Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Focus-Microsoft
[Top] [All Lists]

RE: What server hardening are you doing these days?

Subject: RE: What server hardening are you doing these days?
Date: Thu, 10 Nov 2005 09:12:44 -0500
Personally I us the Windows Server 2003 Security Guide at
http://www.microsoft.com/technet/security/prodtech/windowsserver2003/w20
03hg/.  If it is not in there I am very cautious about applying the
change.  There is also a windows XP security guide at
http://www.microsoft.com/technet/security/prodtech/windowsxp/secwinxp/de
fault.mspx.  I made one change that was not in either guide.  The change
was from a reputable source and claimed this should have no impact on
end users.  This was a modification to the behavior of IE to fix an
unpatched vulnerability.  I did test the change, but not well enough.
Shortly after rolling out the change to our entire organization, one of
our applications stopped working.  This was a third part application.
We had rolled it out using a custom adiminstrative template.  The roll
back required another modification using a custom template.  Again
testing was not totally complete.  It took several weeks before we
finally removed this from all the PCs in our domain.

Dennis

-----Original Message-----
From: Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP]
[mailto:sbradcpa@pacbell.net] 
Sent: Wednesday, November 09, 2005 4:23 PM
To: focus-ms@securityfocus.com
Subject: What server hardening are you doing these days?


Steve Riley's WebLog : When security breaks things:
http://blogs.technet.com/steriley/archive/2005/11/08/414002.aspx

Are folks doing additional hardening to their servers these days and if 
so, what guidance are you using?

Interesting blog post about the impact of such hardening and not 
supported ACL adjusting.

-- 
Letting your vendors set your risk analysis these days?  
http://www.threatcode.com


------------------------------------------------------------------------
---
------------------------------------------------------------------------
---


---------------------------------------------------------------------------
---------------------------------------------------------------------------


<Prev in Thread] Current Thread [Next in Thread>