We thought we would share our instructions for getting a Windows 2000 server
up-to-date. The download URLs we have included are only for English
hotfixes and does not cover client software like Internet Explorer.
1. Download and install the high encryption pack
(http://www.microsoft.com/windows2000/downloads/recommended/encryption/defau
lt.asp)
2. Reboot (this is essential at this point or the next step will have
problems).
3. Download and install Service Pack 1
(http://www.microsoft.com/windows2000/downloads/recommended/sp1/default.asp)
4. Reboot again.
5. Download WGET for Windows
(http://www.interlog.com/~tcharron/wgetwin.html)
6. Run the attached hotfixes.cmd file.
7. Check the folder for any hotfixes that have been renamed with the .bad
extension and download and reapply those.
7. Run keymigrt.exe and follow instructions if there are any.
8. Reboot.
9. Run qfecheck.exe /v to verify that everything installed correctly
9. As new hotfixes are released, add the download URLs to hotfixes.txt.
The attached batch file will download all the service packs into the current
directory. It will then go through and verify the signatures on each one,
renaming any files that do not pass the check. It will then silently
install each hotfix. After downloading the first time you can remove the
line in the batch file that does the downloading and it will use all the
hotfixes in the current directory. Note that although install order does
not matter in Win2k, the batch file will install the hotfixes in the order
in which they were downloaded which is the proper install order.
If you have any comments or questions, we would be glad to hear them. But
before you ask, no, we do not plan on making one of these for NT4 at this
time.
Xato Network Security Team
www.xato.net
--------------------------------------------------
Copyright ©2001 Xato Network Security, Inc.
Xato is a security consulting firm specializing
in Windows 2000 server security. Contact us at
[EMAIL PROTECTED] or [EMAIL PROTECTED] for more information
regarding our consulting services.
--------------------------------------------------
windows 2000 win2k w2k IIS security services consulting
patches service packs sp1 sp2 sp3 install update
administrator password hack pakc harden script command
--------------------------------------------------
"ignore the man behind the curtain"
--------------------------------------------------
hotfixes.zip