Home > Pitching patch: Shavlik Technologies
Information Security magazine:
EMAIL THIS

Pitching patch: Shavlik Technologies

27 May 2005 | By Neil Roiter

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Shavlik Technologies's response was unlike any of the others we evaluated. Shavlik did an excellent job explaining the features of its product, HFNetchkPro. If anything, we got more detail than we needed. It also offered two distinct deployment scenarios: one centrally managed and the other for distributed management.

Beyond that, however, Shavlik didn't make any attempt to discuss its product in terms of our RFP's requirements, environment description and pain points. As a result, we had to pick through the response to figure out what applied to our company.

Like St. Bernard, Shavlik offers the option of using agent-based or agentless options, which would give us a lot of flexibility. The agents (local copies of hfnetchk.exe) check in with the server and automatically download any missing patches. HFNetchkPro was the only suggested product that's agents perform automatic bandwidth throttling, a big plus for distributed environments.

The agent and agentless architectures aren't well integrated. Both options allow for local patch repositories to reduce overall traffic, but each requires its own coordinating and local servers, and its own consoles. Agentless machines have to be grouped manually, while the agent devices can be grouped dynamically.

Shavlik is the only vendor we examined that doesn't test patches for interoperability conflicts. It basically checks to ensure that its patch installs like Microsoft says it will.

We had security concerns with the agentless technology. The local distribution servers can use UNC, which leaves systems open to worms and viruses seeking to exploit open file shares. Further, it uses native Windows logons for authenticating as admins to the clients, meaning credentials are transmitted in cleartext or easily broken hashes.

<< Return to Pitching patch

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary




Search Additional Security Research and Solutions
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts