SharePoint has been pretty luck over the years to avoid the focus of hackers and those looking to create exploits.
About a month ago a vulnerability was reported for SharePoint relating to a possible exploit of a 0day elevation of priviledges via a DOS attack to help. The workaround at the time was to disable the help feature in SharePoint.
V1.0 (April 29, 2010): Advisory published.
V2.0 (June 8, 2010): Advisory updated to reflect publication of security bulletin.
<update (June 22, 2010)>The SharePoint Team has responded with a blog titled “Installing KB938444” tracking a small number of customers who have the issue after installing the patch via windows update. The small business server folks also have a post about Central Admin not being accessible after installing KB938444. They also have some suggestions for troubleshooting the patching as it relates to SharePoint patches in general which I recommend reading.</update>
Microsoft responded by Microsoft Security Advisory (983438) and have issued MS10-039 to address this issue. Creating a patch that was flagged as critical. Those which had their SharePoint servers set to auto update were surprised when they came in to find their SharePoint servers were down, or reporting can’t connect to config database.
There apparently are a number of reported issues with the patching where essentially the patch wasn’t successfully installed and are finding issues post install. In many cases the content databases are out of sync with the binaries. Microsoft is investigating these patching issues and may release an updated patch.
A few articles speak to this as a common occurrence and apparently surprised a few people:
There is a good string in the Newsgroups which goes into the detail of people troubleshooting this issue. I recommend everyone read through this string for troubleshooting detail and more awareness of what has been reported.
As with any SharePoint Patch you should never “just install” the patch. You should test it. It is not recommended on SharePoint Server to use Windows Update Automatic updates. For many reasons the databases will likely be in use and a high availability roll through the servers option could be used to deploy the patches.
For anyone who was affected in a negative way, they should first make sure that the install was successful. Check your logs. I expect most of the failures are due to binary install without databases being updated. As is stated in the newsgroups, the best way to force the patch to apply and update the schema to the databases is to run psconfig with the force parameter.
psconfig -cmd upgrade -inplace b2b -wait –force
That’s the recommended way, which is the equivalent of stsadm –o upgrade with the force option. Others @collabadam have reported that retracting and reinstalling manually has addressed the problem.
What people are missing is the fact that patches should never just “be installed” they have to be rolled out. A patch must be installed on each server in the farm, WSS ones first, then MOSS ones. (Yep that applies in this case!!) Then after they are both installed you can then run the psconfig command above. This will ensure the upgrade has fully completed. Note: You may have to reboot if any binaries are in use.
Since SharePoint is an app which essentially is cumulative it is important that patches are installed in the right order. The latest patches in this case should be installed after the latest service pack as a recommended practice.
If it was me and I wanted to ensure it was going to work right, I’d go with the path that Todd Carter recommends for minimizing downtime. (Assuming this is all tested and passed off as good. That is 1) detach your content databases 2) Install patches (WSS first then MOSS across all your servers starting with the central admin box first) 3) Run psconifg on just the central admin box 4) Reattach all your content databases
Essentially it’s basically like doing a database attach upgrade for the patch.
Did a security patch bust WSS 3.0?
Microsoft says it "is investigating new public claims of a possible installation issue involving MS10-039, a bulletin issued in the June update" and "will make further guidance available if necessary once our investigation is complete."
Hold off on patching if you haven’t on your intranets. I think that’s essentially the tough thing to say since the patch is listed as critical and at the same time may have a regression or bug. Having a DOS attack on an intranet is extremely unlikely. The workaround is to disable the help feature. Don’t do anything rash, follow your procedures for testing and keep in touch with Microsoft.
If you are set to auto update critical patches in any of your SharePoint environments, turn it OFF. You should NEVER have your SharePoint servers set to autoupdate for patching. You should be testing your patches and installing them methodically during a downtime window.
