RE: W2K where to start??

From: Dustin Puryear (dpuryear@usa.net)
Date: 10/22/01


From: "Dustin Puryear" <dpuryear@usa.net>
To: "Michael Bartosh" <mbartosh@mac.com>, <security-basics@securityfocus.com>
Subject: RE: W2K where to start??
Date: Mon, 22 Oct 2001 10:49:32 -0500
Message-ID: <PGECILGGNJGDPJKLFEMIAEDDCAAA.dpuryear@usa.net>

Well, Windows is no more vulnerable than your average UNIX system is out of
the box. This is especially true if you use a mass-market Linux distribution
like Red Hat. You should just apply all of the patches available from
Microsoft for whatever services you are running (you didn't mention which
ones), and sign up for the Microsoft bulletins. In addition, Microsoft has
some very good information about securing your machines under
microsoft.com/security or something similar.

I've also heard good things about the Win2k security documents released by
the NSA. You may want to find and read those.

Regards, Dustin

> -----Original Message-----
> From: Michael Bartosh [mailto:mbartosh@mac.com]
> Sent: Sunday, October 21, 2001 2:37 AM
> To: security-basics@securityfocus.com
> Subject: W2K where to start??
>
>
> Hi-
>
> I'm a unix / Mac guy. I agreed to set up a test installation of W2K
> Advanced Server because the M$ rep has always been nice. It's going
> to be in a DMZ so I'm not as scared as I would be, but my impression
> is that windows in general is full of holes out of box (at least from
> the number of command.exe's in my apache logs it would SEEM so), and
> I don't know where to start when it comes to windows security-
>
> Where is a site I can go to that lists all the updates / patches I
> need to get started. Any general advice?
>
> -mab
>
> --
>



Relevant Pages

  • SecurityFocus Microsoft Newsletter #176
    ... MICROSOFT VULNERABILITY SUMMARY ... Microsoft Windows XP HCP URI Handler Arbitrary Command Execu... ... PHPNuke Category Parameter SQL Injection Vulnerability ... Microsoft Baseline Security Analyzer Vulnerability Identific... ...
    (Focus-Microsoft)
  • SecurityFocus Microsoft Newsletter #49
    ... Subject: SecurityFocus Microsoft Newsletter #49 ... Microsoft Windows NNTP Denial of Service Vulnerability ... Microsoft IIS SSI Buffer Overrun Privelege Elevation Vulnerability ... Microsoft ISA Server H.323 Memory Leak Denial of Service... ...
    (Focus-Microsoft)
  • SecurityFocus Microsoft Newsletter #153
    ... MICROSOFT VULNERABILITY SUMMARY ... ZoneAlarm Random UDP Flood Denial Of Service Vulnerability ... FloosieTek FTGatePro Mail Server Path Disclosure Vulnerabili... ... Microsoft Windows NetBIOS Name Service Reply Information Lea... ...
    (Focus-Microsoft)
  • [NT] Cumulative Security Update for Internet Explorer (MS04-025)
    ... Get your security news from a reliable source. ... * Microsoft Windows NT Workstation 4.0 Service Pack 6a ... Navigation Method Cross-Domain Vulnerability ...
    (Securiteam)
  • SecurityFocus Microsoft Newsletter #120
    ... Strengthening Network Security: FREE Guide Network security is a ... MICROSOFT VULNERABILITY SUMMARY ... Microsoft Windows File Protection Signed File Replacement... ... PlatinumFTPServer Information Disclosure Vulnerability ...
    (Focus-Microsoft)