent-security-warning-update-your-pc-immediately>
>>
> Any idea of where the update is for Windows 7? The article doesn't seem
> to say.

https://www.digitaltrends.com/computing/how-to-fix-print-nightmare-on-windows-right-now/

Windows 11 = 22000.65
Windows 8.1 = KB5004954
Windows 7 = KB5004953

But if you look at this right now, it's a bit of a mess. This is what
they used on the above site to find these. This link won't be valid
a month from now, and it still raises the question, which patch
happened in which month. Now, these are cumulative, but
why has a Windows 7 patch (without the word Embedded in it),
been offered month after month ? Seeing what this coughed up,
is more troubling than downloading the patch.

https://www.catalog.update.microsoft.com/Search.aspx?q=security%20monthly%20quality%20rollup%20%22windows%207%22

What I had hoped to find when going there, is that the x86 and the x64
patches would have different KB numbers, and then I would just
copy and paste the appropriate ones. But by using the same KB number,
and putting multiple entries in the catalog listing, it would be
a lot more work to copy some .msu to give a precise enough answer.

As hard as I try, I just can't prune that fucking list. I can't use
"-embedded" to remove the Embedded versions.

security monthly quality rollup 2021-07

https://www.catalog.update.microsoft.com/Search.aspx?q=security%20monthly%20quality%20rollup%202021-07%20

Anyway, enough griping. Here's a list.

*******

2021-07 Security Monthly Quality Rollup for Windows 7 for x64-based Systems (KB5004953) 375,405,645 bytes

http://download.windowsupdate.com/d/msdownload/update/software/secu/2021/07/windows6.1-kb5004953-x64_62d21485a29cad041230e4c647baeaeacc09ac7c.msu

2021-07 Security Monthly Quality Rollup for Windows 7 for x86-based Systems (KB5004953) 249,086,473 bytes

http://download.windowsupdate.com/d/msdownload/update/software/secu/2021/07/windows6.1-kb5004953-x86_076aed0ffca7ef0c30d6e4dfda0346f6b319f448.msu

*******

2021-07 Security Monthly Quality Rollup for Windows 8.1 for x64-based Systems (KB5004954) 558,526,618 bytes

http://download.windowsupdate.com/c/msdownload/update/software/secu/2021/07/windows8.1-kb5004954-x64_691dc48f8697e7dd2d138d8c6ac2a92d27927467.msu

2021-07 Security Monthly Quality Rollup for Windows 8.1 for x86-based Systems (KB5004954) 364,345,778 bytes

http://download.windowsupdate.com/d/msdownload/update/software/secu/2021/07/windows8.1-kb5004954-x86_fabac48b8c90b1cbd76fb14d0a89515e957e246c.msu

Paul

Re: PrintNightmare: Update your PC immediately

<1k65x0luf7skd.dlg@v.nguard.lh>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1921&group=alt.windows7.general#1921

  copy link   Newsgroups: alt.windows7.general
Path: i2pn2.org!i2pn.org!aioe.org!news.uzoreto.com!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: V@nguard.LH (VanguardLH)
Newsgroups: alt.windows7.general
Subject: Re: PrintNightmare: Update your PC immediately
Date: Tue, 13 Jul 2021 04:47:50 -0500
Organization: Usenet Elder
Lines: 19
Message-ID: <1k65x0luf7skd.dlg@v.nguard.lh>
References: <scivkt$hd4$2@dont-email.me> <scjbfo$a2k$1@dont-email.me>
Reply-To: invalid@invalid.invalid
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Trace: individual.net 7ExUlcbAP0v8zCx3dRexhQDirdM22rzhvEGxyNJ+lqAAZiUe63
Keywords: VanguardLH VLH811
Cancel-Lock: sha1:ai6Q1Yfj9RL1nkJv/HxC2fUfi4w=
User-Agent: 40tude_Dialog/2.0.15.41
 by: VanguardLH - Tue, 13 Jul 2021 09:47 UTC

Jo-Anne <Jo-Anne@nowhere.com> wrote:

> Michael Trew wrote:
>
>> Microsoft issues urgent security warning: Update your PC immediately
>> <Print Nightmare fix>
>> <https://www.ksl.com/article/50203184/microsoft-issues-urgent-security-warning-update-your-pc-immediately>
>
> Any idea of where the update is for Windows 7? The article doesn't seem
> to say.

Looks like it is KB5004945 for Windows 10, but the KB update varies by
OS version; see:

https://www.digitaltrends.com/computing/how-to-fix-print-nightmare-on-windows-right-now/

They say it is KB5004953 for Windows 7. They also say the fix should be
available using the Windows Update client (instead of having to search
the Update Catalog site). Did you try using the WU client?

Re: PrintNightmare: Update your PC immediately

<Y9rWk8pkxW7gFwj+@255soft.uk>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1924&group=alt.windows7.general#1924

  copy link   Newsgroups: alt.windows7.general
Path: i2pn2.org!i2pn.org!news.uzoreto.com!border1.nntp.ams1.giganews.com!nntp.giganews.com!buffer1.nntp.ams1.giganews.com!nntp.brightview.co.uk!news.brightview.co.uk.POSTED!not-for-mail
NNTP-Posting-Date: Tue, 13 Jul 2021 05:36:04 -0500
Message-ID: <Y9rWk8pkxW7gFwj+@255soft.uk>
Date: Tue, 13 Jul 2021 11:35:16 +0100
From: G6JPG@255soft.uk (J. P. Gilliver (John))
Newsgroups: alt.windows7.general
Subject: Re: PrintNightmare: Update your PC immediately
References: <scivkt$hd4$2@dont-email.me> <scjbfo$a2k$1@dont-email.me>
<scjhj1$b72$1@dont-email.me>
Organization: 255 software
MIME-Version: 1.0
Content-Type: text/plain;charset=us-ascii;format=flowed
User-Agent: Turnpike/6.07-M (<PHiDLsPj8kyw$BEg3xZACQqm0I>)
Lines: 60
X-Usenet-Provider: http://www.giganews.com
X-Trace: sv3-jzLiCWRCJJzr/EVTCqVibZyJ9AbR/fcrcM+tbdGzDt2MNPYsE4ZcbCEnJM4wgKq5O/oXvKy+RoG2qj5!xZl4S73ceMQH+7+0n1LFRSo0I0s+4UaaMJ+Ax6/8Rt0NdAcSDLIT93W3Nn38OAMlXmBIy2xs
X-Abuse-and-DMCA-Info: Please be sure to forward a copy of ALL headers
X-Abuse-and-DMCA-Info: Otherwise we will be unable to process your complaint properly
X-Postfilter: 1.3.40
X-Original-Bytes: 3689
 by: J. P. Gilliver (John - Tue, 13 Jul 2021 10:35 UTC

On Tue, 13 Jul 2021 at 04:06:56, Paul <nospam@needed.invalid> wrote (my
responses usually follow points raised):
>Jo-Anne wrote:
>
>>> "We recommend that you install these updates immediately," the company
>>> said.
>>>
>>>
>>><https://www.ksl.com/article/50203184/microsoft-issues-urgent-security
>>>-warning-update-your-pc-immediately>
>> Any idea of where the update is for Windows 7? The article doesn't
>>seem to say.
[]
> Windows 7 = KB5004953
>
>But if you look at this right now, it's a bit of a mess. This is what
>they used on the above site to find these. This link won't be valid
>a month from now, and it still raises the question, which patch
>happened in which month. Now, these are cumulative, but
>why has a Windows 7 patch (without the word Embedded in it),
>been offered month after month ? Seeing what this coughed up,
>is more troubling than downloading the patch.

(What do you mean by "offered"? The only thing I've seen through the
normal update system [I have it set to "tell me but let me choose"] is
the regular MSRT.)
[]
>Anyway, enough griping. Here's a list.
>
>*******
>
>2021-07 Security Monthly Quality Rollup for Windows 7 for x64-based
>Systems (KB5004953) 375,405,645 bytes
>
>http://download.windowsupdate.com/d/msdownload/update/software/secu/2021
>/07/windows6.1-kb5004953-x64_62d21485a29cad041230e4c647baeaeacc09ac7c.ms>u
>
>2021-07 Security Monthly Quality Rollup for Windows 7 for x86-based
>Systems (KB5004953) 249,086,473 bytes
[]
I had (on the 8th, so about 5 days ago) burrowed my way down to that
last one (I'm on 7-32). But when I press enter on it, I get "Preparing
the installation..." then "Searching for updates on this computer ..."
[which takes a while - why? Surely it should know where to look, and
know what it's looking for? If I search for a filename with Everything,
it finds it in a lot less time, and that's _without saying where!], then
"The Windows Modules Installer must be updated before you can install
this package. Please <update the Windows Modules Installer on your
computer>, then retry Setup. \\ OK".