If you have already patched your servers you can either continue with forcing the databases to update with the psconfig –cmd upgrade –inplace b2b –wait –force command. This may take a while, be patient. Reinstalling SharePoint may work, but whatever you reinstall needs to be at a minimum at the version that was installed and applied to the databases. I caution against this since the problem isn’t with the binaries, the problem is in the inconsistency between the databases and the binaries. If the binaries are newer than the databases, they will be upgraded when attached, if the binaries are older then you get the can’t connect to config db error.
If you’re struggling through this, you may find these resources on WSS 3.0 and MOSS 2007 patching useful.
SharePoint TechNet patching resources:
1. Does this affect SharePoint 2010?
No
2. Why are my servers down?
You likely had auto update turned on and the patch was applied, but the patch wasn’t fully installed to update the schema version in the database.
3. I’m getting can’t connect to database what should I do?
If you’re in a single server farm, you should run the PSConfig wizard or simply at the command prompt run: psconfig –cmd –inplace b2b –wait –force
This will force the patch to install. Note: You may need to reboot
If this issue persists contact support, they are available for free for patching issues. See “Help and Support” below.
4. I haven’t installed this critical patch, what should I do?
Don’t install it yet, Microsoft is investigating it. Watch the security bulletins for update of an update of this patch. Bulletin: MS10-039
5. What is the issue in this critical patch?
See below for the info.
6. I’m reading about this and it looks serious why now?
This is actually if you can believe it one of the first critical patches. People who are surprised are those that have auto update turned on. Make sure all your SharePoint servers are not set to auto update.
7. How do I turn off Automatic Updates?
Go into the Control Panel, Double Click on Automatic Updates, and uncheck the box that says "keep my computer up to date…"
8. Why are you saying it’s a best practice NOT to use Automatic Updates for SharePoint?
Because SharePoint patching is tricky. Some patches may take HOURS to update, and patching in SharePoint 2007 causes your environment to be down without manual intervention.
9. Does this patching get any better in SharePoint 2010?
YES! The whole story gets better, that’s for another post, but I still DO NOT recommend Automatic updates. You want to be in control of patches.
10. If I have the MOSS patch do I need the WSS one?
Yes, in fact it should be install the WSS one first, then the MOSS one then psconfig. See the Technet articles for detailed instructions.
11. I’m a little freaked out about all this patching after reading the newsgroups and some of these articles…
Don’t be freaked out. The product team is aware of these issues and has made major investments in SharePoint 2010 to provide more control. Is patching complex in 2007? Yes, it’s a pain, so read up on those technet articles below. It will be one of the painful things you have to do in SharePoint 2007, but the service packs and cumulative updates are worth it. Just make sure you’ve got lots of test experience. Those that have done lots of patching don’t have issues. It’s about being methodical and knowing how to troubleshoot.
Description
Vulnerabilities in Microsoft SharePoint Could Allow Elevation of Privilege (Replaces MS08-077 )
Microsoft Security Bulletin MS10-039: Published June 8
Full details on all the patches in June Black Tuesday (Patch Tuesday)
Credit:
Chris Weber of Casaba Security
Common Vulnerabilities and Exposures Database references:
US based customers can call Microsoft for free patch related support on 1-866-PCSAFETY
Cross-site scripting (XSS) vulnerability in _layouts/help.aspx in Microsoft SharePoint Server 2007 12.0.0.6421 and possibly earlier, and SharePoint Services 3.0 SP1 and SP2, versions, allows remote attackers to inject arbitrary web script or HTML via the cid0 parameter.
Cross-site scripting (XSS) vulnerability in the toStaticHTML API, as used in Microsoft Office InfoPath 2003 SP3, 2007 SP1, and 2007 SP2; Office SharePoint Server 2007 SP1 and SP2; SharePoint Services 3.0 SP1 and SP2; and Internet Explorer 8 allows remote attackers to inject arbitrary web script or HTML via vectors related to sanitization.
