RE: Windows 2003 Server - MS Rulez?

From: Laura A. Robinson (larobins_at_bellatlantic.net)
Date: 05/24/03

  • Next message: Marc Fossi: "Article Announcement: Conducting a Security Audit: An Introductory Overview"
    To: "'Jimi Thompson'" <jimit@myrealbox.com>, "'Street'" <streetseeker@mail.ru>, <focus-ms@securityfocus.com>
    Date: Sat, 24 May 2003 15:46:40 -0400
    
    

     
    > ALL hashes are prone to the "birthday attack". The question becomes
    > seeing if code that will generate the same hash when piped through
    > the hashing function will get you anywhere (i.e. result in a
    > compromise).
    >
    Attacking the hash is far more work than is required to "get around" a hash
    software restriction, as I mentioned in my other post. Hash rules should be
    used for allowing software than would otherwise be disallowed because of
    software restriction default policy (a disallow policy) as opposed to
    disallowing software under an allow policy.

    Laura

    -----------------------------------------------------------------------------
    *** Wireless LAN Policies for Security & Management - NEW White Paper ***
    Just like wired networks, wireless LANs require network security policies
    that are enforced to protect WLANs from known vulnerabilities and threats.
    Learn to design, implement and enforce WLAN security policies to lockdown enterprise WLANs.

    To get your FREE white paper visit us at:
    http://www.securityfocus.com/AirDefense-focus-ms
    ------------------------------------------------------------------------------


  • Next message: Marc Fossi: "Article Announcement: Conducting a Security Audit: An Introductory Overview"

    Relevant Pages

    • Re: How to Remove Software Restriction?
      ... Hopefully you created the software restriction in it's own policy... ... HASH to work on an application... ... policy and create a new one in a GPO that is applied to the entire OU. ...
      (microsoft.public.win2000.active_directory)
    • User Software Restriction Policy
      ... I am trying to set up a "user" software restriction policy... ... created and the hash seems to be in place... ... No applications run except for those that are ...
      (microsoft.public.win2000.group_policy)
    • Software Restriction Policy
      ... I am trying to set up a "user" software restriction policy... ... created and the hash seems to be in place... ... No applications run except for those that are ...
      (microsoft.public.win2000.group_policy)
    • Re: I had high hopes for software restriction policy
      ... This could be due to the hash. ... I am having serious issues with software restriction policy... ... Created a Global Security Group "Restricted Applications Group" and Set ...
      (microsoft.public.windows.group_policy)
    • Re: MSN Messenger Wont Restrict by GPO
      ... but the hash and the test computer were taken from ... > you create a hash rule for a program, Software Restriction Policies ...
      (microsoft.public.windows.group_policy)