Naming Conventions of Servers and Security
From: jwichman@junebox.comDate: 02/05/02
- Previous message: Jonathan Kimpson: "Comparison of VPN methods"
- Next in thread: Snow, Corey: "RE: Naming Conventions of Servers and Security"
- Reply: Snow, Corey: "RE: Naming Conventions of Servers and Security"
- Reply: Andrew Jones: "RE: Naming Conventions of Servers and Security"
- Reply: ian.cowan@perstorp.com: "Re: Naming Conventions of Servers and Security"
- Reply: Grunberg, Jeffrey: "RE: Naming Conventions of Servers and Security"
- Reply: Dan.Hemphill@mwhse.com: "RE: Naming Conventions of Servers and Security"
- Reply: Lindley, Britt: "RE: Naming Conventions of Servers and Security"
- Reply: backoffmymachine@hushmail.com: "RE: Naming Conventions of Servers and Security"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: jwichman@junebox.com To: security-basics@securityfocus.com Date: Tue, 5 Feb 2002 10:41:15 -0600
I have a question about naming conventions.
What is the security communities recommendation on naming servers? Is it
safe to name a server by the function the server provides? We are currently
looking at renaming our entire domain since there are 4 or 5 different
naming conventions currently being used. So far I have been told that
naming a server AABCCC## (where A = Company Division B = Type of device [ S
= Server, N = Network D = Desktop] C = placement of server [DMZ or PRD or
STG]) is weak security because an attacker would have useful knowledge about
the server. I feel most attackers would perform some recon of the network
and have that information before they went in to attack mode anyway.
I realize that it could be easier for an attacker to gain information about
the server, but what about the folks who have to work on the server? If a
server was to go down or be attacked I would rather know immediately from
the name what I could be dealing with or how critical it is to the company
that the server is down.
Please send me your humble opinions.
Thanks
Jeff Wichman
- Previous message: Jonathan Kimpson: "Comparison of VPN methods"
- Next in thread: Snow, Corey: "RE: Naming Conventions of Servers and Security"
- Reply: Snow, Corey: "RE: Naming Conventions of Servers and Security"
- Reply: Andrew Jones: "RE: Naming Conventions of Servers and Security"
- Reply: ian.cowan@perstorp.com: "Re: Naming Conventions of Servers and Security"
- Reply: Grunberg, Jeffrey: "RE: Naming Conventions of Servers and Security"
- Reply: Dan.Hemphill@mwhse.com: "RE: Naming Conventions of Servers and Security"
- Reply: Lindley, Britt: "RE: Naming Conventions of Servers and Security"
- Reply: backoffmymachine@hushmail.com: "RE: Naming Conventions of Servers and Security"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|