(I did follow the link, eventually getting [Windows Modules Installer]
Update for Windows 7 (KB2533552), which tells me "Update for Windows
(KB2533552) is already installed on this computer." Maybe I found the
wrong thing.)
--
J. P. Gilliver. UMRA: 1960/<1985 MB++G()AL-IS-Ch++(p)Ar@T+H+Sh0!:`)DNAf

"I'm very peachable, if people know how to peach" - Sir David Attenborough (on
being asked if he was tired of being described as impeachable), on Desert
Island Discs, 2012-1-29.

Re: PrintNightmare: Update your PC immediately

<DsdAAdr9CX7gFwQ+@255soft.uk>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1925&group=alt.windows7.general#1925

  copy link   Newsgroups: alt.windows7.general
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!border2.nntp.ams1.giganews.com!nntp.giganews.com!buffer2.nntp.ams1.giganews.com!nntp.brightview.co.uk!news.brightview.co.uk.POSTED!not-for-mail
NNTP-Posting-Date: Tue, 13 Jul 2021 05:54:12 -0500
Message-ID: <DsdAAdr9CX7gFwQ+@255soft.uk>
Date: Tue, 13 Jul 2021 11:53:49 +0100
From: G6JPG@255soft.uk (J. P. Gilliver (John))
Newsgroups: alt.windows7.general
Subject: Re: PrintNightmare: Update your PC immediately
References: <scivkt$hd4$2@dont-email.me> <scjbfo$a2k$1@dont-email.me>
<1k65x0luf7skd.dlg@v.nguard.lh>
Organization: 255 software
MIME-Version: 1.0
Content-Type: text/plain;charset=us-ascii;format=flowed
User-Agent: Turnpike/6.07-M (<3DsDL83b8kS38DEgrZfACw5emq>)
Lines: 41
X-Usenet-Provider: http://www.giganews.com
X-Trace: sv3-AW1M1hMl4l6FCrDMzF9A4Vw7rCVKufhS4u8/KG3pq/hzp2TQfhTYY3PRa3rAFM2IIp2oVelhVUB/RAy!aXLediSKloT7yb9g6Ts0OzcURKAsPs31zWdDNUXtmTSuNbbiK/QZJzKS6FNzJWG24HyGAsql
X-Abuse-and-DMCA-Info: Please be sure to forward a copy of ALL headers
X-Abuse-and-DMCA-Info: Otherwise we will be unable to process your complaint properly
X-Postfilter: 1.3.40
X-Original-Bytes: 2683
 by: J. P. Gilliver (John - Tue, 13 Jul 2021 10:53 UTC

On Tue, 13 Jul 2021 at 04:47:50, VanguardLH <V@nguard.LH> wrote (my
responses usually follow points raised):
>Jo-Anne <Jo-Anne@nowhere.com> wrote:
>
>> Michael Trew wrote:
>>
>>> Microsoft issues urgent security warning: Update your PC immediately
[]
>> Any idea of where the update is for Windows 7? The article doesn't seem
>> to say.
>
>Looks like it is KB5004945 for Windows 10, but the KB update varies by
>OS version; see:
>
>https://www.digitaltrends.com/computing/how-to-fix-print-nightmare-on-wi
>ndows-right-now/

(Why do web pages now tend to have bigger and bigger blank banners at
the top? When I load that one, I have to scroll down before I see _any_
content! OK, </rant>.)
>
>They say it is KB5004953 for Windows 7. They also say the fix should be

(See my reply to Paul's post for my experience with that.)

>available using the Windows Update client (instead of having to search
>the Update Catalog site). Did you try using the WU client?

I (W7-32, Home) get the green shield with tick, "Windows is up to date)
There are no updates available for your computer.
Most recent check for updates: Today at 1:48
Updates were installed: 2021-6-9 at 1:6. <View update history>"

If I click on View, the last seven updates - one a month - are just the
MSRT (KB890830), versions 5.84 to 5.90. No sign of 5004953.
--
J. P. Gilliver. UMRA: 1960/<1985 MB++G()AL-IS-Ch++(p)Ar@T+H+Sh0!:`)DNAf

"I'm very peachable, if people know how to peach" - Sir David Attenborough (on
being asked if he was tired of being described as impeachable), on Desert
Island Discs, 2012-1-29.

Re: PrintNightmare: Update your PC immediately

<7bvqegdaiv6fs7dcr8d4guoh4fk2u26e7g@4ax.com>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1926&group=alt.windows7.general#1926

  copy link   Newsgroups: alt.windows7.general
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!news.dns-netz.com!news.freedyn.net!newsfeed.xs4all.nl!newsfeed8.news.xs4all.nl!feeder1.feed.usenet.farm!feed.usenet.farm!news-out.netnews.com!news.alt.net!fdc3.netnews.com!peer03.ams1!peer.ams1.xlned.com!news.xlned.com!peer03.iad!feed-me.highwinds-media.com!news.highwinds-media.com!fx20.iad.POSTED!not-for-mail
From: Merle@invalid.com
Newsgroups: alt.windows7.general
Subject: Re: PrintNightmare: Update your PC immediately
Message-ID: <7bvqegdaiv6fs7dcr8d4guoh4fk2u26e7g@4ax.com>
References: <scivkt$hd4$2@dont-email.me> <scjbfo$a2k$1@dont-email.me>
X-Newsreader: Forte Agent 1.93/32.576 English (American)
X-No-Archive: yes
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Lines: 48
X-Complaints-To: https://www.astraweb.com/aup
NNTP-Posting-Date: Tue, 13 Jul 2021 11:48:14 UTC
Date: Tue, 13 Jul 2021 06:48:14 -0500
X-Received-Bytes: 2750
 by: Merle@invalid.com - Tue, 13 Jul 2021 11:48 UTC

On Tue, 13 Jul 2021 01:22:46 -0500, Jo-Anne <Jo-Anne@nowhere.com>
wrote:

>On 7/12/2021 10:00 PM, Michael Trew wrote:
>> Microsoft issues urgent security warning: Update your PC immediately
>>
>>
>> Microsoft is urging Windows users to immediately install an update
>> after security researchers found a serious vulnerability in the
>> operating system.
>>
>> The security flaw, known as PrintNightmare, affects the Windows Print
>> Spooler service. Researchers at cybersecurity company Sangfor
>> accidentally published a how-to guide for exploiting it.
>>
>> The researchers tweeted in late May that they had found
>> vulnerabilities in Print Spooler, which allows multiple users to
>> access a printer. They published a proof-of-concept online by mistake
>> and subsequently deleted it - but not before it was published
>> elsewhere online, including developer site GitHub.
>>
>> Microsoft warned that hackers that exploit the vulnerability could
>> install programs, view and delete data or even create new user
>> accounts with full user rights. That gives hackers enough command and
>> control of your PC to do some serious damage.
>>
>> Windows 10 is not the only version affected -- Windows 7, which
>> Microsoft has ended support for last year, is also subject to the
>> vulnerability.
>>
>> Despite announcing that it would no longer issue updates for Windows
>> 7, Microsoft issued a patch for its 12-year-old operating system,
>> underscoring the severity of the PrintNightmare flaw. Updates for
>> Windows Server 2016, Windows 10, version 1607, and Windows Server 2012
>> are "expected soon," it said.
>>
>> "We recommend that you install these updates immediately," the company
>> said.
>>
>> <https://www.ksl.com/article/50203184/microsoft-issues-urgent-security-warning-update-your-pc-immediately>
>>
>>
>Any idea of where the update is for Windows 7? The article doesn't seem
>to say.

How-to page.

https://ccm.net/faq/76471-printnightmare-how-to-fix-the-windows-security-bug

Re: PrintNightmare: Update your PC immediately

<scjvbg$5jn$1@dont-email.me>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1927&group=alt.windows7.general#1927

  copy link   Newsgroups: alt.windows7.general
Path: i2pn2.org!i2pn.org!eternal-september.org!reader02.eternal-september.org!.POSTED!not-for-mail
From: mayayana@invalid.nospam (Mayayana)
Newsgroups: alt.windows7.general
Subject: Re: PrintNightmare: Update your PC immediately
Date: Tue, 13 Jul 2021 08:01:07 -0400
Organization: A noiseless patient Spider
Lines: 9
Message-ID: <scjvbg$5jn$1@dont-email.me>
References: <scivkt$hd4$2@dont-email.me>
Injection-Date: Tue, 13 Jul 2021 12:01:52 -0000 (UTC)
Injection-Info: reader02.eternal-september.org; posting-host="70810824a0fd6d54953177d3071ccfe8";
logging-data="5751"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18ad7im8qDD8kYlf1rmpiucdOOSuGSy5+s="
Cancel-Lock: sha1:eiUN4GHS3aWycsI4yrIp0LFmahg=
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.5512
X-Newsreader: Microsoft Outlook Express 6.00.2900.5512
X-Priority: 3
X-MSMail-Priority: Normal
 by: Mayayana - Tue, 13 Jul 2021 12:01 UTC

"Michael Trew" <mt999999@ymail.com> wrote

| Microsoft issues urgent security warning: Update your PC immediately
|

Once again, problems with allowing remote access to your
computer. That's the real problem.

