Re: upgrading to IE6 on w2k servers

From: Ant (cable78_at_gmail.com)
Date: 07/30/04

  • Next message: Jack Cullen: "PIX Firewall Logging Recommendations"
    Date: Fri, 30 Jul 2004 12:53:47 -0500
    To: security-basics@securityfocus.com
    
    

    I wholeheartedly agree. Using IE for anything but updates on a server
    is just asking for trouble. Even when doing Windows updates, I would
    recommend testing them on another box first. I have had too many
    updates hose my workstation to trust Windows updates without testing
    them first.

    On Fri, 30 Jul 2004 21:32:56 +0800, Ian Dexter R. Marquez
    <iandexter@gmail.com> wrote:
    > On Thu, 29 Jul 2004 10:10:28 +0300, Alexandros Papadopoulos
    > <apapadop@alumni.carnegiemellon.edu> wrote:
    > > On Tuesday 27 July 2004 20:10, Ansgar -59cobalt- Wiechers wrote:
    > > > On 2004-07-27 Juan B wrote:
    > > > > I want to know why is it recommended to upgrade my servers to IE6.
    > > > >
    > > > > I didnt find any reason at all !!! ( from the security point of
    > > > > view..).
    > > >
    > > > From a security point of view, the recommended upgrade would be to
    > > > install some other browser, not to upgrade IE.
    > > >
    > > > But there are some reasons for upgrading, e.g.:
    > > >
    > > > - Product lifecycle
    > > > - OE 6 allows for displaying mails as plaintext
    > >
    > > No security conscious person would use Outlook Express to read email on
    > > a server. Come to think of it, no such person would use OE, period.
    > >
    > > > - Better cookie-handling
    > > > - You need at least IE 5.5 to manage a SUS through its web-frontend
    > > > ...
    > > >
    > > > > I only found thie line in lits of site "it is recommended to update
    > > > > to IE6". but why ?
    > > > >
    > > > > why I need to upgrade ?
    > > > > I have IE5 on the servers and I surf the net from those servers.
    > > >
    > > > You shouldn't misuse servers as desktops.
    > >
    > > I second that. The only web connection a server should make is to
    > > windowsupdate.com (if you don't have an internal SUS server).
    > >
    >
    > During a Microsoft event here in the Philippines, IIRC, the Microsoft
    > evangelist specifically said that Windows Server 2003 comes with a
    > lower version of IE because one should never surf the Web on a server
    > in the first place, and the only thing you want to do with IE (in a
    > server) is for updates.
    >
    > --
    > Ian Dexter R. Marquez
    >
    >
    >
    > ---------------------------------------------------------------------------
    > Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off
    > any course! All of our class sizes are guaranteed to be 10 students or less
    > to facilitate one-on-one interaction with one of our expert instructors.
    > Attend a course taught by an expert instructor with years of in-the-field
    > pen testing experience in our state of the art hacking lab. Master the skills
    > of an Ethical Hacker to better assess the security of your organization.
    > Visit us at:
    > http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    > ----------------------------------------------------------------------------
    >
    >

    ---------------------------------------------------------------------------
    Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off
    any course! All of our class sizes are guaranteed to be 10 students or less
    to facilitate one-on-one interaction with one of our expert instructors.
    Attend a course taught by an expert instructor with years of in-the-field
    pen testing experience in our state of the art hacking lab. Master the skills
    of an Ethical Hacker to better assess the security of your organization.
    Visit us at:
    http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    ----------------------------------------------------------------------------


  • Next message: Jack Cullen: "PIX Firewall Logging Recommendations"

    Relevant Pages

    • Re: Strange Server Behaviour
      ... Thanks for updates. ... I am Charles the backup of Brandy, as the Brandy is currently sick at home. ... Microsoft CSS Online Newsgroup Support ... | Subject: Re: Strange Server Behaviour ...
      (microsoft.public.windows.server.sbs)
    • Re: WSUS Client not yet reported
      ... The client still fails to report. ... Check your server status ... Suggestion 2: Check the IIS settings: ... any updates in your thread. ...
      (microsoft.public.windows.server.sbs)
    • Re: Multiple issues (Server & Desktop) since last Windows Updates
      ... I installed the following Windows Updates ... >> and I am still fighting problems since the reboot after the updates. ... > since SP1 on our main Domain controller, which is also DNS server for itself ... >> these printers to their printer collection. ...
      (microsoft.public.windows.file_system)
    • Re: SUS
      ... > I have setup a SUS Server on win2k. ... 0-2.reg will not configure your machine to automatically download updates from ... critical updates or service packs that your machine needs. ... It will also ask you if you want to install them, ...
      (microsoft.public.windows.server.general)
    • Re: FYI for eTrust AV 7.x Users
      ... When I just had my little incident with the redistribution settings on the SBS, my clients were logging successful checks for updates, and the logs indicated that no updates were found. ... That turned out to be because I had not gone back and checked the redistribution server box for 8.x after reinstalling the redistribution server. ... installed the new remote install utility which works the same as v7 did - just edited the .ICF file the way I wanted it and ran the client upgrades from the server. ... I can't remember if it's a separate install, or if you have to click a box when you do the Agent install, but redistribution server is not installed by default. ...
      (microsoft.public.windows.server.sbs)