re: Actual Security Cases

From: H C (keydet89@yahoo.com)
Date: 01/30/03

  • Next message: LEHMANN, TODD: "Group Policy And VPN In W2K Domain"
    Date: Thu, 30 Jan 2003 13:12:58 -0800 (PST)
    From: H C <keydet89@yahoo.com>
    To: security-basics@securityfocus.com
    
    

    > Does anybody know a good internet source of actual
    security related real life cases?

    Unfortunately, some of what you're asking isn't really
    the issue you may think it is...for example, "no
    remote access via modem" (depending on exactly what
    you mean). Remote access isn't that much of a
    security risk, as long as it's implemented,
    configured, and managed/monitored appropriately.

    W/ regards to "no weak passwords", that's easy
    enough...MS released a security advisory in Aug, and
    re-released it in Sept. Evidently there was a rash of
    systems getting infected w/ IRC bots, due to weak or
    non-existant Administrator passwords.

    W/ regards to forwarding corporate email to another
    account...in many cases, that's simply against
    policies. I mean, if it's A Very Bad Thing(tm) if
    someone hacks the remote account and gains access to
    the data, it really isn't so different from writing
    your SSN and CC numbers on a piece of paper, and
    leaving it sitting on a park bench.

    __________________________________________________
    Do you Yahoo!?
    Yahoo! Mail Plus - Powerful. Affordable. Sign up now.
    http://mailplus.yahoo.com



    Relevant Pages

    • RE: How to determine if the latest securiy updates are installed (
      ... ' RQScript.vbs - Remote Access Quarantine Script ... The script verifies the security configuration of the client computer. ... is there no solution without any installation ...
      (microsoft.public.scripting.vbscript)
    • RE: Is this normal?
      ... This is far too common. ... A few simple security tips may help. ... Do not allow root any remote access; create a user and su if you need ...
      (Security-Basics)
    • Re: RWW or VPN issues with remote access
      ... we use RWW for all remote access without a hitch. ... and the vendor insists we install a hardware appliance for their VPN ... I know little about VPN or UltraVNC but when I asked them about ... security, they said UltraVNC had better security than RWW. ...
      (microsoft.public.windows.server.sbs)
    • Re: Security concern
      ... Most offices have some physical security. ... remote access via TS if you're truly paranoid. ... authentication e.g. forming a VPN connection? ...
      (microsoft.public.windows.server.sbs)
    • Help from an MVP would be greatly appreciated.....
      ... >>1) Is it normal to read of 'failed security audits' due ... >>any changes to passwords and or user id's on my system. ... >system processes that handle remote access and security ... I'll have to check back in the security logs to see ...
      (microsoft.public.windowsxp.security_admin)