Re: SecureIIS

From: Chuck Meeusen (cmeeusen@optonline.net)
Date: 09/27/01


Date: Thu, 27 Sep 2001 14:21:25 -0400
From: Chuck Meeusen <cmeeusen@optonline.net>
Subject: Re: SecureIIS
To: FOCUS-MS@SECURITYFOCUS.COM
Message-id: <3BB36E25.B97A71F6@optonline.net>

Slight correction, pcAnywhere v.10 can use the local (remote) SAM, domain or AD

as well.

C.

rusecure ??? wrote:

> Well...
>
> VNC is not secure at all, passes everything in the clear unless you use SSH
> first.
>
> PcAnyWhere has more secure options, but uses it's own user database so
> therefore another bunch of users to manage on every server.
>
> Terminal server is encrypted and uses AD so you only have to manage one set
> of users and obviously easier to manage.
>
> You decide.
>
> MG
>
> -----Original Message-----
> From: Mike Stark [mailto:mstark@dceg.com]
> Sent: Wednesday, September 26, 2001 4:19 PM
> To: Marc Maiffret; Mark Fagan; Focus-Ms (E-mail)
> Subject: RE: SecureIIS
>
> off topic, sorry..on a security note, HOW secure is terminal services for
> windows 2000, is it more secure then pcanywhere and vnc ???...is there any
> info on this..
>
> Thanks
>
> -----Original Message-----
> From: Marc Maiffret [mailto:marc@eeye.com]
> Sent: September 26, 2001 11:49 AM
> To: Mark Fagan; Focus-Ms (E-mail)
> Subject: RE: SecureIIS
>
> its stopped the last 5 or something remote IIS vulnerabilities before
> patches where even released from microsoft.
>
> note: i work for the company that makes secureiis and am one of its
> developers bla bla bla heh
>
> Signed,
> Marc Maiffret
> Chief Hacking Officer
> eEye Digital Security
> T.949.349.9062
> F.949.349.9538
> http://eEye.com/Retina - Network Security Scanner
> http://eEye.com/Iris - Network Traffic Analyzer
> http://eEye.com/SecureIIS - Stop known and unknown IIS vulnerabilities
>
> |-----Original Message-----
> |From: Mark Fagan [mailto:Mark.Fagan@esat.com]
> |Sent: Wednesday, September 26, 2001 4:47 AM
> |To: Focus-Ms (E-mail)
> |Subject: SecureIIS
> |
> |
> |Anybody advise on ability of SecureIIS ?
> |
> |
> |**********************************************************************
> |This email and any files transmitted with it are confidential and
> |intended solely for the use of the individual or entity to whom they
> |are addressed. If you have received this email in error please notify
> |the system manager.
> |
> |http://www.esatbusiness.com
> |
> |**********************************************************************
> |


Quantcast