10 mistakes to avoid when securing your Microsoft Network Infrastructure

Size: px
Start display at page:

Download "10 mistakes to avoid when securing your Microsoft Network Infrastructure"

Transcription

1 10 mistakes to avoid when securing your Microsoft Network Infrastructure Donald R. Glass CISSP, CISA, MCSE, MCSE+I, CNE 1

2 Agenda Preliminaries Introduction, Sun Tzu SANS/ FBI Top 10 List (Microsoft Related) The vulnerabilities The countermeasures Live Demo Conclusions 2

3 Something you should know 3

4 Preliminaries Name: Donald R. Glass, you will never guess what the R. stands for. I won t tell you either. Height: 6 10 = 206 cms. I never played basketball, I never will. Horrendous voice, if you don t understand something, please let me know. All kind of questions and observations will be welcomed. 81 slides, 90 minutes -> > 1.1 min/slide Enjoy the ride... 4

5 The Art of War, Sun Tzu 5

6 The Art of War Hence to fight and conquer in all your battles is not supreme excellence; supreme excellence consists in breaking the enemy's resistance without fighting. Sun Tzu, The Art of War 6

7 The Art of War If you know the enemy and know yourself, you need not fear the result of a hundred battles. If you know yourself but not the enemy, for every victory gained you will also suffer a defeat. If you know neither the enemy nor yourself, you will succumb in every battle. Sun Tzu, The Art of War. 7

8 The ten most commonly exploited vulnerable services in Windows. 8

9 The List Released by the SANS Institute and the National Infrastructure Protection Center (NIPC). It s a two Top Ten lists: one for *NIX and one for Windows. Live document. The Top Twenty is a prioritized list of vulnerabilities that require immediate remediation. 9

10 10

11 Top Vulnerabilities to Windows Systems W1 Internet Information Services (IIS) W2 Microsoft Data Access Components (MDAC) -- Remote Data Services W3 Microsoft SQL Server W4 NETBIOS -- Unprotected Windows Networking Shares W5 Anonymous Logon -- Null Sessions 11

12 Top Vulnerabilities to Windows Systems W6 LAN Manager Authentication -- Weak LM Hashing W7 General Windows Authentication -- Accounts with No Passwords or Weak Passwords W8 Internet Explorer W9 Remote Registry Access W10 Windows Scripting Host 12

13 W1 Internet Information Services (IIS) Failure to handle unanticipated requests. Many IIS vulnerabilities involve a failure to handle improperly (or just deviously) formed HTTP requests. A remote attacker may: View the source code of scripted applications. View files outside of the Web document root. View files the Web server has been instructed not to serve. Execute arbitrary commands on the server (resulting in, for example, deletion of critical files or installation of a backdoor). Example: Unicode directory transversal vulnerability (Code Blue worm). 13

14 W1 Internet Information Services (IIS) Buffer Overflows.. Many ISAPI extensions (including the ASP, HTR, IDQ, PRINTER, and SSI extensions) are vulnerable to buffer overflows. A carefully crafted request from a remote attacker may result in: Denial of service. Execution of arbitrary code and/or commands in the Web server's user context (e.g., as the IUSR_servername or IWAM_servername user). Example:.idq ISAPI extension vulnerability (Code Red and Code Red II) 14

15 W1 Internet Information Services (IIS) Sample Applications. A sample application, newdsn.exe, allowed the remote attacker to create or overwrite arbitrary files on the server. A number of such applications allow remote viewing of arbitrary files, which may be used to gather information such as database userids and passwords. An iisadmin application, ism.dll dll,, allows remote access to sensitive server information including the Administrator's password. 15

16 W1 Internet Information Services (IIS) Operating Systems Affected Windows NT 4 (any flavor) running IIS 4 Windows 2000 Server running IIS 5 Windows XP Professional running IIS

17 W2 Microsoft Data Access Components (MDAC) -- Remote Data Services The Remote Data Services (RDS) component in older versions of Microsoft Data Access Components (MDAC) has a program flaw which allows remote users to run commands locally with administrative privilege. Combined with a flaw in Microsoft Jet database engine 3.5 (part of MS Access), this exploit may also provide anonymous external access to internal databases. These flaws are well- documented and solutions have been available for more than two years, but outdated or misconfigured systems remain exposed and subject to attack. 17

18 W2 Microsoft Data Access Components (MDAC) -- Remote Data Services Operating Systems Affected Most Microsoft Windows NT 4.0 systems running IIS 3.0 or 4.0, Remote Data Services 1.5, or Visual Studio

19 W3 Microsoft SQL Server The Microsoft SQL Server (MSSQL) contains several serious vulnerabilities that allow remote attackers to obtain sensitive information, alter database content, compromise SQL servers, and,, in some configurations, compromise server hosts. MSSQL vulnerabilities are well-publicized and actively under attack. Port 1433 (MSSQL default port) has also been regularly registered d as one of the top scan ports in the Internet Storm Center. 19

20 W3 Microsoft SQL Server Operating Systems Affected Any Microsoft Windows system with Microsoft SQL Server 7.0, Microsoft SQL Server 2000 or Microsoft SQL Server Desktop Engine 2000 installed. 20

21 W4 NETBIOS -- Unprotected Windows Networking Shares Microsoft Windows provides a host machine with the ability to share files or folders across a network with other hosts through Windows network shares. The underlying mechanism of this feature is the Server Message Block (SMB) protocol, or the Common Internet File System (CIFS). Example Sircam virus (see CERT Advisory ) 22) and Nimda worm (see CERT Advisory ). 26). 21

22 W4 NETBIOS -- Unprotected Windows Networking Shares Operating Systems Affected Windows 95 Windows 98 Windows NT Windows Me Windows 2000 Windows XP. 22

23 W5 Anonymous Logon -- Null Sessions A Null Session connection, also known as Anonymous Logon, is a mechanism that allows an anonymous user to retrieve information (such as user names and shares) over the network, or to connect without authentication. On Windows NT, 2000 and XP systems, many local services run under the SYSTEM account, known as LocalSystem on Windows 2000 and XP. The SYSTEM account is used for various critical system operations. When one machine needs to retrieve system data from another, the SYSTEM account will open a null session to the other machine. For example: Network neighborhood. 23

24 W5 Anonymous Logon -- Null Sessions Operating Systems Affected Windows NT Windows 2000 Windows XP. 24

25 W6 LAN Manager Authentication Microsoft locally stores legacy LM password hashes (also known as LANMAN hashes) by default on Windows NT, 2000 and XP systems. The weakness of LM hashes derives from the following: Passwords are truncated to 14 characters. Passwords are padded with spaces to become 14 characters. Passwords are converted to all upper case characters. Passwords are split into two seven character pieces. 25

26 W6 LAN Manager Authentication Operating Systems Affected All Microsoft Windows operating systems. 26

27 W7 General Windows Authentication The most common password vulnerabilities are that: user accounts have weak or nonexistent passwords, regardless of the strength of their password, users fail to protect it, the operating system or additional software creates administrative accounts with weak or nonexistent passwords, and password hashing algorithms are known and often hashes are stored such that they are visible by anyone. 27

28 W7 General Windows Authentication Operating Systems Affected Any operating system or application where users authenticate via a user ID and password. 28

29 W8 Internet Explorer The vulnerabilities can be categorized into multiple classes including: Web page spoofing, ActiveX control vulnerabilities, Active scripting vulnerabilities, MIME-type and content-type type misinterpretation and Buffer overflows. The consequences may include: disclosure of cookies, local files or data, execution of local programs, download and execution of arbitrary code or complete takeover of the vulnerable system. 29

