update.microsoft.com.nsatc.admin.fixme


hello,

i not using wsus, closest forum find related decided post question.

i have been dealing issue several days ever since microsoft removed xp support list of supported products. have not found else issue yet , not sure way should go here.

first of all, details of setup. have firewall protecting domain network. closed network no servers on other side of firewall , no dmz.

started last week when began see alert dns queries in firewall logs.


started analyzing packets , found coming inside of firewall enabled logging on internal dns servers. found dns queries originating many of internal workstations. , querying our internal dns server location of following domain: "(6)update(9)microsoft(3)com(0)." of course our internal dns server forwarding information on our isp's dns server.

proceeded hex dump of both outgoing queries , incoming responses.

outgoing query had hex dump:

"*.......update.microsoft.*
*com.nsatc.net......!....*

incoming responses isp's dns server different:

"*.......update.microsoft.*
*com.nsatc.net......!....*
*...o...admin.!.fixme.exa*
*mple.com.se....*0.....6.*"

have idea "admin fixme" means inside of hex dump? looks cause of alerts "example.com" inside of packet registers attack signature. wrong, not sure start looking. should contact isp or need configuration of automatic updates workstations? searches on internet remotely resembling have turned empty.



appreciate can here since drive me insane.


thanks

does have idea "admin fixme" means inside of hex dump?

don't know authoritatively, "fixme" known term in windows update community, educated guess browse knowledge base article , clicked on "fix me" link in article. suggest inquiring user of client system originated web request.

lawrence garvin, m.s., mcsa, mcitp:ea, mcdba
solarwinds head geek
microsoft mvp - software packaging, deployment & servicing (2005-2014)
mvp profile: http://mvp.microsoft.com/en-us/mvp/lawrence%20r%20garvin-32101
http://www.solarwinds.com/gotmicrosoft
the views expressed on post mine , not reflect views of solarwinds.



Windows Server  >  WSUS



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Windows 2016 RDS event 1306 Connection Broker Client failed to redirect the user... Error: NULL