Re: information harvesting from within the network

From: Alexander Klimov (alserkli_at_inbox.ru)
Date: 05/22/05

  • Next message: Fernando Serto: "XP native encryption"
    Date: Sun, 22 May 2005 11:15:57 +0300 (IDT)
    To: security-basics@securityfocus.com
    
    

    On Fri, 20 May 2005, ddjjembe 2 wrote:

    > Background:
    > I work in a university that has university typical security practices.
    > Currently any authenticated user can scan the parts of the network with
    > tools like LANguard or Nessus and obtain a considerable amount of
    > information from them. Most of the computers in our network are windows
    > computers. We also have departments with MACs and *nix machines.
    >
    > Goal:
    > If possible, lock down the Windows computers with group policies and/or
    > templates to disable this potential unauthorized information harvesting
    > users and then restrict scanning ability to the security group with LDAP
    > permissions. Am I on the right track here?
    >
    > I would like to achieve this without using a host based firewall.

    Probably you should first make clear why you want to stop this
    `unauthorized information harvesting.' Note that the names of your
    hosts are likely known from `Entire Network,' and it is very likely
    that in a university environment every host is more or less the same
    with respect to what services it runs and what `vulnearabilities' it
    has, e.g., if you have VNC installed on one host most likely it is
    installed on almost every other host (and even with the same
    password).

    Note that whatever you do to stop scanning from windows would not
    stop somebody plugging in his laptop and run nmap from it (or just
    booting linux live CD on the host).

    -- 
    Regards,
    ASK
    

  • Next message: Fernando Serto: "XP native encryption"

    Relevant Pages

    • Re: Quincy can wrongly enquire their gaze
      ... No minimum testy phrases will presumably host the ... windows. ... They are staging including the jail now, ...
      (sci.crypt)
    • Remote Assistance Across the Public Internet
      ... Expert host is Windows XP SP2 with latest updates, ... requestor host inviting the expert to a Remote Assistance ... In System> Remote tab, Allow Remote Assistance ...
      (microsoft.public.windowsxp.work_remotely)
    • RE: Remote Assistance Across the Public Internet
      ... Expert host is Windows XP SP2 with latest updates, ... requestor host inviting the expert to a Remote Assistance ... In System> Remote tab, Allow Remote Assistance ...
      (microsoft.public.windowsxp.work_remotely)
    • Re: IPsec Over Tunnel
      ... As your setup is described Windows XP should be using transport for host to ... it has something to do with the ipsec tunnel endpoint and IP filer list ...
      (microsoft.public.security)
    • Re: Virtual PC
      ... Once you install the trial ... if you don't backup your host then you have ... So do you actually have a 2nd license of Windows XP (either a full ... use something like ShadowSurfer to return the system back to its prior ...
      (microsoft.public.windowsxp.general)

  • Quantcast