30 W8 Internet Explorer Operating Systems Affected These vulnerabilities exist on Microsoft Windows systems running any version of Microsoft Internet Explorer. 30

31 W9 Remote Registry Access Microsoft Windows 9x, Windows CE, Windows NT, Windows 2000, Windows ME and Windows XP employ a central hierarchical database, known as the Registry, to manage software, device configurations and user settings. Improper permissions or security settings can permit remote registry access. Attackers can exploit this feature to compromise the system or form the basis for adjusting file association and permissions to enable malicious code. 31

32 W9 Remote Registry Access Operating Systems Affected Windows 9x Windows CE Windows NT Windows 2000 Windows ME Windows XP 32

33 W10 Windows Scripting Host Windows Scripting Host (WSH), permits any text file with a ".vbs vbs" " extension to be executed as a Visual Basic script. With WSH enabled, a typical worm propagates by including a VBScript as the contents of another file and executes when that file is viewed or in some cases previewed. Example: The Love Bug (ILOVEYOU) worm. 33

34 W10 Windows Scripting Host Operating Systems Affected Windows Scripting Host can be installed manually or with Internet Explorer 5 (or higher) on Windows 95 or NT. It is installed by default on Windows 98, ME, 2000 and XP machines. 34

35 How to detect, prevent and correct these vulnerabilities 35

36 W1 Internet Information Services (IIS) How to determine if you are vulnerable. It is simplest to presume that you are vulnerable if the cumulative roll-up has not been applied. To determine whether the cumulative roll-up has been applied on your server, check the registry for the entry listed as follows: Windows NT 4: HKEY_LOCAL_MACHINE\SOFTWARE SOFTWARE\Microsoft\Windows NT\CurrentVersion CurrentVersion\Hotfix\Q

37 W1 Internet Information Services (IIS) or Windows NT 4 Terminal Server Edition: HKEY_LOCAL_MACHINE\SOFTWARE SOFTWARE\Microsoft\Windows NT\CurrentVersion CurrentVersion\Hotfix\Q Windows 2000: HKEY_LOCAL_MACHINE\SOFTWARE SOFTWARE\Microsoft\Updates\Window s 2000\SP3 SP3\Q Windows XP: HKEY_LOCAL_MACHINE\SOFTWARE SOFTWARE\Microsoft\Updates\Window s XP\SP1 SP1\Q

38 W1 Internet Information Services (IIS) Use the HFNetChk tool to verify the presence of the corresponding patch: NT 4: Q NT 4 Terminal Server Edition: Q or XP: Q

39 W1 Internet Information Services (IIS) You are probably vulnerable to sample application exploits if any of the following files reside in your %wwwroot%/scripts directory: code.asp codebrws.asp ism.dll newdsn.exe viewcode.asp winmsdp.exe 39

40 W1 Internet Information Services (IIS) How to Protect Against It. Apply the current patches. Stay current. Eliminate sample applications. Unmap necessary ISAPI extensions. Filter HTTP requests. Perform periodic vulnerability assessments of your Web servers. 40

41 W1 Internet Information Services (IIS) How to Protect Against It Tools. Network Security Hotfix Checker HFNetChk microsoft.com/.com/technet/security/tools/hfnetchk.asp IIS Lockdown Wizard microsoft.com/.com/technet/security/tools/locktool.asp URLScan filter (currently integrated in the IIS Lockdown Wizard). microsoft.com/.com/technet/security/tools/urlscan.asp 41

42 W2 Microsoft Data Access Components (MDAC) -- Remote Data Services How to determine if you are vulnerable. If you are running Microsoft Windows NT 4.0 and IIS 3.0 or 4.0, then check for the existence of "msadcs" msadcs.dll" 42

43 W2 Microsoft Data Access Components (MDAC) -- Remote Data Services How to Protect Against It. If possible, upgrade to MDAC version 2.1 or greater (this may introduce compatibility issues. microsoft.com/data/download..com/data/download.htm Install JetCopkg.exe (MS99-030) JetCopkg.exe is a modified Jet 3.5 engine that has safety features enabled in it to prevent exploitation, referred to as 'sandbox' mode. microsoft.com/default..com/default.aspx?scid=kb;en-us;q If MDAC is not needed, delete the msadcs.dll dll library. 43

44 W2 Microsoft Data Access Components (MDAC) -- Remote Data Services How to Protect Against It Additional references. You, your servers, RDS, and thousands of script kiddies..how to keep your website intact.. (Defending against RDS attacks). wiretrip.net/.net/rfp/p/doc.asp/i2/f3/d29.htm PRB: Security Implications of RDS 1.5, IIS 3.0 or 4.0, and ODBC. microsoft.com/default..com/default.aspx?scid=kb;en-us;q

45 W2 Microsoft Data Access Components (MDAC) -- Remote Data Services Unauthorized ODBC Data Access with RDS and IIS. microsoft.com/.com/technet/treeview/default.asp?url=/ =/technet/ security/bulletin/ms asp Re-Release: Release: Unauthorized Access to IIS Servers through ODBC Data Access with RDS. microsoft.com/.com/technet/treeview/default.asp?url=/ =/technet/ security/bulletin/ms asp 45

46 W3 Microsoft SQL Server How to determine if you are vulnerable. Check the registry for the following value: HKEY_LOCAL_MACHINE\SOFTWARE SOFTWARE\Microsoft\MSSQLServer\M SSQLServer If set, it means that SQL Server or SQL Server Desktop Engine is installed. Use the Microsoft Baseline Security Analizer (MBSA) to check for missing patches and hotfixes. microsoft.com/.com/technet/security/tools/tools/mbsahome.a sp 46

47 W3 Microsoft SQL Server How to Protect Against It. Apply the latest service pack for Microsoft SQL server. Apply the latest cumulative patch that is released after the latest service pack. Apply any individual patches that are released after the latest cumulative patch. Secure the server at system and network level. Perform periodic vulnerability assessments of your SQL servers. 47

48 W3 Microsoft SQL Server How to Protect Against It - Secure the server. Ensure that the built-in in "sa" sa" " account has a strong password, even if your SQL server does not run using this account. Run the MSSQLServer service and SQL Server Agent under a valid domain account with minimal privileges, not as a domain administrator or the SYSTEM (on NT) or LocalSystem (on 2000 or XP) account. 48

49 W3 Microsoft SQL Server Enable Windows NT Authentication. Enable auditing for successful and failed logins. Stop and restart the MSSQLServer service. Configure your clients to use NT authentication. Packet filtering should be performed at network borders to prohibit non-authorized externally-initiated inbound connections to services. Ingress filtering of TCP ports 1433 and 1434 could prevent attackers outside of your network from scanning or infecting vulnerable Microsoft SQL servers in the local network that are not explicitly authorized to provide public SQL services. 49

50 W3 Microsoft SQL Server If TCP ports 1433 and 1434 need to be available on your Internet gateways, enable and customize egress/ingress filtering to prevent misuse of these ports. 50

51 W4 NETBIOS -- Unprotected Windows Networking Shares How to determine if you are vulnerable. Use the Microsoft Baseline Security Analizer (MBSA) to check if the server is vulnerable to SMB exploits. microsoft.com/.com/technet/security/tools/tools/mbsahome.a sp Use any other available network scanner. Please, be advised that proper testing should be performed prior to start using unfamiliar tools in a production environment. 51

