RE: Securing NT4 Server Websites

From: Rosado, Rafael (Rafael) (rarosado@lucent.com)
Date: 01/30/03

  • Next message: Richard H. Cotterell: "Re: Listing processes and killing processes through command line in W indows"
    From: "Rosado, Rafael (Rafael)" <rarosado@lucent.com>
    To: simont@lantic.net
    Date: Wed, 29 Jan 2003 18:34:19 -0700
    
    

    Simon,

    You might also want to consider downloading and running the "freebie" tools
    from the Center for Internet Security (CIS) against the NT/2000 Servers to
    ensure these are hardened (http://www.cisecurity.org). Other "freebie"
    tools to consider are the Microsoft Baseline Security Analyzer (MSBA -
    http://www.microsoft.com) and Nessus (http://www.nessus.org).

    Good Luck!

    Rafael Rosado, CISSP, CISA
    IT Security Manager
    Caribbean and Latin America Region (CALA) &
    Global Risk Assessment and Penetration Testing
    Lucent Technologies O
    Corporate Security
    Business Assurance and Risk Mitigation Services (B.A.R.M.S.)
    2400 SW 145th Avenue - Room 3S039
    Miramar, Florida 33027
    +1 954-885-2176 (voice) *
    +1 954-885-3861 (fax) *
    +1 954-648-3532 (mobile) or 9546483532@mobile.att.net (text message) *
    rarosado@lucent.com (email) *

    This electronic mail message contains information belonging to Lucent
    Technologies, which may be confidential and/or legal privileged. The
    information is intended only for the use of the individual or entity named
    above. If you are not the intended recipient, you are hereby notified that
    any disclosure, printing, copying, distribution, or the taking of any action
    in reliance on the contents of this electronically mailed information is
    strictly prohibited. If you receive this message in error, please
    immediately notify us by electronic mail and delete this message.

    -----Original Message-----
    From: David M. Fetter [mailto:dfetter@setec-astronomy.biz]
    Sent: Wednesday, January 29, 2003 3:22 PM
    To: simont@lantic.net
    Cc: Security-Basics
    Subject: Re: Securing NT4 Server Websites

    Try http://nsa2.www.conxion.com/.

    Simon Taplin wrote:
    > Can somebody give me some suggestions for websites/pages for securing a
    Win
    > NT4 server which will be acting as a file server only. I would use Win2k
    but
    > Win2K and the m/b don't work together for some or another reason.
    >
    > I will already be installing SP6a + hotfixes and making sure that IIS is
    not
    > running, but what else?
    >
    > Thanks
    > Simon
    >
    >
    > Quote of the day:
    > Systems Administration is the kind of job that nobody notices if you're
    > doing it well. People only take notice of their systems when they're not
    > working.
    > ---
    >
    > This email has been scanned by AVG Anti-Virus
    > Checked by AVG anti-virus system (http://www.grisoft.com).
    > Version: 6.0.445 / Virus Database: 250 - Release Date: 2003/01/21
    >
    >
    >
    >

    -- 
    David M. Fetter (MegaSurge) - http://www.setec-astronomy.biz/
    "The world is full of power and energy and a person can go far by just 
    skimming off a tiny bit of it." Neal Stephenson - Snow Crash
    


    Relevant Pages

    • security-basics Digest of: get.123_145
      ... VPN to ASP a security risk? ... Re: Multiple IPSec tunnels? ... Subject: Security NT Server ... VPN to ASP a security risk? ...
      (Security-Basics)
    • << SBS News of the week - Sept 26 >>
      ... And he points to the info you need to put the file on the server in the ... at the network perimeter. ... The Symantec Firewall/VPN and the Gateway Security ... by the firewall at risk. ...
      (microsoft.public.backoffice.smallbiz2000)
    • Re: << SBS News of the week - Sept 26 >>
      ... > And he points to the info you need to put the file on the server in the ... > at the network perimeter. ... The Symantec Firewall/VPN and the Gateway Security ... An attacker can exploit these flaws in tandem via specially ...
      (microsoft.public.backoffice.smallbiz2000)
    • << SBS News of the week - Sept 26 >>
      ... And he points to the info you need to put the file on the server in the ... at the network perimeter. ... The Symantec Firewall/VPN and the Gateway Security ... by the firewall at risk. ...
      (microsoft.public.windows.server.sbs)
    • Re: << SBS News of the week - Sept 26 >>
      ... > And he points to the info you need to put the file on the server in the ... > at the network perimeter. ... The Symantec Firewall/VPN and the Gateway Security ... An attacker can exploit these flaws in tandem via specially ...
      (microsoft.public.windows.server.sbs)