Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: What server hardening are you doing these days? |
|---|---|
| Date: | Thu, 10 Nov 2005 09:12:44 -0500 |
Personally I us the Windows Server 2003 Security Guide at http://www.microsoft.com/technet/security/prodtech/windowsserver2003/w20 03hg/. If it is not in there I am very cautious about applying the change. There is also a windows XP security guide at http://www.microsoft.com/technet/security/prodtech/windowsxp/secwinxp/de fault.mspx. I made one change that was not in either guide. The change was from a reputable source and claimed this should have no impact on end users. This was a modification to the behavior of IE to fix an unpatched vulnerability. I did test the change, but not well enough. Shortly after rolling out the change to our entire organization, one of our applications stopped working. This was a third part application. We had rolled it out using a custom adiminstrative template. The roll back required another modification using a custom template. Again testing was not totally complete. It took several weeks before we finally removed this from all the PCs in our domain. Dennis -----Original Message----- From: Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP] [mailto:sbradcpa@pacbell.net] Sent: Wednesday, November 09, 2005 4:23 PM To: focus-ms@securityfocus.com Subject: What server hardening are you doing these days? Steve Riley's WebLog : When security breaks things: http://blogs.technet.com/steriley/archive/2005/11/08/414002.aspx Are folks doing additional hardening to their servers these days and if so, what guidance are you using? Interesting blog post about the impact of such hardening and not supported ACL adjusting. -- Letting your vendors set your risk analysis these days? http://www.threatcode.com ------------------------------------------------------------------------ --- ------------------------------------------------------------------------ --- --------------------------------------------------------------------------- ---------------------------------------------------------------------------
| Previous by Date: | What server hardening are you doing these days?, Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP] |
|---|---|
| Next by Date: | RE: What server hardening are you doing these days?, Derick Anderson |
| Previous by Thread: | Re: What server hardening are you doing these days?, Thor (Hammer of God) |
| Next by Thread: | RE: What server hardening are you doing these days?, Derick Anderson |
| Indexes: | [Date] [Thread] [Top] [All Lists] |