52 W4 NETBIOS -- Unprotected Windows Networking Shares How to Protect Against It. Disable sharing wherever it is not required. Do not permit sharing with hosts on the Internet. Ensure all Internet-facing hosts have Windows network shares disabled. Do not permit unauthenticated shares. If file sharing is required, then don't permit unauthenticated access to a share. 52

53 W4 NETBIOS -- Unprotected Windows Networking Shares Restrict shares to only the minimum folders required. Generally, only one folder and possibly sub-folders of that folder. Restrict permissions on shared folders to the minimum required. Be especially careful to only permit write access when it is absolutely required. For added security, allow sharing only to specific IP addresses because DNS names can be spoofed. 53

54 W4 NETBIOS -- Unprotected Windows Networking Shares Block ports used for Windows shares at your network perimeter. Block the NetBIOS ports commonly used by Windows shares at your network perimeter using either your external router or perimeter firewall. The ports that should be blocked are TCP and UDP, and 445 TCP and 445 UDP. 54

55 W5 Anonymous Logon -- Null Sessions How to determine if you are vulnerable. Try to establish a Null session using the following command: net use \\a.b.c.d\ipc$ $ /user: where a.b.c.d is the IP address of the remote system. 55

56 W5 Anonymous Logon -- Null Sessions How to Protect Against It. Modify the RestrictAnonymous Registry key HKLM/System/CurrentControlSet CurrentControlSet/Control/LSA/ /Control/LSA/RestrictAnonymous Restricts anonymous users from displaying lists of users and from viewing security permissions. Note: This setting may have a negative impact on domain controller operations. Test the setting BEFORE you apply it to a production network. 56

57 W5 Anonymous Logon -- Null Sessions Modify the RestrictAnonymous Registry key Available Settings: 0 (Disabled): Anonymous users are not restricted. 1 (Enabled): Users who log on anonymously (also known as null session connections) cannot display lists of domain user names or o share names. 2 (Enabled): Anonymous users have no access without explicit anonymous permissions. (only in W2K/ XP versions). Block TCP and UDP ports 135, 137, 138, 139 and 445 at the external router or firewall. 57

58 W6 LAN Manager Authentication How to determine if you are vulnerable. If you are running a default installation of NT, 2000 or XP, you are vulnerable since LAN Manager hashes are stored locally by default. If you have legacy operating systems in your environment that require LM authentication in order to communicate to servers, then you are vulnerable because those machines send LM hashes which can be sniffed off the network. 58

59 W6 LAN Manager Authentication How to Protect Against It. Disable LM Authentication across the network. Set the LMCompatibilityLevel Registry key (in HKLM/System\CurrentControlSet CurrentControlSet\Control\LSA) to: If all of your systems are Windows NT SP4 or later, you can set this to 3 on all clients and 5 on all domain controllers to prevent any a transmission of LM hashes on the network. Legacy systems (such as Windows 95/98) will not use NTLMv2 with the default Microsoft Network Client. To get NTLMv2 capability, install the Directory Services Client. Once installed, the registry value name is "LMCompatibility" LMCompatibility," and the allowed values are 0 or 3. 59

60 W6 LAN Manager Authentication Prevent the LM Hash from Being Stored. One major problem with simply removing the LM hashes being passed over the network is that the hashes are still created and stored in the SAM or Active Directory. Microsoft has a mechanism available for turning off the creation of the LM hashes altogether, but only in Windows 2000 and XP. Windows 2000: HKLM\System System\CurentControlSet\Control\LSA\NoLMHash Windows XP: HKLM\System System\CurentControlSet\Control\LSA (Value: NoLMHash,, Data type: REG_DWORD, Value: 1). 60

61 W6 LAN Manager Authentication How to Protect Against It additional references. How to Disable LM Authentication on Windows NT [Q147706] LMCompatibilityLevel and Its Effects [Q175641] microsoft.com/default..com/default.aspx?scid=kb%3ben- us%3b microsoft.com/default..com/default.aspx?scid=kb%3ben- us%3b

62 W6 LAN Manager Authentication How to Enable NTLMv2 Authentication for Windows 95/98/2000/NT [Q239869] New Registry Key to Remove LM Hashes from Active Directory and Security Account Manager microsoft.com/default..com/default.aspx?scid=kb%3ben- us%3b microsoft.com/default..com/default.aspx?scid=kb%3ben- us%3b

63 W7 General Windows Authentication How to determine if you are vulnerable. Test the passwords using a known password cracker. Note: Never run a password scanner, even on systems for which you have administrative access, without explicit and preferably written permission from your employer. Administrators with the most benevolent of intentions have been fired for running password cracking tools without authority to do so. 63

64 W7 General Windows Authentication How to Protect Against It. Ensure that passwords are strong. Protect strong passwords. Tightly control accounts. Maintain a strong password policy for the enterprise. 64

65 W7 General Windows Authentication How to Protect Against It Tools. LC4 (l0phtcrack version 4) atstake.com/research/.com/research/lc/ John the Ripper openwall.com/john/ Symantec NetRecon enterprisesecurity.symantec.com/products/products..com/products/products.cfm?prod uctid=46 65

66 W8 Internet Explorer How to determine if you are vulnerable. Make sure the latest service packs, hotfixes and patches are installed. This could be done by: Windows Update service Network Security Hotfix Checker (NFNetChk( NFNetChk) Microsoft Baseline Security Analyzer (MBSA) 66

67 W8 Internet Explorer How to Protect Against It. Apply the latest service pack for Internet Explorer. Apply the latest cumulative patch that is released after the latest service pack. Apply any individual patches that are released after the latest cumulative patch. 67

68 W9 Remote Registry Access How to determine if you are vulnerable. NT Resource Kit (NTRK) available from Microsoft contains an executable file entitled "regdump" regdump.exe" that will passively test remote registry access permissions from a Windows NT host against other Windows NT/Windows 2000 or Windows XP hosts on the Internet or internal network. msdn.microsoft.com/library/default.asp?.com/library/default.asp?url=/library/en- us/apcguide apcguide/htm/utilities_10.asp A collection of command line shell scripts that will test for registry access permissions and a range of other related security concerns. afentis.com/top20 68

69 W9 Remote Registry Access How to Protect Against It. Restrict Network Access. To restrict network access to the registry create the following Registry key: HKEY_LOCAL_MACHINE\SYSTEM SYSTEM\CurrentControlSet\Control\SecurePipeServ ers\winreg Description: REG_SZ Value: Registry Server Security permissions set on this key define the Users or Groups that are permitted remote Registry access. Default Windows installations define this key and set the Access Control List to provide full privileges to the system Administrator and Administrators Group (and Backup Operators in Windows 2000). 69

70 W9 Remote Registry Access Limit the authorized remote access. Enforcing strict restrictions upon the registry can have adverse side effects upon dependent services, such as the Directory Replicator and the network printer Spooler service. It is therefore possible to add a degree of granularity to the permissions, by adding either the account name that the service is running under to the access list of the "winreg" winreg" " key, or by configuring Windows to bypass the access restriction to certain keys by listing them in the Machine or Users value under the AllowedPaths key. 70

71 W9 Remote Registry Access For Windows NT: HKEY_LOCAL_MACHINE\SYSTEM SYSTEM\CurrentControlSet\Control\Secure PipeServers\winreg winreg\allowedpaths Value: Machine Value Type: REG_MULTI_SZ - Multi string Default Data: System\CurrentControlSet CurrentControlSet\Control\ProductOptions System\CurrentControlSet CurrentControlSet\Control\Print\Printers Printers System\CurrentControlSet CurrentControlSet\Services\Eventlog Software\Microsoft Microsoft\WindowsNT\CurrentVersion System\CurrentControlSet CurrentControlSet\Services\Replicator Valid Range: (A valid path to a location in the registry) Description: Allow machines access to listed locations in the registry provided that no explicit access restrictions exist for that location. 71