Unspecified vulnerability in Microsoft Windows SharePoint Services 3.0 SP1 and SP2 allows remote attackers to cause a denial of service (hang) via crafted requests to the Help page that cause repeated restarts of the application pool, aka "Sharepoint Help Page Denial of Service Vulnerability."
More information on Symantec’s http://www.securityfocus.com/bid/40409
http://www.microsoft.com/technet/security/bulletin/ms10-039.mspx
983444 (http://support.microsoft.com/kb/983444/ ) MS10-039: Description of the security update for Windows SharePoint Services 3.0: June 8, 2010
979445 (http://support.microsoft.com/kb/979445/ ) MS10-039: Description of the security update for Microsoft Office SharePoint Server 2007: June 8, 2010
Info from KB:
“This security update resolves one publicly disclosed and two privately reported vulnerabilities in Microsoft SharePoint. The most severe vulnerability could allow elevation of privilege if an attacker convinced a user of a targeted SharePoint site to click on a specially crafted link.
The security update is rated important for all supported versions of Microsoft SharePoint Services 3.0 and all supported editions of Microsoft Office InfoPath 2003, Microsoft Office InfoPath 2007, and Microsoft Office SharePoint Server 2007. For more information, see the subsection, Affected and Non-Affected Software, in this section.
The security update addresses the vulnerabilities by modifying the way that Microsoft SharePoint validates input that is provided to an HTTP query, the way that toStaticHTML sanitizes HTML content in Microsoft SharePoint, and the way that Microsoft SharePoint handles specially crafted requests to the Help page. For more information about the vulnerability, see the Frequently Asked Questions (FAQ) subsection for the specific vulnerability entry under the next section, Vulnerability Information.
This security update also addresses the vulnerability first described in Microsoft Security Advisory 983438.
Recommendation. Microsoft recommends that customers apply the update at the earliest opportunity.
Known Issues. Microsoft Knowledge Base Article 2028554 documents the currently known issues that customers may experience when installing this security update. The article also documents recommended solutions for these issues. When currently known issues and recommended solutions pertain only to specific releases of this software, this article provides links to further articles.”
Not affected
[1]For supported editions of Microsoft Office SharePoint Server 2007, in addition to security update package KB979445, customers also need to install the security update for Microsoft Windows SharePoint Services 3.0 (KB983444) to be protected from the vulnerabilities described in this bulletin.
For home users, no-charge support is available by calling 1-866-PCSAFETY in the United States and Canada or by contacting your local Microsoft subsidiary. For more information about how to contact your local Microsoft subsidiary for support issues with security updates, visit the Microsoft International Support website:
http://support.microsoft.com/common/international.aspx?rdpath=4 (http://support.microsoft.com/common/international.aspx?rdpath=4)
North American customers can also obtain instant access to unlimited no-charge email support or to unlimited individual chat support by visiting the following Microsoft website:
http://support.microsoft.com/oas/default.aspx?&prid=7552 (http://support.microsoft.com/oas/default.aspx?&prid=7552)
For enterprise customers, support for security updates is available through your usual support contacts.
It’s no longer a fierce battle. The battle is over and we welcome you with open arms. It’s a time of reparations it’s a time of healing. If I could I’d say welcome Notes admins and developers on an icon like the statue of liberty. Which represents the open arms that America once had for welcoming the rejected.
12 years ago I use to bow to the power of the Notes developers as I’d do our little ASP apps. On the web team with Notes/Domino developers and us purist ASP later to be Exchange, .NET and SharePoint development team.
Had an interesting conversation with Tim Fountain a Notes to SharePoint shepherd now at Quest who has been helping Notes people find their way into SharePoint with tools and solutions with the Notes Migrator. Fascinating to hear the insights from the notes migration team which essentially spent their careers now on both sides of the fence. Tim in a recent email explained…
“There’s been recent disturbances in the Notes blogosphere as two respected Notes developers have started to chart a different course. One headed straight for SharePoint. His first two posts on the topics:
I think if we can get these folks hooked into the community, once they get past the technology differences they become powerful advocates. We need a welcome wagon for the Notes transition people.” closed quote.