Re: PrintNightmare: Update your PC immediately

<OiLjj0vlFY7gFwBi@255soft.uk>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1928&group=alt.windows7.general#1928

  copy link   Newsgroups: alt.windows7.general
Path: i2pn2.org!i2pn.org!aioe.org!feeder1.feed.usenet.farm!feed.usenet.farm!border1.nntp.ams1.giganews.com!nntp.giganews.com!buffer1.nntp.ams1.giganews.com!nntp.brightview.co.uk!news.brightview.co.uk.POSTED!not-for-mail
NNTP-Posting-Date: Tue, 13 Jul 2021 07:06:37 -0500
Message-ID: <OiLjj0vlFY7gFwBi@255soft.uk>
Date: Tue, 13 Jul 2021 13:04:53 +0100
From: G6JPG@255soft.uk (J. P. Gilliver (John))
Newsgroups: alt.windows7.general
Subject: Re: PrintNightmare: Update your PC immediately
References: <scivkt$hd4$2@dont-email.me> <scjbfo$a2k$1@dont-email.me>
<7bvqegdaiv6fs7dcr8d4guoh4fk2u26e7g@4ax.com>
Organization: 255 software
MIME-Version: 1.0
Content-Type: text/plain;charset=us-ascii;format=flowed
User-Agent: Turnpike/6.07-M (<vRmDL0Xn8kSl3BEgGRdACQw3Ad>)
Lines: 21
X-Usenet-Provider: http://www.giganews.com
X-Trace: sv3-KHMlU6ePiBcVRszEwDiO9wFni2BUa9ytyCLFW8zsrkEwjoI/NlP0kDeSwAZyISVg/QWRwnl4Opcik8w!Ugh+FAfOO2ivwqOD+N/NgbaZgdjduTCEyzRzVjVI1GoVeHso0g8eZ/hrmvx1UB6d2yuu3SdN
X-Abuse-and-DMCA-Info: Please be sure to forward a copy of ALL headers
X-Abuse-and-DMCA-Info: Otherwise we will be unable to process your complaint properly
X-Postfilter: 1.3.40
X-Original-Bytes: 1921
 by: J. P. Gilliver (John - Tue, 13 Jul 2021 12:04 UTC

On Tue, 13 Jul 2021 at 06:48:14, Merle@invalid.com wrote (my responses
usually follow points raised):
>On Tue, 13 Jul 2021 01:22:46 -0500, Jo-Anne <Jo-Anne@nowhere.com>
>wrote:
[]
>>Any idea of where the update is for Windows 7? The article doesn't seem
>>to say.
>
>How-to page.
>
>https://ccm.net/faq/76471-printnightmare-how-to-fix-the-windows-security-bug

Just points to KB5004953 (Rollup, 237 MB) or '4951 (Security Only, 21.1
MB). When I try either of those, I get told to update the Windows
Modules Installer first, which I have not succeeded in doing. (Any
guidance on that [or otherwise implement '4953] would be appreciated.)
--
J. P. Gilliver. UMRA: 1960/<1985 MB++G()AL-IS-Ch++(p)Ar@T+H+Sh0!:`)DNAf

Veni, Vidi, Video (I came, I saw, I'll watch it again later) - Mik from S+AS
Limited (mik@saslimited.demon.co.uk), 1998

Re: PrintNightmare: Update your PC immediately

<vg0regloob4gftll7svndej2gspdbnjohg@4ax.com>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1929&group=alt.windows7.general#1929

  copy link   Newsgroups: alt.windows7.general
Path: i2pn2.org!i2pn.org!aioe.org!feeder1.feed.usenet.farm!feed.usenet.farm!peer01.ams4!peer.am4.highwinds-media.com!peer01.iad!feed-me.highwinds-media.com!news.highwinds-media.com!fx17.iad.POSTED!not-for-mail
From: Merle@invalid.com
Newsgroups: alt.windows7.general
Subject: Re: PrintNightmare: Update your PC immediately
Message-ID: <vg0regloob4gftll7svndej2gspdbnjohg@4ax.com>
References: <scivkt$hd4$2@dont-email.me> <scjbfo$a2k$1@dont-email.me> <7bvqegdaiv6fs7dcr8d4guoh4fk2u26e7g@4ax.com> <OiLjj0vlFY7gFwBi@255soft.uk>
X-Newsreader: Forte Agent 1.93/32.576 English (American)
X-No-Archive: yes
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Lines: 27
X-Complaints-To: https://www.astraweb.com/aup
NNTP-Posting-Date: Tue, 13 Jul 2021 12:11:37 UTC
Date: Tue, 13 Jul 2021 07:11:37 -0500
X-Received-Bytes: 1801
 by: Merle@invalid.com - Tue, 13 Jul 2021 12:11 UTC

On Tue, 13 Jul 2021 13:04:53 +0100, "J. P. Gilliver (John)"
<G6JPG@255soft.uk> wrote:

>On Tue, 13 Jul 2021 at 06:48:14, Merle@invalid.com wrote (my responses
>usually follow points raised):
>>On Tue, 13 Jul 2021 01:22:46 -0500, Jo-Anne <Jo-Anne@nowhere.com>
>>wrote:
>[]
>>>Any idea of where the update is for Windows 7? The article doesn't seem
>>>to say.
>>
>>How-to page.
>>
>>https://ccm.net/faq/76471-printnightmare-how-to-fix-the-windows-security-bug
>
>Just points to KB5004953 (Rollup, 237 MB) or '4951 (Security Only, 21.1
>MB). When I try either of those, I get told to update the Windows
>Modules Installer first, which I have not succeeded in doing. (Any
>guidance on that [or otherwise implement '4953] would be appreciated.)

I'm guilty of not reading it fully. I've stuck with XP for the years,
so I really wasn't that involved.

I also looked all over out of mere curiosity and couldn't find that
dang update

I think those article writers couldn't find it, too,. :o)

Re: PrintNightmare: Update your PC immediately

<sckcju.420.1@ID-201911.user.individual.net>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1932&group=alt.windows7.general#1932

  copy link   Newsgroups: alt.windows7.general
Path: i2pn2.org!i2pn.org!aioe.org!news.uzoreto.com!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: this@ddress.is.invalid (Frank Slootweg)
Newsgroups: alt.windows7.general
Subject: Re: PrintNightmare: Update your PC immediately
Date: 13 Jul 2021 13:48:22 GMT
Organization: NOYB
Lines: 35
Message-ID: <sckcju.420.1@ID-201911.user.individual.net>
References: <scivkt$hd4$2@dont-email.me> <scjvbg$5jn$1@dont-email.me>
X-Trace: individual.net +7F7KQBdmbFpzIDpV9aS5Al3LvHzguE9bMMXF+rh7zST1EbjkU
X-Orig-Path: not-for-mail
Cancel-Lock: sha1:QcwavCztpIae9dznJW9ciWfZvaM=
User-Agent: tin/1.6.2-20030910 ("Pabbay") (UNIX) (CYGWIN_NT-6.3-WOW/2.8.0(0.309/5/3) (i686)) Hamster/2.0.2.2
X-Antivirus: Avast (VPS 210712-4, 07/12/2021), Outbound message
X-Antivirus-Status: Clean
 by: Frank Slootweg - Tue, 13 Jul 2021 13:48 UTC

Mayayana <mayayana@invalid.nospam> wrote:
> "Michael Trew" <mt999999@ymail.com> wrote
>
> | Microsoft issues urgent security warning: Update your PC immediately
>
> Once again, problems with allowing remote access to your
> computer. That's the real problem.

Indeed. The reports are very unclear about which kind of users are
really at risk and what to do to make sure you don't take any unneeded
risks.

The reports vary from only computers in a domain are at risk, to
'everybody' is at risk.

They don't bother to explain how to make sure that a small home
network - i.e. two or more computers with one or more printers - is
secure, i.e. printers can be used within the LAN, but is safe from
attacks from the WAN.

I tried to check the settings of my (built-in) (8.1) Windows Firewall,
but the terminology is too ambiguous for me and there are too many
Inbound Rules for me to see the forest for the trees.

I don't worry about the PrintNightmare vulnerability, because I do
have the update (and before that I had disabled the Print Spooler
service (that was the only specific and usable advice in the reports)).
But it would be nice if there was a cookbook as to how to configure the
Windows Firewall to not allow any unneeded inbound or outbound
connections.

Another approach would be a trusted sites which 'attacks' your
computer to report any unneeded inbound connections/ports.