72 W9 Remote Registry Access Value: Users Value Type: REG_MULTI_SZ - Multi string Default Data: (none) Valid Range: (A valid path to a location in the registry) Description: Allow users access to listed locations in the registry provided that no explicit access restrictions exist for that location. 72

73 W9 Remote Registry Access In the Microsoft Windows 2000 and Windows XP Registry: Value: Machine Value Type: REG_MULTI_SZ - Multi string Default Data: System\CurrentControlSet CurrentControlSet\Control\ProductOptions System\CurrentControlSet CurrentControlSet\Control\Print\Printers Printers System\CurrentControlSet CurrentControlSet\control\Server Application System\CurrentControlSet CurrentControlSet\Services\Eventlog\ Software\Microsoft Microsoft\Windows NT\CurrentVersion Value: Users (does not exist by default) 73

74 W9 Remote Registry Access How to Protect Against It additional references. How to Restrict Access to NT Registry from a Remote Computer. microsoft.com/default..com/default.aspx?scid=kb%3ben- us%3b

75 W10 Windows Scripting Host (WSH) How to determine if you are vulnerable. If you are running Windows 95 or NT with IE 5 or higher, or are running Windows 98, ME, 2000 or XP, and have not disabled WSH, then you are vulnerable. 75

76 W10 Windows Scripting Host (WSH) How to Protect Against It. Disable or remove Windows Scripting Host. Always keep the Anti-virus software and definitions up-to to- date. 76

77 How to assess your level of exposure 77

78 78

79 Conclusions Most of these vulnerabilities have been know for a number of years. Most of the countermeasures are not hard to deploy. Still there are the most exploited vulnerabilities. 79

80 emrisk.com/ 80

81 Silka M. Gonzalez CISA, CPA President emrisk.com or Donald R. Glass CISSP, CISA, MCSE, MCSE+I, CNE Manager emrisk.com

82 This document was created with Win2PDF available at The unregistered version of Win2PDF is for evaluation or non-commercial use only.

www.fbi.gov www.nipc.gov www.sans.org

www.fbi.gov www.nipc.gov www.sans.org The Twenty Most Critical Internet Security Vulnerabilities (Updated) ~ The Experts Consensus Version 3.21 October 17, 2002 Copyright 2001-2002, The SANS Institute Questions / comments may be directed to

More information

The Twenty Most Critical Internet Security Vulnerabilities (Updated) ~ The Experts Consensus

The Twenty Most Critical Internet Security Vulnerabilities (Updated) ~ The Experts Consensus The Twenty Most Critical Internet Security Vulnerabilities (Updated) ~ The Experts Consensus Version 4.0 October 8, 2003 Copyright (C) 2001-2003, SANS Institute Questions / comments may be directed to

More information

Web Application Threats and Vulnerabilities Web Server Hacking and Web Application Vulnerability

Web Application Threats and Vulnerabilities Web Server Hacking and Web Application Vulnerability Web Application Threats and Vulnerabilities Web Server Hacking and Web Application Vulnerability WWW Based upon HTTP and HTML Runs in TCP s application layer Runs on top of the Internet Used to exchange

More information

INNOV-04 The SANS Top 20 Internet Security Vulnerabilities

INNOV-04 The SANS Top 20 Internet Security Vulnerabilities INNOV-04 The SANS Top 20 Internet Security Vulnerabilities (and what it means to OpenEdge Applications) Michael Solomon, CISSP PMP CISM Solomon Consulting Inc. www.solomonconsulting.com (Thanks to John

More information

Five Steps to Improve Internal Network Security. Chattanooga ISSA

Five Steps to Improve Internal Network Security. Chattanooga ISSA Five Steps to Improve Internal Network Security Chattanooga ISSA 1 Find Me AverageSecurityGuy.info @averagesecguy stephen@averagesecurityguy.info github.com/averagesecurityguy ChattSec.org 2 Why? The methodical

More information

Microsoft Security Bulletin MS09-064 - Critical

Microsoft Security Bulletin MS09-064 - Critical Microsoft Security Bulletin MS09-064 - Critical: Vulnerability in License Logging Se... Page 1 of 11 TechNet Home > TechNet Security > Bulletins Microsoft Security Bulletin MS09-064 - Critical Vulnerability

More information

Nessus scanning on Windows Domain

Nessus scanning on Windows Domain Nessus scanning on Windows Domain A little inside information and Nessus can go a long way By Sunil Vakharia sunilv@phreaker.net Version 1.0 4 November 2003 About this paper This paper is not a tutorial

More information

1 hours, 30 minutes, 38 seconds Heavy scan. All scanned network resources. Copyright 2001, FTP access obtained

1 hours, 30 minutes, 38 seconds Heavy scan. All scanned network resources. Copyright 2001, FTP access obtained home Network Vulnerabilities Detail Report Grouped by Vulnerability Report Generated by: Symantec NetRecon 3.5 Licensed to: X Serial Number: 0182037567 Machine Scanned from: ZEUS (192.168.1.100) Scan Date:

More information

Using Microsoft s Free Security Tools Help Secure your Windows Systems taken from Web and Other Sources by Thomas Jerry Scott November, 2003

Using Microsoft s Free Security Tools Help Secure your Windows Systems taken from Web and Other Sources by Thomas Jerry Scott November, 2003 Using Microsoft s Free Security Tools Help Secure your Windows Systems taken from Web and Other Sources by Thomas Jerry Scott November, 2003 The following chart shows the name and download locations for

More information

SECURITY BEST PRACTICES FOR CISCO PERSONAL ASSISTANT (1.4X)

SECURITY BEST PRACTICES FOR CISCO PERSONAL ASSISTANT (1.4X) WHITE PAPER SECURITY BEST PRACTICES FOR CISCO PERSONAL ASSISTANT (1.4X) INTRODUCTION This document covers the recommended best practices for hardening a Cisco Personal Assistant 1.4(x) server. The term

More information

A Roadmap for Securing IIS 5.0

A Roadmap for Securing IIS 5.0 This document was grafted together from various Web and other sources by Thomas Jerry Scott for use in his Web and other Security courses. Jerry hopes you find this information helpful in your quest to

More information

Medical Device Security Health Imaging Digital Capture. Security Assessment Report for the Kodak Capture Link Server V1.00

Medical Device Security Health Imaging Digital Capture. Security Assessment Report for the Kodak Capture Link Server V1.00 Medical Device Security Health Imaging Digital Capture Security Assessment Report for the Kodak Capture Link Server V1.00 Version 1.0 Eastman Kodak Company, Health Imaging Group Page 1 Table of Contents

More information

Windows Remote Access

Windows Remote Access Windows Remote Access A newsletter for IT Professionals Education Sector Updates Issue 1 I. Background of Remote Desktop for Windows Remote Desktop Protocol (RDP) is a proprietary protocol developed by

More information

Hands-On Ethical Hacking and Network Defense Second Edition Chapter 8 Desktop and Server OS Vulnerabilities

Hands-On Ethical Hacking and Network Defense Second Edition Chapter 8 Desktop and Server OS Vulnerabilities Objectives After reading this chapter and completing the exercises, you will be able to: Describe vulnerabilities of Windows and Linux operating systems Identify specific vulnerabilities and explain ways

