RE: Share Point?

From: Corey Flood (cflood_at_bigcityfunding.com)
Date: 05/09/03

  • Next message: John Davis: "RE: Share Point?"
    To: <focus-ms@securityfocus.com>
    Date: Fri, 9 May 2003 13:11:58 -0700
    
    

    I have Share Point Team Services set up on our domain as an
    intra/extranet and the users are not local on my configuration. I used
    the option second option to use domain authentication....so the user's
    name is domainname\username and it uses the information such as password
    and actual name...I dont know what port it uses to authenticate to the
    AD Server.

    Also, in the IIS settings for the site you can use the IIS security (or
    lack thereof), you can also move the port or make the share point site
    ssl, which is what I did....hope any of this helps...

    -Corey Flood
    Big City Funding
    IT Manager / Loan Officer
    cflood@bigcityfunding.com

    -----Original Message-----
    From: Roberts Phillip (IBM) [mailto:phillip.roberts@thomson.net]
    Sent: Friday, May 09, 2003 11:01 AM
    To: 'focus-ms@securityfocus.com'
    Subject: RE: Share Point?

    Couldn't you make that server its own PDC/Domain within the DMZ in order
    to
    avoid this as an issue?

    -----Original Message-----
    From: Matt Andreko [mailto:mandreko@ori.net]
    Sent: Friday, May 09, 2003 11:25 AM
    To: 'Derek Schaible'; focus-ms@securityfocus.com
    Subject: RE: Share Point?

    Be sure to make a note that Sharepoint (at least sharepoint team
    services) uses local users. It does not use some authentication
    database or anything. If you tell it to create a new user for the site,
    or if the site allows a user to sign up, that user has an NT password on
    the system. This could help in establishing a privilege escalation
    exploit.

    Normally the local users are pretty stripped down, but it could be used
    with an exploit of some sort that requires little privilege.

    -----Original Message-----
    From: Derek Schaible [mailto:dschaible@cssiinc.com]
    Sent: Friday, May 09, 2003 8:33 AM
    To: focus-ms@securityfocus.com
    Subject: Share Point?

    Greetings List,

    I have a customer who wants to place sharepoint in a DMZ for outside
    clients to access documents. It is their intent to place all of their
    data regarding a project on the SharePoint server and use that as the
    single point of storage for this project. Meaning, everyone on the team
    uses this one share in the DMZ.

    Does this sound safe? Has anyone here tested Share Point's security?
    I'm sure this isn't the first time someone has needed to do something
    like this, how have some of you handled this scenario?

    I appreciate anyone's input on this matter and any advice at all is
    welcome!

    Thanks,
    Derek

    ------------------------------------------------------------------------
    -----
    FastTrain has your solution for a great CISSP Boot Camp. The industry`s
    most
    recognized corporate security certification track, provides a
    comprehensive
    prospectus based upon the core principle concepts of security. This ALL
    INCLUSIVE curriculum utilizes lectures, case studies and true hands-on
    utilization
    of pertinent security tools. For a limited time you can enter for a
    chance
    to win one of the latest technological innovations, the SEGWAY HT.
    Log onto http://www.securityfocus.com/FastTrain-focus-ms
    ------------------------------------------------------------------------
    ------

    ------------------------------------------------------------------------

    ----
    -
    FastTrain has your solution for a great CISSP Boot Camp. The industry`s
    most
    recognized corporate security certification track, provides a
    comprehensive 
    prospectus based upon the core principle concepts of security. This ALL
    INCLUSIVE curriculum utilizes lectures, case studies and true hands-on
    utilization 
    of pertinent security tools. For a limited time you can enter for a
    chance 
    to win one of the latest technological innovations, the SEGWAY HT. 
    Log onto http://www.securityfocus.com/FastTrain-focus-ms
    ------------------------------------------------------------------------
    ----
    --
    ------------------------------------------------------------------------
    -----
    FastTrain has your solution for a great CISSP Boot Camp. The industry`s
    most 
    recognized corporate security certification track, provides a
    comprehensive 
    prospectus based upon the core principle concepts of security. This ALL
    INCLUSIVE curriculum utilizes lectures, case studies and true hands-on
    utilization 
    of pertinent security tools. For a limited time you can enter for a
    chance 
    to win one of the latest technological innovations, the SEGWAY HT. 
    Log onto http://www.securityfocus.com/FastTrain-focus-ms
    ------------------------------------------------------------------------
    ------
    -----------------------------------------------------------------------------
    FastTrain has your solution for a great CISSP Boot Camp. The industry`s most 
    recognized corporate security certification track, provides a comprehensive 
    prospectus based upon the core principle concepts of security. This ALL INCLUSIVE curriculum utilizes lectures, case studies and true hands-on utilization 
    of pertinent security tools. For a limited time you can enter for a chance 
    to win one of the latest technological innovations, the SEGWAY HT. 
    Log onto http://www.securityfocus.com/FastTrain-focus-ms
    ------------------------------------------------------------------------------
    

  • Next message: John Davis: "RE: Share Point?"

    Relevant Pages

    • RE: LANguard vs Nessus
      ... prospectus based upon the core principle concepts of security. ... This ALL INCLUSIVE curriculum utilizes lectures, case studies and true hands-on utilization ... of pertinent security tools. ... For a limited time you can enter for a chance ...
      (Security-Basics)
    • RE: block internet at two workstations :VSMail mx1
      ... > Data Security Administrator ... > FastTrain has your solution for a great CISSP Boot Camp. ... > INCLUSIVE curriculum utilizes lectures, ... For a limited time you can enter for a chance ...
      (Security-Basics)
    • RE: p2p and ISA
      ... End Users can't install what they don't have access to. ... > recognized corporate security certification track, ... This ALL INCLUSIVE curriculum utilizes lectures, ... For a limited time you can enter ...
      (Focus-Microsoft)
    • Re: some permission problem?
      ... > prospectus based upon the core principle concepts of security. ... INCLUSIVE curriculum utilizes lectures, ...
      (Security-Basics)
    • RE: Malware test sites
      ... > recognized corporate security certification track, ... > prospectus based upon the core principle concepts of security. ... > INCLUSIVE curriculum utilizes lectures, ...
      (Security-Basics)