I appreciate Tim’s insight and agree we need to do something to better integrate and help Notes/Domino people integrate into our community.
I saw this tweet this morning. Which has already been retweeted a couple of times… @cool_v: is wondering why IBM doesn’t advertise Lotus Notes/Domino???? I am so tired of hearing about Sharepoint!
I think they need to step back a little… The concern isn’t about the advertising, it’s about it’s lack of strategy or what comes across as flippant and cutting it comes across as abandon. The lumbering giant of Notes is tired. It’s time to put it to rest.
We’ve all come a long way. I think it’s time to see SharePoint as the true App Development Platform that it is. SharePoint 2010 with SharePoint Designer 2010 and Visual Studio 2010 have a lot to bring for the Notes/Domino developer to make it sooo much easier for them.
For some serious insight let me quote the Notes evangelist JonVon.Net
“…something else has been going on at the same time. Along came Connections – based entirely on Websphere and Java. The Sametime software has become, more and more, based on Java and Websphere as well. And Quickr, again based on J2EE, is replacing NSF-based Quickplace. The NSF just isn’t present in any meaningful way in IBM’s new Social Software stack. “
They tried to sell a different email engine under the Workplace brand, but that effort folded when no one, anywhere, bought it. Goodbye Workplace.
Something about that thing about IBM selling Lotus Notes as messaging, and only as messaging, has finally caught up with us. Something about IBM fundamentally not believing in Notes as an application development platform, and refusing to market it as application development, has created the reality that we now face in the marketplace. And the competition is at long last eating Lotus Notes for breakfast. And honestly, I think at some level in the IBM organization, there are those who are relieved it’s finally going away. Because what they want is to sell the really expensive Websphere stuff. Domino, I’m guessing, just doesn’t net them the rivers of cash from the Fortune 100 like the big iron stuff does. But Domino getting its clock cleaned by Exchange and Sharepoint leaves a huge hole in IBM’s strategy.
… It’s good stuff. But it seems, it’s too little, too late…
See, where I work, they are abandoning Notes mail for Exchange. And last week we were told that the political winds at high levels in our company are whispering "Sharepoint". We responded by saying that we were ultimately agnostic about what code we wrote in. And this is essentially true. But we know in our heart of hearts that we will not be as productive as we were, no matter how good we get at Sharepoint development or any of the technologies in the Microsoft stack. We were also told, by the way, that any of us who wished to remain "pure Domino" developers would be given personal assistance in finding a new job.”
Read the full text and don’t miss the insightful comments at Javon.net “Lotus Notes: The Long Goodbye”
(emphasis added)
—
Thanks for being so honest. Let us in the SharePoint community know what we can do to help.
William Eberle
RE: Lotus Notes: The Long Goodbye
“It always saddens me to read posts, or see discussions, like this. The same talk has been going on for years. The part that makes me sad is the truth of it and the waste of the potential of Lotus Notes/Domino.
Despite the emotional effect it has on me, it is good to see such well-written words as it helps keep in front of me a clearer picture of the current state of Lotus Notes/Domino.
Well done!”
Matt White
Lotus Notes: The Long Goodbye
Great post all round. I suspect, unfortunately, it is all too accurate.
Stuart McIntyre
Lotus Notes: The Long Goodbye
*Very* uncomfortable reading, but you made your point beautifully. I wish I could say ‘it ain’t so’, but I can’t.
I think many in the SharePoint Community are realizing we are having a great time. The work of the SharePoint community has changed to be much more like a family these days. It has been for years now, but lately the community has really been jelling.