More information

Windows Operating Systems. Basic Security

Windows Operating Systems. Basic Security Windows Operating Systems Basic Security Objectives Explain Windows Operating System (OS) common configurations Recognize OS related threats Apply major steps in securing the OS Windows Operating System

More information

SQL Server Hardening

SQL Server Hardening Considerations, page 1 SQL Server 2008 R2 Security Considerations, page 4 Considerations Top SQL Hardening Considerations Top SQL Hardening considerations: 1 Do not install SQL Server on an Active Directory

More information

Penetration Testing Report Client: Business Solutions June 15 th 2015

Penetration Testing Report Client: Business Solutions June 15 th 2015 Penetration Testing Report Client: Business Solutions June 15 th 2015 Acumen Innovations 80 S.W 8 th St Suite 2000 Miami, FL 33130 United States of America Tel: 1-888-995-7803 Email: info@acumen-innovations.com

More information

GFI White Paper PCI-DSS compliance and GFI Software products

GFI White Paper PCI-DSS compliance and GFI Software products White Paper PCI-DSS compliance and Software products The Payment Card Industry Data Standard () compliance is a set of specific security standards developed by the payment brands* to help promote the adoption

More information

Microsoft Baseline Security Analyzer

Microsoft Baseline Security Analyzer The (MBSA) checks computers running Microsoft Windows Server 2008 R2 for common security misconfigurations. The following are the scanning options selected for Cisco Unified ICM Real-Time Distributor running

More information

Medical Device Security Health Imaging Digital Capture. Security Assessment Report for the Kodak DryView 8150 Imager Release 1.0.

Medical Device Security Health Imaging Digital Capture. Security Assessment Report for the Kodak DryView 8150 Imager Release 1.0. Medical Device Security Health Imaging Digital Capture Security Assessment Report for the Kodak DryView 8150 Imager Release 1.0 Page 1 of 9 Table of Contents Table of Contents... 2 Executive Summary...

More information

Overview of Network Security The need for network security Desirable security properties Common vulnerabilities Security policy designs

Overview of Network Security The need for network security Desirable security properties Common vulnerabilities Security policy designs Overview of Network Security The need for network security Desirable security properties Common vulnerabilities Security policy designs Why Network Security? Keep the bad guys out. (1) Closed networks

More information

Sitefinity Security and Best Practices

Sitefinity Security and Best Practices Sitefinity Security and Best Practices Table of Contents Overview The Ten Most Critical Web Application Security Risks Injection Cross-Site-Scripting (XSS) Broken Authentication and Session Management

More information

Web App Security Audit Services

Web App Security Audit Services locuz.com Professional Services Web App Security Audit Services The unsecured world today Today, over 80% of attacks against a company s network come at the Application Layer not the Network or System

More information

Security Maintenance Practices. IT 4823 Information Security Administration. Patches, Fixes, and Revisions. Hardening Operating Systems

Security Maintenance Practices. IT 4823 Information Security Administration. Patches, Fixes, and Revisions. Hardening Operating Systems IT 4823 Information Security Administration Securing Operating Systems June 18 Security Maintenance Practices Basic proactive security can prevent many problems Maintenance involves creating a strategy

More information

KB303215 - Microsoft Network Security Hotfix Checker (Hfnetchk.exe) Tool Is Available

KB303215 - Microsoft Network Security Hotfix Checker (Hfnetchk.exe) Tool Is Available Page 1 of 8 Knowledge Base Microsoft Network Security Hotfix Checker (Hfnetchk.exe) Tool Is Available PSS ID Number: 303215 Article Last Modified on 3/2/2004 The information in this article applies to:

More information

Database Auditing: Best Practices. Rob Barnes, CISA Director of Security, Risk and Compliance Operations rbarnes@appsecinc.com

Database Auditing: Best Practices. Rob Barnes, CISA Director of Security, Risk and Compliance Operations rbarnes@appsecinc.com Database Auditing: Best Practices Rob Barnes, CISA Director of Security, Risk and Compliance Operations rbarnes@appsecinc.com Verizon 2009 Data Breach Investigations Report: 285 million records were compromised

More information

Microsoft Security Bulletin MS09-053 - Important

Microsoft Security Bulletin MS09-053 - Important Microsoft Security Bulletin MS09-053 - : Vulnerabilities in FTP Service for...page 1 of 28 TechNet Home > TechNet Security > Bulletins Microsoft Security Bulletin MS09-053 - Vulnerabilities in FTP Service

More information

Cyberspace Security Issues and Challenges

Cyberspace Security Issues and Challenges Cyberspace Security Issues and Challenges Manu Malek, Ph.D. Department of Computer Science Stevens Institute of Technology mmalek@stevens.edu MSU Seminar, 10/06/03 M. Malek 1 Outline Security status Security

More information

6WRUP:DWFK. Policies for Dedicated SQL Servers Group

6WRUP:DWFK. Policies for Dedicated SQL Servers Group OKENA 71 Second Ave., 3 rd Floor Waltham, MA 02451 Phone 781 209 3200 Fax 781 209 3199 6WRUP:DWFK Policies for Dedicated SQL Servers Group The sample policies shipped with StormWatch address both application-specific

More information

Thick Client Application Security

Thick Client Application Security Thick Client Application Security Arindam Mandal (arindam.mandal@paladion.net) (http://www.paladion.net) January 2005 This paper discusses the critical vulnerabilities and corresponding risks in a two

More information

Medical Device Security Health Imaging Digital Capture. Security Assessment Report for the Kodak CR V4.1

Medical Device Security Health Imaging Digital Capture. Security Assessment Report for the Kodak CR V4.1 Medical Device Security Health Imaging Digital Capture Security Assessment Report for the Kodak CR V4.1 Version 1.0 Eastman Kodak Company, Health Imaging Group Page 1 Table of Contents Table of Contents

More information

Before deploying SiteAudit it is recommended to review the information below. This will ensure efficient installation and operation of SiteAudit.

Before deploying SiteAudit it is recommended to review the information below. This will ensure efficient installation and operation of SiteAudit. SiteAudit Knowledge Base Deployment Check List June 2012 In This Article: Platform Requirements Windows Settings Discovery Configuration Before deploying SiteAudit it is recommended to review the information

More information

INTERNATIONAL JOURNAL OF COMPUTER ENGINEERING & TECHNOLOGY (IJCET)

INTERNATIONAL JOURNAL OF COMPUTER ENGINEERING & TECHNOLOGY (IJCET) INTERNATIONAL JOURNAL OF COMPUTER ENGINEERING & TECHNOLOGY (IJCET) International Journal of Computer Engineering and Technology (IJCET), ISSN 0976 ISSN 0976 6367(Print) ISSN 0976 6375(Online) Volume 3,

More information

Integrated Network Vulnerability Scanning & Penetration Testing SAINTcorporation.com

Integrated Network Vulnerability Scanning & Penetration Testing SAINTcorporation.com SAINT Integrated Network Vulnerability Scanning and Penetration Testing www.saintcorporation.com Introduction While network vulnerability scanning is an important tool in proactive network security, penetration

More information

Last Updated: July 2011. STATISTICA Enterprise Server Security

Last Updated: July 2011. STATISTICA Enterprise Server Security Last Updated: July 2011 STATISTICA Enterprise Server Security STATISTICA Enterprise Server Security Page 2 of 10 Table of Contents Executive Summary... 3 Introduction to STATISTICA Enterprise Server...