Any pointers to these are welcome.

Re: PrintNightmare: Update your PC immediately

<sckdji.420.1@ID-201911.user.individual.net>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1934&group=alt.windows7.general#1934

  copy link   Newsgroups: alt.windows7.general
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!lilly.ping.de!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: this@ddress.is.invalid (Frank Slootweg)
Newsgroups: alt.windows7.general
Subject: Re: PrintNightmare: Update your PC immediately
Date: 13 Jul 2021 14:05:20 GMT
Organization: NOYB
Lines: 33
Message-ID: <sckdji.420.1@ID-201911.user.individual.net>
References: <scivkt$hd4$2@dont-email.me> <scjbfo$a2k$1@dont-email.me> <scjhj1$b72$1@dont-email.me>
X-Trace: individual.net LdjCfhqLIg2MskuWw8M31g5cjg4Et0cK1Asp57uDePYUdG5ICe
X-Orig-Path: not-for-mail
Cancel-Lock: sha1:rkQsh3UC3XUsHkCVeUxrZk5EyJw=
User-Agent: tin/1.6.2-20030910 ("Pabbay") (UNIX) (CYGWIN_NT-6.3-WOW/2.8.0(0.309/5/3) (i686)) Hamster/2.0.2.2
X-Antivirus: Avast (VPS 210712-4, 07/12/2021), Outbound message
X-Antivirus-Status: Clean
 by: Frank Slootweg - Tue, 13 Jul 2021 14:05 UTC

Paul <nospam@needed.invalid> wrote:
> Jo-Anne wrote:
>
> >> "We recommend that you install these updates immediately," the company
> >> said.
> >>
> >> <https://www.ksl.com/article/50203184/microsoft-issues-urgent-security-warning-update-your-pc-immediately>
> >>
> > Any idea of where the update is for Windows 7? The article doesn't seem
> > to say.
>
> https://www.digitaltrends.com/computing/how-to-fix-print-nightmare-on-windows-right-now/

[Report of trip to the moon and back.]

I just followed the "it said." (Microsoft said) link in the KSL.com
article.

That brought me to

'Out-of-Band (OOB) Security Update available for CVE-2021-34527'
<https://msrc-blog.microsoft.com/2021/07/06/out-of-band-oob-security-update-available-for-cve-2021-34527>

And then is was just happy sailing by just following the links.

And yes, that included getting the right (x64/x86 (non-Embedded)) bits
from the Microsoft Update Catalog for those who need those.

N.B. I don't need any of this, because I did get the (8.1) update in
Windows Update, but because people seemed to have problems finding the
right KB-number, etc., I just read the article and followed the links.

[...]

Re: PrintNightmare: Update your PC immediately

<sck8b9$5cb$1@dont-email.me>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1936&group=alt.windows7.general#1936

  copy link   Newsgroups: alt.windows7.general
Path: i2pn2.org!i2pn.org!eternal-september.org!reader02.eternal-september.org!.POSTED!not-for-mail
From: mayayana@invalid.nospam (Mayayana)
Newsgroups: alt.windows7.general
Subject: Re: PrintNightmare: Update your PC immediately
Date: Tue, 13 Jul 2021 10:34:35 -0400
Organization: A noiseless patient Spider
Lines: 33
Message-ID: <sck8b9$5cb$1@dont-email.me>
References: <scivkt$hd4$2@dont-email.me> <scjvbg$5jn$1@dont-email.me> <sckcju.420.1@ID-201911.user.individual.net>
Injection-Date: Tue, 13 Jul 2021 14:35:21 -0000 (UTC)
Injection-Info: reader02.eternal-september.org; posting-host="70810824a0fd6d54953177d3071ccfe8";
logging-data="5515"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18nfJqHGz732lebXlXp+4sbfcRB18qUzY4="
Cancel-Lock: sha1:Xsckx1ZC6ZqEoa2mynQSNVNn2gU=
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.5512
X-Newsreader: Microsoft Outlook Express 6.00.2900.5512
X-Priority: 3
X-MSMail-Priority: Normal
 by: Mayayana - Tue, 13 Jul 2021 14:34 UTC

"Frank Slootweg" <this@ddress.is.invalid> wrote

| > Once again, problems with allowing remote access to your
| > computer. That's the real problem.
| | Indeed. The reports are very unclear about which kind of users are
| really at risk and what to do to make sure you don't take any unneeded
| risks.
| | The reports vary from only computers in a domain are at risk, to
| 'everybody' is at risk.
| | They don't bother to explain how to make sure that a small home
| network - i.e. two or more computers with one or more printers - is
| secure, i.e. printers can be used within the LAN, but is safe from
| attacks from the WAN.
|

"By sending a request to add a printer, e.g. by using
RpcAddPrinterDriverEx() over SMB or RpcAsyncAddPrinterDriver() over RPC, a
remote, authenticated attacker..."

I never enable local networking, file sharing, etc, so I'm not
sure how that works.
I assume it's the same insofar as it's allowing another machine
to access yours. Doesn't a LAN that allows lax security locally
generally use a firewall machine to filter remote access? On the
other hand, if only one machine on the network is set up to
enable something like remote desktop then you've got a way in.

Re: PrintNightmare: Update your PC immediately

<sck9ua$qeb$1@dont-email.me>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1937&group=alt.windows7.general#1937

  copy link   Newsgroups: alt.windows7.general
Path: i2pn2.org!i2pn.org!eternal-september.org!reader02.eternal-september.org!.POSTED!not-for-mail
From: nospam@needed.invalid (Paul)
Newsgroups: alt.windows7.general
Subject: Re: PrintNightmare: Update your PC immediately
Date: Tue, 13 Jul 2021 11:02:33 -0400
Organization: A noiseless patient Spider
Lines: 61
Message-ID: <sck9ua$qeb$1@dont-email.me>
References: <scivkt$hd4$2@dont-email.me> <scjbfo$a2k$1@dont-email.me> <1k65x0luf7skd.dlg@v.nguard.lh> <DsdAAdr9CX7gFwQ+@255soft.uk>
Mime-Version: 1.0
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Tue, 13 Jul 2021 15:02:34 -0000 (UTC)
Injection-Info: reader02.eternal-september.org; posting-host="5ae4f633c68c34114968e5e9147ab2fc";
logging-data="27083"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/oCG2A6sfeVfqfZp01nnUadQceu6nmHyg="
User-Agent: Ratcatcher/2.0.0.25 (Windows/20130802)
Cancel-Lock: sha1:InxudcchhG3oQpuEhJvReSIqcsA=
In-Reply-To: <DsdAAdr9CX7gFwQ+@255soft.uk>
 by: Paul - Tue, 13 Jul 2021 15:02 UTC

J. P. Gilliver (John) wrote:
> On Tue, 13 Jul 2021 at 04:47:50, VanguardLH <V@nguard.LH> wrote (my
> responses usually follow points raised):
>> Jo-Anne <Jo-Anne@nowhere.com> wrote:
>>
>>> Michael Trew wrote:
>>>
>>>> Microsoft issues urgent security warning: Update your PC immediately
> []
>>> Any idea of where the update is for Windows 7? The article doesn't seem
>>> to say.
>>
>> Looks like it is KB5004945 for Windows 10, but the KB update varies by
>> OS version; see:
>>
>> https://www.digitaltrends.com/computing/how-to-fix-print-nightmare-on-wi
>> ndows-right-now/
>
> (Why do web pages now tend to have bigger and bigger blank banners at
> the top? When I load that one, I have to scroll down before I see _any_
> content! OK, </rant>.)
>>
>> They say it is KB5004953 for Windows 7. They also say the fix should be
>
> (See my reply to Paul's post for my experience with that.)
>
>> available using the Windows Update client (instead of having to search
>> the Update Catalog site). Did you try using the WU client?
>
> I (W7-32, Home) get the green shield with tick, "Windows is up to date)
> There are no updates available for your computer.
> Most recent check for updates: Today at 1:48
> Updates were installed: 2021-6-9 at 1:6. <View update history>"
>
> If I click on View, the last seven updates - one a month - are just the
> MSRT (KB890830), versions 5.84 to 5.90. No sign of 5004953.

In the past, "emergency updates" to OSes that are out of
support, don't show up in Windows Update scan window.

Someone has to tell us the KB, or indicate whether it's a tiny
patch or a huge one.

This is why I have a natural tendency to inspect catalog.update.microsoft.com
for the details (like, if someone offers a link there). I still need a hint
as to what flavor of patch will be offered, and in this case, it's the
unnecessary ginormous variety (a cumulative, when the patch is probably
2-5MB in size. They'll do anything to get copies of api-* into OSes,
if it kills them :-/

I was just surprised at how many cumulatives were on offer for
Windows 7, when Windows 7 is out of support. I know they have
extended support plans, for $$$ per year, and maybe the files
are for those people. The emergency patch might be for
everyone, rather than the $$$ people.