I mentioned that I was reaching out to the LATAM and Hispanic SharePoint Community. That outreach continues. I recently returned from one of my favorite conferences ever in Lima, Peru. That was most awesome. Looking forward to next year! I hope we’ll add stops in Santiago and Rio next time.
June 3
Tercer Simposio Latinoamericano de SharePoint, sede México. SharePoint 2010, La plataforma de productividad para la empresa y la Web
Jueves, 03 de Junio de 2010 09:00 a.m. – jueves, 03 de junio de 2010 08:00 p.m. Ciudad de México
Hora de recepción: 08:30 a.m.
Hacienda Los Morales
Salón La Troje
Vázquez de Mella 525 col. Bosque, México, D.F.
México Distrito Federal 11510
Mexico
Next week I’m in Mexico City for an annual SharePoint Seminario event that is on it’s 3rd year! Last year I met SharePoint Experts, Guru’s and MVPs from Bolivia, Chile, Costa Rico and Mexico. I’m looking forward to seeing Hector, Luis, and the rest of the crew. I learned so much last year and gained some valuable connections.
Luis sent me a huge set of links around the community and the event.
Registration Url: https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032452786&Culture=es-MX
Community page: http://mssharepoint.multiply.com
Blogs Page: http://sharepointblogs.com.mx
PodCast Page: http://www.sharepoint.com.mx
Facebook Group: http://www.facebook.com/home.php?#!/group.php?gid=56850858767&ref=ts
LinkedIn Group: http://www.linkedin.com/groups?gid=1926509&trk=myg_ugrp_ovr
I recently connected with the Quest country manager in Mexico, Diana Ibáñez. Will be great to see how Quest is doing in Mexico and better understand the SharePoint tools market.
Hope to see you there!!!
I got a brilliant Question a while back at a SharePoint 2010 event. During the Q&A someone asked… are Service Apps easier to manage than the old SSP?
Why is that such a brilliant question? Because there are so many levels to the answer to that question. The container of services such as the SSP has become so flexible, I’m finding just getting my head around proxy groups, service instances, and services with sync and dependencies that it’s easy to say No way! Today I have to say man the service app alone has grown exponentially in SharePoint 2010. You start digging and you get deeper and deeper and it keeps going! I’m working on a deck for Teched on Global Deployments and I’m finding it’s very difficult to simply explain the dependencies and how the metadata service would work across the WAN. The posters have been the most helpful as I’ve found there really isn’t much written on how to deploy services across the wan just yet. I do promise to put together my thoughts on the topic following this presentation. Global SharePoint 2010 has tons of potential. Obviously we still don’t have replication, but did you know you can deploy multiple metadata services and designate one as primary? I didn’t, but I’m finding as I keep digging these service apps and what they are continues to provide more solutions and more flexibility.
Here’s a few things to get your head around…
Are there services in SharePoint that are not Service Apps?
Yes, there are many… they are listed in “services on server” the section in Central Admin that ultimately determines what you’re running on your boxes. The only one that’s required to run on the web front end is the SharePoint Foundation Web Application. The inbound email is another common example of a service that usually is configured on a front end or two if you know what you’re doing. That Foundation Web Application is actually a requirement to run on all WFEs, don’t forget it! If that service isn’t running you’re WFE box is effectively down. The service should only be stopped on the App tier.
Is there one search database? How many search databases can I expect?
There are many. In fact the larger the environment the more property and crawl databases you’ll get. You’ll also see the Search Query and Site Settings Service for managing the search settings that are configured per site collection. The Search Server Search service has it’s own database as well. The databases and configuration should be deployed
Don’t be confused if all you see is this dialog in the posters.
The Profiles don’t just rely on one database either… or just one service for that matter. If you’re wondering why profiles don’t work, make sure you are following the path of making sure that social tagging and managed metadata service are also enabled. These are dependencies that aren’t very apparent though the UI. Some people will think Profile Sync is to another Profile Service. It’s actually required for synchronizing between Active directory. There’s a lot to get your head on around here. I’ve been enjoying Octavie’s blog a new one for me, but very rich with information.