More information

Potential Targets - Field Devices

Potential Targets - Field Devices Potential Targets - Field Devices Motorola Field Devices: Remote Terminal Units ACE 3600 Front End Devices ACE IP Gateway ACE Field Interface Unit (ACE FIU) 2 Credential Cracking Repeated attempts to

More information

IT HEALTHCHECK TOP TIPS WHITEPAPER

IT HEALTHCHECK TOP TIPS WHITEPAPER WHITEPAPER PREPARED BY MTI TECHNOLOGY LTD w: mti.com t: 01483 520200 f: 01483 520222 MTI Technology have been specifying and conducting IT Healthcheck s across numerous sectors including commercial, public

More information

Medical Device Security Health Imaging Digital Capture. Security Assessment Report for the Kodak DR V2.0

Medical Device Security Health Imaging Digital Capture. Security Assessment Report for the Kodak DR V2.0 Medical Device Security Health Imaging Digital Capture Security Assessment Report for the Kodak DR V2.0 Version 1.0 Eastman Kodak Company, Health Imaging Group Page 1 Table of Contents Table of Contents

More information

NCIRC Security Tools NIAPC Submission Summary Microsoft Baseline Security Analyzer (MBSA)

NCIRC Security Tools NIAPC Submission Summary Microsoft Baseline Security Analyzer (MBSA) NCIRC Security Tools NIAPC Submission Summary Microsoft Baseline Security Analyzer (MBSA) Document Reference: Security Tools Internal NIAPC Submission NIAPC Category: Operating System Security Management

More information

Microsoft Software Update Services and Managed Symantec Anti-virus. Michael Satut TSS/Crown IT Support m-satut@northwestern.edu

Microsoft Software Update Services and Managed Symantec Anti-virus. Michael Satut TSS/Crown IT Support m-satut@northwestern.edu Microsoft Software Update Services and Managed Symantec Anti-virus Michael Satut TSS/Crown IT Support m-satut@northwestern.edu Introduction The recent increase in virus and worm activity has created the

More information

Network and Host-based Vulnerability Assessment

Network and Host-based Vulnerability Assessment Network and Host-based Vulnerability Assessment A guide for information systems and network security professionals 6600 Peachtree-Dunwoody Road 300 Embassy Row Atlanta, GA 30348 Tel: 678.443.6000 Toll-free:

More information

The Trivial Cisco IP Phones Compromise

The Trivial Cisco IP Phones Compromise Security analysis of the implications of deploying Cisco Systems SIP-based IP Phones model 7960 Ofir Arkin Founder The Sys-Security Group ofir@sys-security.com http://www.sys-security.com September 2002

More information

3. Broken Account and Session Management. 4. Cross-Site Scripting (XSS) Flaws. Web browsers execute code sent from websites. Account Management

3. Broken Account and Session Management. 4. Cross-Site Scripting (XSS) Flaws. Web browsers execute code sent from websites. Account Management What is an? s Ten Most Critical Web Application Security Vulnerabilities Anthony LAI, CISSP, CISA Chapter Leader (Hong Kong) anthonylai@owasp.org Open Web Application Security Project http://www.owasp.org

More information

Five Steps to Improve Internal Network Security. Chattanooga Information security Professionals

Five Steps to Improve Internal Network Security. Chattanooga Information security Professionals Five Steps to Improve Internal Network Security Chattanooga Information security Professionals Who Am I? Security Analyst: Sword & Shield Blogger: averagesecurityguy.info Developer: github.com/averagesecurityguy

More information

HoneyBOT User Guide A Windows based honeypot solution

HoneyBOT User Guide A Windows based honeypot solution HoneyBOT User Guide A Windows based honeypot solution Visit our website at http://www.atomicsoftwaresolutions.com/ Table of Contents What is a Honeypot?...2 How HoneyBOT Works...2 Secure the HoneyBOT Computer...3

More information

Windows IIS Server hardening checklist

Windows IIS Server hardening checklist General Windows IIS Server hardening checklist By Michael Cobb Do not connect an IIS Server to the Internet until it is fully hardened. Place the server in a physically secure location. Do not install

More information

6WRUP:DWFK. Policies for Dedicated IIS Web Servers Group. V2.1 policy module to restrict ALL network access

6WRUP:DWFK. Policies for Dedicated IIS Web Servers Group. V2.1 policy module to restrict ALL network access OKENA 71 Second Ave., 3 rd Floor Waltham, MA 02451 Phone 781 209 3200 Fax 781 209 3199 6WRUP:DWFK Policies for Dedicated IIS Web Servers Group The policies shipped with StormWatch address both application-specific

More information

About Microsoft Windows Server 2003

About Microsoft Windows Server 2003 About Microsoft Windows Server 003 Windows Server 003 (WinK3) requires extensive provisioning to meet both industry best practices and regulatory compliance. By default the Windows Server operating system

More information

System Administration Training Guide. S100 Installation and Site Management

System Administration Training Guide. S100 Installation and Site Management System Administration Training Guide S100 Installation and Site Management Table of contents System Requirements for Acumatica ERP 4.2... 5 Learning Objects:... 5 Web Browser... 5 Server Software... 5

More information

Burst Technology bt-loganalyzer SE

Burst Technology bt-loganalyzer SE Burst Technology bt-loganalyzer SE Burst Technology Inc. 9240 Bonita Beach Rd, Bonita Springs, FL 34135 CONTENTS WELCOME... 3 1 SOFTWARE AND HARDWARE REQUIREMENTS... 3 2 SQL DESIGN... 3 3 INSTALLING BT-LOGANALYZER...

More information

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard Payment Card Industry (PCI) Data Security Standard Security Scanning Procedures Version 1.1 Release: September 2006 Table of Contents Purpose...1 Introduction...1 Scope of PCI Security Scanning...1 Scanning

More information

31 Ways To Make Your Computer System More Secure

31 Ways To Make Your Computer System More Secure 31 Ways To Make Your Computer System More Secure Copyright 2001 Denver Tax Software, Inc. 1. Move to more secure Microsoft Windows systems. Windows NT, 2000 and XP can be made more secure than Windows

More information

Hack Your SQL Server Database Before the Hackers Do

Hack Your SQL Server Database Before the Hackers Do Note: This article was edited in Oct. 2013, from numerous Web Sources. TJS At the Install: The default install for SQL server makes it is as secure as it will ever be. DBAs and developers will eventually

More information

REPORT ON AUDIT OF LOCAL AREA NETWORK OF C-STAR LAB

REPORT ON AUDIT OF LOCAL AREA NETWORK OF C-STAR LAB REPORT ON AUDIT OF LOCAL AREA NETWORK OF C-STAR LAB Conducted: 29 th March 5 th April 2007 Prepared By: Pankaj Kohli (200607011) Chandan Kumar (200607003) Aamil Farooq (200505001) Network Audit Table of

More information

My FreeScan Vulnerabilities Report

My FreeScan Vulnerabilities Report Page 1 of 6 My FreeScan Vulnerabilities Report Print Help For 66.40.6.179 on Feb 07, 008 Thank you for trying FreeScan. Below you'll find the complete results of your scan, including whether or not the

More information

GFI LANguard Network Security Scanner 3.3. Manual. By GFI Software Ltd.

