RE: SIM Tools, and endpoint security.

From: Drew Simonis (simonis_at_myself.com)
Date: 05/25/05

  • Next message: Justin.Ross_at_signalsolutionsinc.com: "RE: Value of IDS, ROI"
    To: THolman@toplayer.com, focus-ids@securityfocus.com
    Date: Wed, 25 May 2005 12:44:20 -0500
    
    

    >
    > Hi Drew,
    >
    > I'm referring to Windows File Protection -
    > http://support.microsoft.com/kb/310747/EN-US/
    >
    > This is configurable via Group Policy and offers 100% protection of system
    > files on the intended target.

    Back in the day, I remember being able to trick SFC into replacing with the
    wrong file. I suppose this has been fixed?

    >
    > ..add to this Windows XP SP2, then you've got a pretty rock solid
    > workstation base that is not open to infection (as the firewall doesn't
    > allow anything in), and maintains integrity of system files (so malicious
    > code can't take over the system).

    I don't agree with this statement. There are a few key assumptions.
    First, you assume that the only way to become infected is via the network.
    That is obviously false, as all of our email worms show. But, even if it
    were true, most workstations allow inbound file sharing via CIFS, which
    is a common attack vector and propogation method. So, client firewalls
    don't offer nearly the protection one might wish for unless configured
    correctly (not often done in large enterprises). In addition, the problem
    with the Windows file checker is that it doesn't allow for checking of
    arbitrary other programs. So, we have yet another windows only solution,
    which is to be expected. However, it doesn't equate to 100% protection
    nor does it obviate the need to install 3rd party tools that offer broader
    coverage.

    Anyway, malware doesn't need to monkey with the system files to take over
    the system.

    > There's quite a lot more to Microsoft's OS security that often gets
    > overlooked, and many sysadmins are steered away from this with clever
    > marcoms and end up buying 3rd party applications to fill the gap.
    >
    > My point is, be 100% sure that what you've got cannot do what you want,
    > before you go and buy something else! ;)

    All said, a good point. I'd add to be sure what you want before looking
    for products.

    -Ds

    -- 
    ___________________________________________________________
    Sign-up for Ads Free at Mail.com
    http://promo.mail.com/adsfreejump.htm
    --------------------------------------------------------------------------
    Test Your IDS
    Is your IDS deployed correctly?
    Find out quickly and easily by testing it with real-world attacks from 
    CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 
    to learn more.
    --------------------------------------------------------------------------
    

  • Next message: Justin.Ross_at_signalsolutionsinc.com: "RE: Value of IDS, ROI"

    Relevant Pages

    • RE: Office 2007 Enterprise - Deployment
      ... Files\Common Files\Microsoft Shared\Web Server ... the Windows File protection prompt. ... Even if I copy the file from the dllcache - I still get the Windows File ... The Windows Installer service cannot update one or more protected Windows ...
      (microsoft.public.office.setup)
    • RE: Office 2007 Enterprise - Deployment
      ... Server>Details>IIS>Details and install (or uninstall if it is already ... installed) the FrontPage 2002 Server Extensions ... the Windows File protection prompt. ... Even if I copy the file from the dllcache - I still get the Windows File ...
      (microsoft.public.office.setup)
    • Re: anything to worry about??...
      ... could not be verified as valid because Windows File ... Protection is terminating. ... >Open the case and check all the cables, ... i have two hard drives, ...
      (microsoft.public.security)
    • Re: Where can I get MD5 hash of system files?
      ... Rock wrote: ... > It'd be nice if MS actually took their own evangelists' advice, ... >>CTFMON.EXE is a valid windows file. ... >>Windows File Protection. ...
      (alt.computer.security)
    • Re: Code Obsfucation
      ... Therefore, God exists. ... the free Dotfuscator Community Edition is included with VS 2005. ... If you need an extra level of protection you can either upgrade to ... Dofuscator Professional Edition or use any of the many 3rd party tools ...
      (microsoft.public.dotnet.languages.csharp)