I’ve heard a lot of complaints about mysites or profiles failing to be configured properly. I suggest reading these two articles. First Octavie’s Setting up User Profiles Service Application, he learned by making mistakes. I like those kind of articles. The setting up the managed metadata service is good stuff too. Remember you can and should I’d say, plan on having local managed metadata services even if only used for cache and designating the main one as primary. Wish there were more good examples of global deployment step by step configurations out there.
The TechNet article “Configure Profile Synchronization” is a new article only as old as May 12. Very fresh and relevant. How about the hidden “Profile Synchronization does not work on a stand-alone installation for SharePoint Server 2010.” That’s wild isn’t it!
As well people who have ever installed or configured an application. Ever heard “After starting the User Profile Synchronization service, wait for 5-10 minutes before proceeding to the next step.” That’s actually very important.
These services are started automatically when the User Profile Synchronization service is started. It may take up to 10 minutes for these to start after starting the User Profile Synchronization Service. Do not start them manually.
Some Free “15” Planning Feedback SharePoint Team…
This request it to make the deployment and configuration easier. Request is for a wizard. Let’s come up with Service App Proxy Groups that essentially bring together groups of functionality. I know we just got out from under the SSP grouping, and it being to restrictive, now we’re on the opposite end of the spectrum where you pick and choose everything, but it could be easier if you said. I want Search! or I want ECM or I want Social Mysites and Profiles and you got all the services and dependencies all getting configured in a nice little wizard. It’s tough to know what the options are and what’s required. If you don’t know what the questions and options are, how can you effectively deploy in the best configuration?
In the meantime… Would also be nice to have some serious guidance around how to pull off Enterprise Managed Metadata. There are lots of nice hints, but this is something that could really be put together that shows how the primary and synchronization and using it as a true global service such that the AJAX works, and the branching of the term store works by region, but also gives you the real nature of enterprise managed taxonomy. There’s a set of docs we need for IT and a set of docs for the business. Sounds like an SDPS for Enterprise Information Management.
In my next post on Service Apps I’ll discuss more about the global aspects…
Ryan Duguid, Microsoft’s Senior Product Manager for ECM. We’re really happy to have Ryan participate in what’s sure to be another great webinar focused on a topic that is near and dear to our hearts, email management in SharePoint 2010. Microsoft will be strongly promoting the use of SharePoint 2010 for email management in this webinar.
Register for the Webcast
You are invited to attend the June 17th webinar: “SharePoint 2010 – What’s New for Email Management?” Join guest speaker Ryan Duguid, Microsoft’s Senior Product Manager for ECM, as he discusses SharePoint 2010 and how it fits into Microsoft’s overall email management strategy for the enterprise.
SharePoint 2010 introduces a number of new features that greatly enhance its capability as a platform for Enterprise Content Management. Since email is an important part of any organization’s ECM strategy, understanding how SharePoint 2010 can be used for email management is critical. In the webinar, Ryan will provide some insights into:
• What’s new in SharePoint 2010 to enrich email management
• How taxonomy & the Managed Metadata Service benefit email
• How to leverage the Content Organizer
• The role of Document Sets & In-Place Records Management
Colligo will also be demonstrating the new SharePoint 2010 features of the Contributor Add-In for Outlook and show how they extend and enhance the email management capabilities of SharePoint 2010.
WHAT – SharePoint 2010 – What’s New for Email Management?
WHEN & WHERE – Thursday, June 17, 2010
8:00 AM Pacific / 11:00 AM Eastern
4:00 PM London / 5:00 PM Paris
Online Webinar
PRESENTERS – Ryan Duguid, Sr. Product Manager, ECM, Microsoft
Barry Jinks, President & CEO, Colligo Networks Inc.
COST – COMPLIMENTARY
Register for the Webcast