GFI LANguard Network Security Scanner 3.3. Manual. By GFI Software Ltd. GFI LANguard Network Security Scanner 3.3 Manual By GFI Software Ltd. GFI SOFTWARE Ltd. http://www.gfi.com E-mail: info@gfi.com Information in this document is subject to change without notice. Companies,

More information

Remote Administration

Remote Administration Windows Remote Desktop, page 1 pcanywhere, page 3 VNC, page 7 Windows Remote Desktop Remote Desktop permits users to remotely execute applications on Windows Server 2008 R2 from a range of devices over

More information

Threat Modeling. Deepak Manohar

Threat Modeling. Deepak Manohar Threat Modeling Deepak Manohar Outline Motivation Past Security Approaches Common problems with past security approaches Adversary s perspective Vs Defender s perspective Why defender s perspective? Threat

More information

WhatsUp Gold v16.3 Installation and Configuration Guide

WhatsUp Gold v16.3 Installation and Configuration Guide WhatsUp Gold v16.3 Installation and Configuration Guide Contents Installing and Configuring WhatsUp Gold using WhatsUp Setup Installation Overview... 1 Overview... 1 Security considerations... 2 Standard

More information

Hardening IIS Servers

Hardening IIS Servers 8 Hardening IIS Servers Overview This chapter focuses on the guidance and procedures required to harden the IIS servers in your environment. To provide comprehensive security for Web servers and applications

More information

Protecting Your Organisation from Targeted Cyber Intrusion

Protecting Your Organisation from Targeted Cyber Intrusion Protecting Your Organisation from Targeted Cyber Intrusion How the 35 mitigations against targeted cyber intrusion published by Defence Signals Directorate can be implemented on the Microsoft technology

More information

Web Security School Entrance Exam

Web Security School Entrance Exam Web Security School Entrance Exam By Michael Cobb 1) What is SSL used for? a. Encrypt data as it travels over a network b. Encrypt files located on a Web server c. Encrypt passwords for storage in a database

More information

by New Media Solutions 37 Walnut Street Wellesley, MA 02481 p 781-235-0128 f 781-235-9408 www.avitage.com Avitage IT Infrastructure Security Document

by New Media Solutions 37 Walnut Street Wellesley, MA 02481 p 781-235-0128 f 781-235-9408 www.avitage.com Avitage IT Infrastructure Security Document Avitage IT Infrastructure Security Document The purpose of this document is to detail the IT infrastructure security policies that are in place for the software and services that are hosted by Avitage.

More information

The Ten Most Important Steps You Can Take to Protect Your Windows-based Servers from Hackers

The Ten Most Important Steps You Can Take to Protect Your Windows-based Servers from Hackers The Ten Most Important Steps You Can Take to Protect Your Windows-based Servers from Hackers University of California, Riverside Computing and Communications Author: Joel Nylander Document Goal This document

More information

Networking Best Practices Guide. Version 6.5

Networking Best Practices Guide. Version 6.5 Networking Best Practices Guide Version 6.5 Summer 2010 Copyright: 2010, CCH, a Wolters Kluwer business. All rights reserved. Material in this publication may not be reproduced or transmitted in any form

More information

Step-by-Step Guide to Securing Windows XP Professional with Service Pack 2 in Small and Medium Businesses

Step-by-Step Guide to Securing Windows XP Professional with Service Pack 2 in Small and Medium Businesses Step-by-Step Guide to Securing Windows XP Professional with Service Pack 2 in Small and Medium Businesses 2004 Microsoft Corporation. All rights reserved. This document is for informational purposes only.

More information

ms-help://ms.technet.2005mar.1033/security/tnoffline/security/smbiz/winxp/fwgrppol...

ms-help://ms.technet.2005mar.1033/security/tnoffline/security/smbiz/winxp/fwgrppol... Page 1 of 16 Security How to Configure Windows Firewall in a Small Business Environment using Group Policy Introduction This document explains how to configure the features of Windows Firewall on computers

More information

If you know the enemy and know yourself, you need not fear the result of a hundred battles.

If you know the enemy and know yourself, you need not fear the result of a hundred battles. Rui Pereira,B.Sc.(Hons),CIPS ISP/ITCP,CISSP,CISA,CWNA/CWSP,CPTE/CPTC Principal Consultant, WaveFront Consulting Group ruiper@wavefrontcg.com 1 (604) 961-0701 If you know the enemy and know yourself, you

More information

Release Notes for Websense Email Security v7.2

Release Notes for Websense Email Security v7.2 Release Notes for Websense Email Security v7.2 Websense Email Security version 7.2 is a feature release that includes support for Windows Server 2008 as well as support for Microsoft SQL Server 2008. Version

More information

Microsoft Baseline Security Analyzer (MBSA)

Microsoft Baseline Security Analyzer (MBSA) Microsoft Baseline Security Analyzer Microsoft Baseline Security Analyzer (MBSA) is a software tool released by Microsoft to determine security state by assessing missing security updates and lesssecure

More information

Vulnerability Assessment and Penetration Testing

Vulnerability Assessment and Penetration Testing Vulnerability Assessment and Penetration Testing Module 1: Vulnerability Assessment & Penetration Testing: Introduction 1.1 Brief Introduction of Linux 1.2 About Vulnerability Assessment and Penetration

More information

Hosts HARDENING WINDOWS NETWORKS TRAINING

Hosts HARDENING WINDOWS NETWORKS TRAINING BROADVIEW NETWORKS Hosts HARDENING WINDOWS NETWORKS TRAINING COURSE OVERVIEW A hands-on security course that teaches students how to harden, monitor and protect Microsoft Windows based networks. A hardening

More information

Locking down a Hitachi ID Suite server

Locking down a Hitachi ID Suite server Locking down a Hitachi ID Suite server 2016 Hitachi ID Systems, Inc. All rights reserved. Organizations deploying Hitachi ID Identity and Access Management Suite need to understand how to secure its runtime

More information

VULNERABILITY ASSESSMENT WHITEPAPER INTRODUCTION, IMPLEMENTATION AND TECHNOLOGY DISCUSSION

VULNERABILITY ASSESSMENT WHITEPAPER INTRODUCTION, IMPLEMENTATION AND TECHNOLOGY DISCUSSION VULNERABILITY ASSESSMENT WHITEPAPER INTRODUCTION, IMPLEMENTATION AND TECHNOLOGY DISCUSSION copyright 2003 securitymetrics Security Vulnerabilities of Computers & Servers Security Risks Change Daily New

More information

Windows Security. Introduction. Topics. Loughborough University. Janet Web Cache Service. Matthew Cook http://escarpment.net/

Windows Security. Introduction. Topics. Loughborough University. Janet Web Cache Service. Matthew Cook http://escarpment.net/ Windows Security Matthew Cook http://escarpment.net/ Introduction Loughborough University http://www.lboro.ac.uk/computing/ Janet Web Cache Service http://wwwcache.ja.net/ Bandwidth Management Advisory

More information

Web Plus Security Features and Recommendations

Web Plus Security Features and Recommendations Web Plus Security Features and Recommendations (Based on Web Plus Version 3.x) Centers for Disease Control and Prevention National Center for Chronic Disease Prevention and Health Promotion Division of

More information

Windows Attack - Gain Enterprise Admin Privileges in 5 Minutes

Windows Attack - Gain Enterprise Admin Privileges in 5 Minutes Windows Attack - Gain Enterprise Admin Privileges in 5 Minutes Compass Security AG, Daniel Stirnimann Compass Security AG Glärnischstrasse 7 Postfach 1628 CH-8640 Rapperswil Tel +41 55-214 41 60 Fax +41

More information

Web Security School Final Exam

Web Security School Final Exam Web Security School Final Exam By Michael Cobb 1.) Which of the following services is not required to run a Windows server solely configured to run IIS and publish a Web site on the Internet? a. IIS Admin

More information

SQL Server Hardening

SQL Server Hardening Considerations, page 1 SQL Server 2008 R2 Security Considerations, page 4 Considerations Top SQL Hardening Considerations Top SQL Hardening considerations: 1 Do not install SQL Server on an Active Directory