You would know, if you double clicked a .msu and it said
"not for this OS", as this would indicate it was for a
different servicing stack.

Paul

Re: PrintNightmare: Update your PC immediately

<sckb62$bac$1@dont-email.me>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1939&group=alt.windows7.general#1939

  copy link   Newsgroups: alt.windows7.general
Path: i2pn2.org!i2pn.org!eternal-september.org!reader02.eternal-september.org!.POSTED!not-for-mail
From: nospam@needed.invalid (Paul)
Newsgroups: alt.windows7.general
Subject: Re: PrintNightmare: Update your PC immediately
Date: Tue, 13 Jul 2021 11:23:45 -0400
Organization: A noiseless patient Spider
Lines: 57
Message-ID: <sckb62$bac$1@dont-email.me>
References: <scivkt$hd4$2@dont-email.me> <scjbfo$a2k$1@dont-email.me> <7bvqegdaiv6fs7dcr8d4guoh4fk2u26e7g@4ax.com> <OiLjj0vlFY7gFwBi@255soft.uk>
Mime-Version: 1.0
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Tue, 13 Jul 2021 15:23:46 -0000 (UTC)
Injection-Info: reader02.eternal-september.org; posting-host="5ae4f633c68c34114968e5e9147ab2fc";
logging-data="11596"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/oUeT9kWGz9zndSrAEcLY2Ku2qnRFikXI="
User-Agent: Ratcatcher/2.0.0.25 (Windows/20130802)
Cancel-Lock: sha1:RpBP/xcebtfvn3mmuIwVbicqyug=
In-Reply-To: <OiLjj0vlFY7gFwBi@255soft.uk>
 by: Paul - Tue, 13 Jul 2021 15:23 UTC

J. P. Gilliver (John) wrote:
> On Tue, 13 Jul 2021 at 06:48:14, Merle@invalid.com wrote (my responses
> usually follow points raised):
>> On Tue, 13 Jul 2021 01:22:46 -0500, Jo-Anne <Jo-Anne@nowhere.com>
>> wrote:
> []
>>> Any idea of where the update is for Windows 7? The article doesn't seem
>>> to say.
>>
>> How-to page.
>>
>> https://ccm.net/faq/76471-printnightmare-how-to-fix-the-windows-security-bug
>>
>
> Just points to KB5004953 (Rollup, 237 MB) or '4951 (Security Only, 21.1
> MB). When I try either of those, I get told to update the Windows
> Modules Installer first, which I have not succeeded in doing. (Any
> guidance on that [or otherwise implement '4953] would be appreciated.)

Recipe here. Two files. SSU + 4953

https://docs.microsoft.com/en-us/answers/questions/239165/windows-module-installer-must-be-updated-before-yo.html

"BrittWinn-8018 - 4 days ago

Upon trying to install KB5004953 to mitigate the PrintNightmare
exploit on Windows 7, I received the message that the PC needed
to update the Windows Modules Installer.

The link to MS 2533552 works, but the links on that page pointing
to the downloadable update files lead to a page that states the
downloads are no longer available.

I followed the link provided by JuanSbrado-3258, downloaded the
Servicing Stack Update from the MS Update Catalog, and installed
this MSU (KB4592510).

https://support.microsoft.com/en-us/help/4592510/servicing-stack-update

After installing the Servicing Stack Update, I am now able to install
the KB5004953 update.

Thank you JuanSabrado-3258."

It appears to be (partially) an SSU issue.

I think at some point, there was also an irritating "End of Support"
patch that puts something on the screen. At the time, some people would
name and shame such patches (so others would not get bands or messages
on their screen), but perhaps that also had something to do
with the SSU status.

In the past, if a necessary SSU was missing, double clicking a
..msu file would say "Not For This OS", when in fact it was for the
OS, but the .msu was too bashful to indicate what item was missing.

Paul

Re: PrintNightmare: Update your PC immediately

<sckidt.dic.1@ID-201911.user.individual.net>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1940&group=alt.windows7.general#1940

  copy link   Newsgroups: alt.windows7.general
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!news.uzoreto.com!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: this@ddress.is.invalid (Frank Slootweg)
Newsgroups: alt.windows7.general
Subject: Re: PrintNightmare: Update your PC immediately
Date: 13 Jul 2021 15:27:35 GMT
Organization: NOYB
Lines: 21
Message-ID: <sckidt.dic.1@ID-201911.user.individual.net>
References: <scivkt$hd4$2@dont-email.me> <scjbfo$a2k$1@dont-email.me> <1k65x0luf7skd.dlg@v.nguard.lh> <DsdAAdr9CX7gFwQ+@255soft.uk> <sck9ua$qeb$1@dont-email.me>
X-Trace: individual.net o8hrDloQlptagF7rsH0UwQmedHimSkbNdf63y+XyK8sQkh6nHY
X-Orig-Path: not-for-mail
Cancel-Lock: sha1:5BXJ2lcKh8CVQXMxb/sd00n1nxQ=
User-Agent: tin/1.6.2-20030910 ("Pabbay") (UNIX) (CYGWIN_NT-6.3-WOW/2.8.0(0.309/5/3) (i686)) Hamster/2.0.2.2
X-Antivirus: Avast (VPS 210712-4, 07/12/2021), Outbound message
X-Antivirus-Status: Clean
 by: Frank Slootweg - Tue, 13 Jul 2021 15:27 UTC

Paul <nospam@needed.invalid> wrote:
[...]

> Someone has to tell us the KB, or indicate whether it's a tiny
> patch or a huge one.

KB5004953 Monthly Rollup, i.e. huge.

KB5004951 Security Only, i.e. tiny

(As always,) Both KB articles have pointers to the Microsoft Update
Catalog bits, if needed.

Source:
'Windows Print Spooler Remote Code Execution Vulnerability'
<https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527>

As mentioned before, I got to this page by just following links from
the KSL.com article in the OP. Not really rocket science.

[...]

Re: PrintNightmare: Update your PC immediately

<sckbpm$je7$1@dont-email.me>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1941&group=alt.windows7.general#1941

  copy link   Newsgroups: alt.windows7.general
Path: i2pn2.org!i2pn.org!eternal-september.org!reader02.eternal-september.org!.POSTED!not-for-mail
From: nospam@needed.invalid (Paul)
Newsgroups: alt.windows7.general
Subject: Re: PrintNightmare: Update your PC immediately
Date: Tue, 13 Jul 2021 11:34:14 -0400
Organization: A noiseless patient Spider
Lines: 62
Message-ID: <sckbpm$je7$1@dont-email.me>
References: <scivkt$hd4$2@dont-email.me> <scjvbg$5jn$1@dont-email.me> <sckcju.420.1@ID-201911.user.individual.net> <sck8b9$5cb$1@dont-email.me>
Mime-Version: 1.0
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Tue, 13 Jul 2021 15:34:14 -0000 (UTC)
Injection-Info: reader02.eternal-september.org; posting-host="5ae4f633c68c34114968e5e9147ab2fc";
logging-data="19911"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18l4IymLQABOK0rsUF0MB7amWnRC3S6E6o="
User-Agent: Ratcatcher/2.0.0.25 (Windows/20130802)
Cancel-Lock: sha1:P86onSjPkHQh8U4bbOBL6w9srw8=
In-Reply-To: <sck8b9$5cb$1@dont-email.me>
 by: Paul - Tue, 13 Jul 2021 15:34 UTC

Mayayana wrote:
> "Frank Slootweg" <this@ddress.is.invalid> wrote
>
> | > Once again, problems with allowing remote access to your
> | > computer. That's the real problem.
> |
> | Indeed. The reports are very unclear about which kind of users are
> | really at risk and what to do to make sure you don't take any unneeded
> | risks.
> |
> | The reports vary from only computers in a domain are at risk, to
> | 'everybody' is at risk.
> |
> | They don't bother to explain how to make sure that a small home
> | network - i.e. two or more computers with one or more printers - is
> | secure, i.e. printers can be used within the LAN, but is safe from
> | attacks from the WAN.
> |
>
> "By sending a request to add a printer, e.g. by using
> RpcAddPrinterDriverEx() over SMB or RpcAsyncAddPrinterDriver() over RPC, a
> remote, authenticated attacker..."
>
> I never enable local networking, file sharing, etc, so I'm not
> sure how that works.
> I assume it's the same insofar as it's allowing another machine
> to access yours. Doesn't a LAN that allows lax security locally
> generally use a firewall machine to filter remote access? On the
> other hand, if only one machine on the network is set up to
> enable something like remote desktop then you've got a way in.

They're worried about a "they got inside my perimeter" attack.

