RE: [Full-Disclosure] Re: Securing Windows 2000 Server Documentat ion

From: Sung J. Choe (schoe@oicinc.com)
Date: 02/25/03

  • Next message: Steve Wray: "RE: [Full-Disclosure] Re: Terminal Emulator Security Issues"
    From: "Sung J. Choe" <schoe@oicinc.com>
    To: "'guninski@guninski.com'" <guninski@guninski.com>
    Date: Tue, 25 Feb 2003 10:46:01 -1000
    

    > Obviously the microsoft certified solitaire experts (aka MCSE) who
    administrate
    > the microsoft internal network have not read this propaganda

    ;-p
    Or, similar to Nazi Germany, they began to believe their own propaganda
    resulting in undeserved confidence in their internal security posture.

    .--------------------------------------------------.
    | Sung J. Choe <schoe[at]oicinc.com>, TICSA |
    | Systems Administrator, Facility Security Officer |
    .--------------------------------------------------.----.
                        | Oceanic Imaging Consultants, Inc. |
                        | Phone #: (808) 539-3634 x3634 |
                        .-----------------------------------.

    568D CAD6 53A0 92E6 4A2A 4E87 3BA0 5F90 37BB 8EE7

    > -----Original Message-----
    > From: Georgi Guninski [mailto:guninski@guninski.com]
    > Sent: Tuesday, February 25, 2003 5:55 AM
    > To: Michael Howard
    > Cc: full-disclosure@lists.netsys.com
    > Subject: [Full-Disclosure] Re: Securing Windows 2000 Server
    > Documentation
    >
    >
    > Obviously the microsoft certified solitaire experts (aka
    > MCSE) who administrate
    > the microsoft internal network have not read this propaganda
    > since their
    > internal network got infected by the sql worm according to the news.
    >
    > Georgi Guninski
    >
    > Michael Howard wrote:
    > > The Microsoft Solutions for Security team has released
    > 'Securing Windows
    > > 2000 Server'. This is the first of several prescriptive security
    > > solutions planned for release this year. These new security
    > solutions
    > > are designed to provide customers with authoritative,
    > proven, and tested
    > > solutions that address today's security challenges and business
    > > requirements.
    > >
    > > The contents include:
    > >
    > > Chapter 1: Introduction to Securing Windows 2000 Server
    > > This chapter introduces the Securing Windows 2000 Server guide. It
    > > includes a brief overview of each of the other chapters.
    > >
    > <snip>
    >
    >
    > _______________________________________________
    > Full-Disclosure - We believe in it.
    > Charter: http://lists.netsys.com/full-disclosure-charter.html
    >

    
    

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


    • application/octet-stream attachment: schoe.vcf


    Relevant Pages

    • Re: slightly off topic - flaws in using win2k for wireless security and openbsd replacing
      ... > Hi UNIX security professionals and hobbyists, ... > Basically, we have our wired internal network, then we have a dual-NIC ... > win2k server that acts as a Microsoft PPTP VPN server, ... > The problem I see is, anybody can connect to the wireless access point ...
      (comp.security.unix)
    • Re: Encryption of printer files
      ... security specs. ... The problem lies in the fact that if we are so worried about encrypting the ... internal network it could fall back to the above security specs. ... risk can be limited with an encrypted session to ...
      (comp.unix.sco.misc)
    • Re: Anyone know why the Alpha market is so so quiet?
      ... through firewalls are only a minor part of the overall security ... plugged directly into your internal network do not have "buggies" ... It'll be a different story when you start seeing more people with Linux on the Laptop. ... Give a man a fish, and he eats for a day. ...
      (comp.os.vms)
    • Re: Dual NIC Card - Question
      ... Yes there is a security hole there. ... Traffic will not route from NIC to NIC ... internal network by connecting it via the 2nd NIC to your DMZ network. ... > installed a 2nd NIC on each of my servers for backup traffic. ...
      (microsoft.public.windows.server.networking)
    • Re: Exchange server in DMZ, not FE server. Is this ever ok?
      ... It will turn out that it doesn't add value in terms of security ... If I hear you as saying having a firewall present is without value, ... NICs - one for the internal network, and the other for the DMZ. ...
      (microsoft.public.security)