More information

G/On. Basic Best Practice Reference Guide Version 6. For Public Use. Make Connectivity Easy

G/On. Basic Best Practice Reference Guide Version 6. For Public Use. Make Connectivity Easy For Public Use G/On Basic Best Practice Reference Guide Version 6 Make Connectivity Easy 2006 Giritech A/S. 1 G/On Basic Best Practices Reference Guide v.6 Table of Contents Scope...3 G/On Server Platform

More information

FREQUENTLY ASKED QUESTIONS

FREQUENTLY ASKED QUESTIONS FREQUENTLY ASKED QUESTIONS Secure Bytes, October 2011 This document is confidential and for the use of a Secure Bytes client only. The information contained herein is the property of Secure Bytes and may

More information

Directory and File Transfer Services. Chapter 7

Directory and File Transfer Services. Chapter 7 Directory and File Transfer Services Chapter 7 Learning Objectives Explain benefits offered by centralized enterprise directory services such as LDAP over traditional authentication systems Identify major

More information

enicq 5 System Administrator s Guide

enicq 5 System Administrator s Guide Vermont Oxford Network enicq 5 Documentation enicq 5 System Administrator s Guide Release 2.0 Published November 2014 2014 Vermont Oxford Network. All Rights Reserved. enicq 5 System Administrator s Guide

More information

Securing Active Directory Correctly

Securing Active Directory Correctly SESSION ID: TECH-F02 Securing Active Directory Correctly Derek Melber, MVP Technical Evangelist ManageEngine @derekmelber About Your Speaker Derek Melber, MCSE & MVP (Group Policy and AD) derek@manageengine.com

More information

Contents Introduction xxvi Chapter 1: Understanding the Threats: E-mail Viruses, Trojans, Mail Bombers, Worms, and Illicit Servers

Contents Introduction xxvi Chapter 1: Understanding the Threats: E-mail Viruses, Trojans, Mail Bombers, Worms, and Illicit Servers Contents Introduction xxvi Chapter 1: Understanding the Threats: E-mail Viruses, Trojans, Mail Bombers, Worms, and Illicit Servers 1 Introduction 2 Essential Concepts 3 Servers, Services, and Clients 3

More information

E-commerce. Security. Learning objectives. Internet Security Issues: Overview. Managing Risk-1. Managing Risk-2. Computer Security Classifications

E-commerce. Security. Learning objectives. Internet Security Issues: Overview. Managing Risk-1. Managing Risk-2. Computer Security Classifications Learning objectives E-commerce Security Threats and Protection Mechanisms. This lecture covers internet security issues and discusses their impact on an e-commerce. Nov 19, 2004 www.dcs.bbk.ac.uk/~gmagoulas/teaching.html

More information

Adjusting Prevention Policy Options Based on Prevention Events. Version 1.0 July 2006

Adjusting Prevention Policy Options Based on Prevention Events. Version 1.0 July 2006 Adjusting Prevention Policy Options Based on Prevention Events Version 1.0 July 2006 Table of Contents 1. WHO SHOULD READ THIS DOCUMENT... 4 2. WHERE TO GET MORE INFORMATION... 4 3. VERIFYING THE OPERATION

More information

System Management. What are my options for deploying System Management on remote computers?

System Management. What are my options for deploying System Management on remote computers? Getting Started, page 1 Managing Assets, page 2 Distributing Software, page 3 Distributing Patches, page 4 Backing Up Assets, page 5 Using Virus Protection, page 6 Security, page 7 Getting Started What

More information

Professional Penetration Testing Techniques and Vulnerability Assessment ...

Professional Penetration Testing Techniques and Vulnerability Assessment ... Course Introduction Today Hackers are everywhere, if your corporate system connects to internet that means your system might be facing with hacker. This five days course Professional Vulnerability Assessment

More information

Penetration Testing with Kali Linux

Penetration Testing with Kali Linux Penetration Testing with Kali Linux PWK Copyright 2014 Offensive Security Ltd. All rights reserved. Page 1 of 11 All rights reserved to Offensive Security, 2014 No part of this publication, in whole or

More information

Secure Web Application Coding Team Introductory Meeting December 1, 2005 1:00 2:00PM Bits & Pieces Room, Sansom West Room 306 Agenda

Secure Web Application Coding Team Introductory Meeting December 1, 2005 1:00 2:00PM Bits & Pieces Room, Sansom West Room 306 Agenda Secure Web Application Coding Team Introductory Meeting December 1, 2005 1:00 2:00PM Bits & Pieces Room, Sansom West Room 306 Agenda 1. Introductions for new members (5 minutes) 2. Name of group 3. Current

More information

Computer Networks & Computer Security

Computer Networks & Computer Security Computer Networks & Computer Security Software Engineering 4C03 Project Report Hackers: Detection and Prevention Prof.: Dr. Kartik Krishnan Due Date: March 29 th, 2004 Modified: April 7 th, 2004 Std Name:

More information

ITEC441- IS Security. Chapter 15 Performing a Penetration Test

ITEC441- IS Security. Chapter 15 Performing a Penetration Test 1 ITEC441- IS Security Chapter 15 Performing a Penetration Test The PenTest A penetration test (pentest) simulates methods that intruders use to gain unauthorized access to an organization s network and

More information

Securing the University Network

Securing the University Network Securing the University Network Abstract Endpoint policy compliance solutions take either a network-centric or device-centric approach to solving the problem. The body of this paper addresses these two

More information

NNT CIS Microsoft SQL Server 2008R2 Database Engine Level 1 Benchmark Report 0514a

NNT CIS Microsoft SQL Server 2008R2 Database Engine Level 1 Benchmark Report 0514a NNT CIS Microsoft SQL Server 2008R2 Database Engine Level 1 Benchmark Report 0514a: WIN- 2LR8M18J6A1 On WIN-2LR8M18J6A1 - By admin for time period 6/10/2014 8:59:44 AM to 6/10/2014 8:59:44 AM NNT CIS Microsoft

More information

Understanding Microsoft Web Application Security

Understanding Microsoft Web Application Security Understanding Microsoft Web Application Security Rajya Bhaiya Gradient Vision Info@GradientVision.com (415) 599-0220 www.gradientvision.com (ISC) 2 San Francisco Chapter Info@ISC2-SF-Chapter.org (415)

More information

Activity 1: Scanning with Windows Defender

Activity 1: Scanning with Windows Defender Activity 1: Scanning with Windows Defender 1. Click on Start > All Programs > Windows Defender 2. Click on the arrow next to Scan 3. Choose Custom Scan Page 1 4. Choose Scan selected drives and folders

More information

Chapter 4 Application, Data and Host Security

Chapter 4 Application, Data and Host Security Chapter 4 Application, Data and Host Security 4.1 Application Security Chapter 4 Application Security Concepts Concepts include fuzzing, secure coding, cross-site scripting prevention, crosssite request

More information

March 2012 www.tufin.com

March 2012 www.tufin.com SecureTrack Supporting Compliance with PCI DSS 2.0 March 2012 www.tufin.com Table of Contents Introduction... 3 The Importance of Network Security Operations... 3 Supporting PCI DSS with Automated Solutions...

More information

IIS Web Server Hardening

IIS Web Server Hardening 403_Ent_DMZ_AC.qxd 10/25/06 12:04 PM Page A:183 Appendix C IIS Web Server Hardening Solutions in this chapter: Understanding Common Vulnerabilities with Microsoft IIS Web Server Patching and Securing the

More information