Sure, all the people here, don't port forward unnecessary stuff
to the Internet, so that an attack surface is presented for easy
pickings. Nobody here would be stupid enough to sit in Starbucks,
and print sheets of paper on their home printer, because it
happens to be port forwarded. It's also a lot of work to Port Forward
stuff, which is likely a major security achievement, that lazy users
are protected by their laziness.

But, if a Black Hat finds one exploit to get inside your perimeter,
and then they unleash all these "remote" exploits on your local LAN,
your second and third computers are going to fall over. Potentially
you lose the whole room full of computers to ransomware.

That is about how secure my computer room is. If anyone
gets inside the perimeter, it would take practically
no effort at all, to tip over all computers. On the WinXP
setup, it would be the missing SMB patch (patch didn't install
properly and had to be removed).

Since the emergency patches (like the WinXP SMB one) don't
show up in Windows Update, that's part of the problem with the
emergency patch idea. To successfully patch all your computers,
you'd have to be fricken Einstein (like knowing your WinXP SMB
patch is missing, then figuring out a way to get the KB number).
My WinXP SMB is not exposed to the Internet, by Port Forwarding,
but if someone gets inside my perimeter, running that exploit
would soon make toast out of it.

Paul

Re: PrintNightmare: Update your PC immediately

<cndonai13e4$.dlg@v.nguard.lh>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1942&group=alt.windows7.general#1942

  copy link   Newsgroups: alt.windows7.general
Path: i2pn2.org!i2pn.org!aioe.org!news.uzoreto.com!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: V@nguard.LH (VanguardLH)
Newsgroups: alt.windows7.general
Subject: Re: PrintNightmare: Update your PC immediately
Date: Tue, 13 Jul 2021 11:16:30 -0500
Organization: Usenet Elder
Lines: 109
Message-ID: <cndonai13e4$.dlg@v.nguard.lh>
References: <scivkt$hd4$2@dont-email.me> <scjbfo$a2k$1@dont-email.me> <1k65x0luf7skd.dlg@v.nguard.lh> <DsdAAdr9CX7gFwQ+@255soft.uk>
Reply-To: invalid@invalid.invalid
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Trace: individual.net Y+4rEGr6tf7RPE6uucJjAA+01gyL6QtmFogeCqwzMVhQFI/gw+
Keywords: VanguardLH VLH811
Cancel-Lock: sha1:vojPp/R3+gJQuU1oIjOYahvW2j4=
User-Agent: 40tude_Dialog/2.0.15.41
 by: VanguardLH - Tue, 13 Jul 2021 16:16 UTC

"J. P. Gilliver (John)" <G6JPG@255soft.uk> wrote:

> VanguardLH <V@nguard.LH> wrote:
>
>> Jo-Anne <Jo-Anne@nowhere.com> wrote:
>>
>>> Michael Trew wrote:
>>>
>>>> Microsoft issues urgent security warning: Update your PC
>>>> immediately
>>>
>>> Any idea of where the update is for Windows 7? The article doesn't
>>> seem to say.
>>
>> Looks like it is KB5004945 for Windows 10, but the KB update varies
>> by OS version; see:
>>
>> https://www.digitaltrends.com/computing/how-to-fix-print-nightmare-on-windows-right-now/
>
> (Why do web pages now tend to have bigger and bigger blank banners at
> the top? When I load that one, I have to scroll down before I see _any_
> content! OK, </rant>.)

I don't see a huge banner. I see the black banner at the top consisting
of their site branding, and a line showing what's trending (like I would
give a gnat's fart).

However, I use uBlock Origin which cuts out a lot of the noise. If I
disable uBO and refresh the document, yep, there's a much bigger banner.
What do you use for an adblocker?

In uBO, I do not have it subscribe to every blacklist, just the
following ones:

My filters
uBlock filters
uBlock filters - privacy
uBlock filters - resource abuse
AdGuard Base
EasyList
AdGuard Tracking Protection
EasyPrivacy
Online Malicious URL Blocklist
AdGuard Annoyances
AdGuard Social Media
uBlock filters - Annoyances

I don't subscribe to any of the hosts files (Pollock, MVPS, Lowe) as I
find they are slow to update and overly aggressive. The ones I picked
above have been sufficient to get rid of a majority of visual noise.

>> available using the Windows Update client (instead of having to
>> search the Update Catalog site). Did you try using the WU client?
>
> I (W7-32, Home) get the green shield with tick, "Windows is up to date)
> There are no updates available for your computer.
> Most recent check for updates: Today at 1:48
> Updates were installed: 2021-6-9 at 1:6. <View update history>"
>
> If I click on View, the last seven updates - one a month - are just the
> MSRT (KB890830), versions 5.84 to 5.90. No sign of 5004953.

Guess you're stuck using the WU Catalog site if you want the fix early.
Sometimes the catalog site will let you get an update sooner than when
Microsoft gets around to pushing it out to their WSUS server. Since the
fix is bundled in a cumulative patch, maybe you won't get it until next
Patch Tuesday. Wait a minute, isn't that today? The update was
out-of-band for Windows 10, but might be rolled into the monthly updates
for older and unsupported versions of Windows. MS also does load
balancing on their servers, so not everyone gets offered an update at
the same time; it's available, but not now for everyone. They often
spread it out. I had to wait 6 months for a feature update to Windows
10, and which just a month or two prior to the next feature update.

Because updates are re-released as new versions to fix problems with the
prior version released, the same update (by the same KB number) may be
presented multiple times. Plus, there are dependencies that are checked
to see if your setup should receive the update. In the long awaited
feature update (forget which one), there were a lot of, um, anomalies it
would cause. Until they fixed them, the update wasn't offered to a lot
of users. If the users just couldn't wait, they had to go to the WU
Catalog site to get them, and take the risk if those anomalies were
exhibited in their setup.

From what you said in reply to Paul when you tried to get the Print
Nightmare patch, you retrieved the one with a title of "2021-07 Security
Monthly Quality Rollup for Windows 7 for x86-based Systems (KB5004953)".
Looks like the right one for a non-embedded 32-bit version of Win 7.
When I clicked on the Download button, a window popped up listing
"windows6.1-kb5004953-x86_076aed0ffca7ef0c30d6e4dfda0346f6b319f448.msu".
I clicked on the hyperlink, and it downloaded okay despite I was using
Windows 10 x64 Home 21h2. I did *NOT* elect the default action of "Open
with". I selected "Save file". If I were to apply the update, I want
to download it (to ensure I have it for later as retries are sometimes
needed), and then prepare to run it (by saving an image backup first).
It downloaded okay. I can't test running it because I don't have any
Windows 7 hosts at home, anymore. Instead of downloading AND installing
in one step, see if you get different results by downloading only, and
then double-clicking the .msu file in File Explorer. Before running it,
I would disable any AV software, except Defender, and AVs can interfere
with installations.

I see you hit one of those dependencies for an update (Windows Modules
Installer) that the WU client would've taken care of due to the manifest
for the update. Personally, if I were still running Windows 7, and for
personal use, I wouldn't care about the Print Nightmare patch. That's
only when allowing remote access to the print spooler. Do you allow
remote access to your printers from the Internet (i.e., outside your
intranetwork)? I'd just wait until WU offered the update.

Re: PrintNightmare: Update your PC immediately

<1i114ecrfju98$.1ie8h08usu77m.dlg@40tude.net>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1944&group=alt.windows7.general#1944

  copy link   Newsgroups: alt.windows7.general
Path: i2pn2.org!i2pn.org!eternal-september.org!reader02.eternal-september.org!.POSTED!not-for-mail
From: giraffenos.pam@homecall.co.uk (PeterC)
Newsgroups: alt.windows7.general
Subject: Re: PrintNightmare: Update your PC immediately
Date: Tue, 13 Jul 2021 17:47:10 +0100
Organization: A noiseless patient Spider
Lines: 22
Message-ID: <1i114ecrfju98$.1ie8h08usu77m.dlg@40tude.net>
References: <scivkt$hd4$2@dont-email.me> <scjbfo$a2k$1@dont-email.me> <7bvqegdaiv6fs7dcr8d4guoh4fk2u26e7g@4ax.com> <OiLjj0vlFY7gFwBi@255soft.uk> <sckb62$bac$1@dont-email.me>
Reply-To: giraffenos.pam@homecall.co.uk
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Injection-Info: reader02.eternal-september.org; posting-host="a78dfe8c4c2718e8830d2d2104fcf902";
logging-data="8680"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX193dvtdk/pbnFR2hGphj861"
User-Agent: 40tude_Dialog/2.0.15.84
Cancel-Lock: sha1:lhquXfnV2ch0JRwvz96zJ77xF00=
 by: PeterC - Tue, 13 Jul 2021 16:47 UTC

On Tue, 13 Jul 2021 11:23:45 -0400, Paul wrote:

> I followed the link provided by JuanSbrado-3258, downloaded the
> Servicing Stack Update from the MS Update Catalog, and installed
> this MSU (KB4592510).
>
> https://support.microsoft.com/en-us/help/4592510/servicing-stack-update
>
> After installing the Servicing Stack Update, I am now able to install
> the KB5004953 update.
>
> Thank you JuanSabrado-3258."
>
> It appears to be (partially) an SSU issue.

I installed the SSU OK. Installation of the Security Update went through to
the point of restarting; as it booted up it failed and rolled back. Tried
twice, same result.
--
Peter.
The gods will stay away
whilst religions hold sway

Re: PrintNightmare: Update your PC immediately

<MPG.3b57d10bd956b3298fde9@news.individual.net>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1947&group=alt.windows7.general#1947

  copy link   Newsgroups: alt.windows7.general
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!lilly.ping.de!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: the_stan_brown@fastmail.fm (Stan Brown)
Newsgroups: alt.windows7.general
Subject: Re: PrintNightmare: Update your PC immediately
Date: Tue, 13 Jul 2021 17:34:54 -0700
Organization: Oak Road Systems
Lines: 56
Message-ID: <MPG.3b57d10bd956b3298fde9@news.individual.net>
References: <scivkt$hd4$2@dont-email.me> <scjbfo$a2k$1@dont-email.me> <scjhj1$b72$1@dont-email.me>
Mime-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: 8bit
X-Trace: individual.net tqjN9sVMqAKAfWuu5DMTAA9AY+Sx6Gmsod0YuO3FM7fNajdzIQ
Cancel-Lock: sha1:YgYvRgu97X9n73kiGpKEGKWGmz0=
User-Agent: MicroPlanet-Gravity/3.0.4
 by: Stan Brown - Wed, 14 Jul 2021 00:34 UTC

On Tue, 13 Jul 2021 04:06:56 -0400, Paul wrote:
>
> Jo-Anne wrote:
>
> >> "We recommend that you install these updates immediately," the company
> >> said.
> >>
> >> <https://www.ksl.com/article/50203184/microsoft-issues-urgent-security-warning-update-your-pc-immediately>
> >>
> > Any idea of where the update is for Windows 7? The article doesn't seem
> > to say.
>
> https://www.digitaltrends.com/computing/how-to-fix-print-nightmare-on-windows-right-now/
>
> Windows 11 = 22000.65
> Windows 8.1 = KB5004954
> Windows 7 = KB5004953
>
> But if you look at this right now, it's a bit of a mess.

Woody Leonhardt says as much on askwoody.com. (He was our guru during
MS's years-long effort to "upgrade" Windows 7 installations to
Windows 10 by stealth.)

By searching
printnightmare site:askwoody.com
I found
https://www.askwoody.com/2021/print-nightmare-is-going-to-be-a-
nightmare/

Woody points out that "this [PrintNightmare] is a big deal on domain
controllers ? not so much on stand alone computers." So that's one
large group of Win 7 users off the hook.

He goes on to say that PrintNightmare " allows attackers to wiggle in
via a remote authenticated user and raise the rights of that
account." But if you recall, Windows 7 Home doesn't allow remote
logins,(*) so Windows 7 Home users would seem to be safe. If you have
one of the business editions of Windows 7, and you're not logging in
to your computer remotely, you can just disable Remote Desktop
_server_ (which you should probably do anyway, on general security
principles) and you should be fine.

So the only Windows 7 folks who seem to be vulnerable are those who
allow remote logins into their computer and have the print spooler
both enabled. I don't deny it's a serious vulnerability for them, but
near the end of the article Woods links to a workaround from TrueSec.

(*) All versions of Windows 7 have Remote Desktop _client_, by which
you can use your computer as a terminal to log in to a remote
computer. That's kind of Remote Desktop is not vulnerable.

--
Stan Brown, Tehachapi, California, USA https://BrownMath.com/
https://OakRoadSystems.com/
Shikata ga nai...

Re: PrintNightmare: Update your PC immediately

<MPG.3b57d1983978fcc898fdea@news.individual.net>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1948&group=alt.windows7.general#1948

  copy link   Newsgroups: alt.windows7.general
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!lilly.ping.de!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: the_stan_brown@fastmail.fm (Stan Brown)
Newsgroups: alt.windows7.general
Subject: Re: PrintNightmare: Update your PC immediately
Date: Tue, 13 Jul 2021 17:37:14 -0700
Organization: Oak Road Systems
Lines: 16
Message-ID: <MPG.3b57d1983978fcc898fdea@news.individual.net>
References: <scivkt$hd4$2@dont-email.me> <scjvbg$5jn$1@dont-email.me>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Trace: individual.net 2X5wFiAW8TBzVXoA/ePSbAeyCHBL/wVMGmSXM+ARjS0pd1vrxV
Cancel-Lock: sha1:bpaxjeW97wL5sAKHvXypAUY5sMQ=
User-Agent: MicroPlanet-Gravity/3.0.4
 by: Stan Brown - Wed, 14 Jul 2021 00:37 UTC

On Tue, 13 Jul 2021 08:01:07 -0400, Mayayana wrote:
>
> "Michael Trew" <mt999999@ymail.com> wrote
>
> | Microsoft issues urgent security warning: Update your PC immediately
> |
>
> Once again, problems with allowing remote access to your
> computer. That's the real problem.

History is made: I agree with you, Mayayana. :-)

--
Stan Brown, Tehachapi, California, USA https://BrownMath.com/
https://OakRoadSystems.com/
Shikata ga nai...

Re: PrintNightmare: Update your PC immediately

<MPG.3b57d1cc55ffcc4c98fdeb@news.individual.net>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1949&group=alt.windows7.general#1949

  copy link   Newsgroups: alt.windows7.general
Path: i2pn2.org!i2pn.org!aioe.org!news.uzoreto.com!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: the_stan_brown@fastmail.fm (Stan Brown)
Newsgroups: alt.windows7.general
Subject: Re: PrintNightmare: Update your PC immediately
Date: Tue, 13 Jul 2021 17:38:05 -0700
Organization: Oak Road Systems
Lines: 11
Message-ID: <MPG.3b57d1cc55ffcc4c98fdeb@news.individual.net>
References: <scivkt$hd4$2@dont-email.me> <scjvbg$5jn$1@dont-email.me> <sckcju.420.1@ID-201911.user.individual.net>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Trace: individual.net QkEGDon8ZnzVAFMpWufCrgvsrIE4L7NImHbstmWVw3ayTWI9Ov
Cancel-Lock: sha1:qBYusSeQnsUIJwb1VVqe/c2BPCU=
User-Agent: MicroPlanet-Gravity/3.0.4
 by: Stan Brown - Wed, 14 Jul 2021 00:38 UTC

On 13 Jul 2021 13:48:22 GMT, Frank Slootweg wrote:
> Another approach would be a trusted sites which 'attacks' your
> computer to report any unneeded inbound connections/ports.
>

grc.com, and follow "Shields Up!"

--
Stan Brown, Tehachapi, California, USA https://BrownMath.com/
https://OakRoadSystems.com/
Shikata ga nai...

Re: PrintNightmare: Update your PC immediately

<sclj1n$1in1$1@gioia.aioe.org>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1950&group=alt.windows7.general#1950

  copy link   Newsgroups: alt.windows7.general
Path: i2pn2.org!i2pn.org!aioe.org!b16G+DO7ld86VfOEkvPsDQ.user.gioia.aioe.org.POSTED!not-for-mail
From: not_me@not_there.invalid (David E. Ross)
Newsgroups: alt.windows7.general
Subject: Re: PrintNightmare: Update your PC immediately
Date: Tue, 13 Jul 2021 19:44:09 -0700
Organization: I am @ david at rossde dot com.
Lines: 60
Message-ID: <sclj1n$1in1$1@gioia.aioe.org>
References: <scivkt$hd4$2@dont-email.me>
NNTP-Posting-Host: b16G+DO7ld86VfOEkvPsDQ.user.gioia.aioe.org
Mime-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: 7bit
X-Complaints-To: abuse@aioe.org
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:52.0) Gecko/20100101
Thunderbird/52.9.1
Content-Language: en-US
X-Notice: Filtered by postfilter v. 0.9.2
X-Antivirus: AVG (VPS 210713-10, 07/13/2021), Outbound message
X-Antivirus-Status: Clean
 by: David E. Ross - Wed, 14 Jul 2021 02:44 UTC

On 7/12/2021 8:00 PM, Michael Trew wrote:
> Microsoft issues urgent security warning: Update your PC immediately
>
>
> Microsoft is urging Windows users to immediately install an update
> after security researchers found a serious vulnerability in the
> operating system.
>
> The security flaw, known as PrintNightmare, affects the Windows Print
> Spooler service. Researchers at cybersecurity company Sangfor
> accidentally published a how-to guide for exploiting it.
>
> The researchers tweeted in late May that they had found
> vulnerabilities in Print Spooler, which allows multiple users to
> access a printer. They published a proof-of-concept online by mistake
> and subsequently deleted it - but not before it was published
> elsewhere online, including developer site GitHub.
>
> Microsoft warned that hackers that exploit the vulnerability could
> install programs, view and delete data or even create new user
> accounts with full user rights. That gives hackers enough command and
> control of your PC to do some serious damage.
>
> Windows 10 is not the only version affected -- Windows 7, which
> Microsoft has ended support for last year, is also subject to the
> vulnerability.
>
> Despite announcing that it would no longer issue updates for Windows
> 7, Microsoft issued a patch for its 12-year-old operating system,
> underscoring the severity of the PrintNightmare flaw. Updates for
> Windows Server 2016, Windows 10, version 1607, and Windows Server 2012
> are "expected soon," it said.
>
> "We recommend that you install these updates immediately," the company
> said.
>
> <https://www.ksl.com/article/50203184/microsoft-issues-urgent-security-warning-update-your-pc-immediately>
>

I successfully installed the Servicing stack update (KB4592510). To be
sure, I then did a warm reboot. Then I tried to install the Print
Spooler update (KB5004951) for Windows 7 Ultimate SP1 x64.

When I did a warm reboot, I got the message that configuring the update
failed and the update was being removed. This was during the boot up
after the shutdown.

The failed update file that I tried is
windows6.1-kb5004951-x64_2fcf9eaa66615884884cc1cb9f75fc96294cbf2a.msu

Do I have the wrong file? If not, what did I do wrong?

--
David E. Ross
<http://www.rossde.com/>

At the recent Conservative Political Action Conference in Texas,
a featured speaker urged the mostly Republican attendees to
avoid COVID-19 vaccines. Good! There will be fewer live
Republican voters in 2022.

Re: PrintNightmare: Update your PC immediately

<sclkqf$td0$1@dont-email.me>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1951&group=alt.windows7.general#1951

  copy link   Newsgroups: alt.windows7.general
Path: i2pn2.org!i2pn.org!eternal-september.org!reader02.eternal-september.org!.POSTED!not-for-mail
From: nospam@needed.invalid (Paul)
Newsgroups: alt.windows7.general
Subject: Re: PrintNightmare: Update your PC immediately
Date: Tue, 13 Jul 2021 23:14:23 -0400
Organization: A noiseless patient Spider
Lines: 78
Message-ID: <sclkqf$td0$1@dont-email.me>
References: <scivkt$hd4$2@dont-email.me> <sclj1n$1in1$1@gioia.aioe.org>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Wed, 14 Jul 2021 03:14:24 -0000 (UTC)
Injection-Info: reader02.eternal-september.org; posting-host="6a8d4559cf3c251a001be55926d15d68";
logging-data="30112"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/jz5WhgFbBuVBj8AX5ICgF9U28Wp6eMsI="
User-Agent: Ratcatcher/2.0.0.25 (Windows/20130802)
Cancel-Lock: sha1:Yqj9PYMjsCKXjo7QH+HZGLyW2g8=
In-Reply-To: <sclj1n$1in1$1@gioia.aioe.org>
 by: Paul - Wed, 14 Jul 2021 03:14 UTC

David E. Ross wrote:
> On 7/12/2021 8:00 PM, Michael Trew wrote:
>> Microsoft issues urgent security warning: Update your PC immediately
>>
>>
>> Microsoft is urging Windows users to immediately install an update
>> after security researchers found a serious vulnerability in the
>> operating system.
>>
>> The security flaw, known as PrintNightmare, affects the Windows Print
>> Spooler service. Researchers at cybersecurity company Sangfor
>> accidentally published a how-to guide for exploiting it.
>>
>> The researchers tweeted in late May that they had found
>> vulnerabilities in Print Spooler, which allows multiple users to
>> access a printer. They published a proof-of-concept online by mistake
>> and subsequently deleted it - but not before it was published
>> elsewhere online, including developer site GitHub.
>>
>> Microsoft warned that hackers that exploit the vulnerability could
>> install programs, view and delete data or even create new user
>> accounts with full user rights. That gives hackers enough command and
>> control of your PC to do some serious damage.
>>
>> Windows 10 is not the only version affected -- Windows 7, which
>> Microsoft has ended support for last year, is also subject to the
>> vulnerability.
>>
>> Despite announcing that it would no longer issue updates for Windows
>> 7, Microsoft issued a patch for its 12-year-old operating system,
>> underscoring the severity of the PrintNightmare flaw. Updates for
>> Windows Server 2016, Windows 10, version 1607, and Windows Server 2012
>> are "expected soon," it said.
>>
>> "We recommend that you install these updates immediately," the company
>> said.
>>
>> <https://www.ksl.com/article/50203184/microsoft-issues-urgent-security-warning-update-your-pc-immediately>
>>
>
> I successfully installed the Servicing stack update (KB4592510). To be
> sure, I then did a warm reboot. Then I tried to install the Print
> Spooler update (KB5004951) for Windows 7 Ultimate SP1 x64.
>
> When I did a warm reboot, I got the message that configuring the update
> failed and the update was being removed. This was during the boot up
> after the shutdown.
>
> The failed update file that I tried is
> windows6.1-kb5004951-x64_2fcf9eaa66615884884cc1cb9f75fc96294cbf2a.msu
>
> Do I have the wrong file? If not, what did I do wrong?
>

Read between the lines, here.

Looks like we're going to need to do innumerable
experiments to get this piece of crap to work!!!

https://support.microsoft.com/en-us/topic/july-6-2021-kb5004951-security-only-update-out-of-band-e05a81cd-9b45-4622-b715-ddb2367bca47

"Failure to configure Windows updates.
Reverting Changes.
Do not turn off your computer"

If you do not have an ESU MAK
add-on key installed and activated. <=== paid version of W7 past-2020
support

Does disingenuous Microsoft strike again ?

Now, you have a new hobby. Trying stuff
until an update stays put. Maybe the bloated
version will install ? Or, maybe not.

Paul

Re: PrintNightmare: Update your PC immediately

<scll19$vt0$1@dont-email.me>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1952&group=alt.windows7.general#1952

  copy link   Newsgroups: alt.windows7.general
Path: i2pn2.org!i2pn.org!eternal-september.org!reader02.eternal-september.org!.POSTED!not-for-mail
From: nospam@needed.invalid (Paul)
Newsgroups: alt.windows7.general
Subject: Re: PrintNightmare: Update your PC immediately
Date: Tue, 13 Jul 2021 23:18:01 -0400
Organization: A noiseless patient Spider
Lines: 30
Message-ID: <scll19$vt0$1@dont-email.me>
References: <scivkt$hd4$2@dont-email.me> <scjbfo$a2k$1@dont-email.me> <7bvqegdaiv6fs7dcr8d4guoh4fk2u26e7g@4ax.com> <OiLjj0vlFY7gFwBi@255soft.uk> <sckb62$bac$1@dont-email.me> <1i114ecrfju98$.1ie8h08usu77m.dlg@40tude.net>
Mime-Version: 1.0
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Wed, 14 Jul 2021 03:18:01 -0000 (UTC)
Injection-Info: reader02.eternal-september.org; posting-host="6a8d4559cf3c251a001be55926d15d68";
logging-data="32672"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX19fRqiVufKWoetGvZtqb7gDRIZNnzEfmT0="
User-Agent: Ratcatcher/2.0.0.25 (Windows/20130802)
Cancel-Lock: sha1:yCRB5Q9TSDbLC5/kEUGx/ZvLNZw=
In-Reply-To: <1i114ecrfju98$.1ie8h08usu77m.dlg@40tude.net>
 by: Paul - Wed, 14 Jul 2021 03:18 UTC

PeterC wrote:
> On Tue, 13 Jul 2021 11:23:45 -0400, Paul wrote:
>
>> I followed the link provided by JuanSbrado-3258, downloaded the
>> Servicing Stack Update from the MS Update Catalog, and installed
>> this MSU (KB4592510).
>>
>> https://support.microsoft.com/en-us/help/4592510/servicing-stack-update
>>
>> After installing the Servicing Stack Update, I am now able to install
>> the KB5004953 update.
>>
>> Thank you JuanSabrado-3258."
>>
>> It appears to be (partially) an SSU issue.
>
> I installed the SSU OK. Installation of the Security Update went through to
> the point of restarting; as it booted up it failed and rolled back. Tried
> twice, same result.

See reply to David Ross. Looks like 4951 may need an
ESU MAK. That's $$$ paid extra support for Windows 7
enterprise users or the like. They buy an additional
license key, to get extended support.

We're going to need some "success stories" from
somewhere, to see if the bloated version (the Cumulative)
is the only thing that works for regular Windows7 users.

Paul

Pages:123
server_pubkey.txt

rocksolid light 0.9.81
clearnet tor