RE: Windows XP SP2 and Security Tools

From: Roger A. Grimes (roger_at_banneretcs.com)
Date: 09/20/05

  • Next message: Henrik Becker: "Re: Log Analyzer Tool"
    Date: Tue, 20 Sep 2005 12:31:11 -0400
    To: "Steve McLaughlin" <Steve.McLaughlin@aggreko.co.uk>, <pen-test@securityfocus.com>, <security-basics@securityfocus.com>
    
    

    From the Pen testers perspective:

    Lots of tools are broken by SP2, not all can be fixed by a regedit
    patch. Do install the regedit patch that comes along with the Windows
    version of nmap...it will increase the number of sessions you can launch
    at once.

    DEP/NX will "break" lots of other tools at least partially (ex. Cain,
    Lsadump, etc.)

    Microsoft is getting better at security and that makes the tools harder
    to use too, unfortunately for pen testers...but overall it means good
    things for the overall security.

    Roger

    ************************************************************************
    ***
    *Roger A. Grimes, InfoWorld, Security Columnist
    *CPA, CISSP, MCSE: Security (2000/2003/MVP), TICSA, CEH, CHFI
    *email: roger_grimes@infoworld.com or roger@banneretcs.com
    *Author of Honeypots for Windows (Apress)
    *http://www.apress.com/book/bookDisplay.html?bID=281
    ************************************************************************
    ****

    -----Original Message-----
    From: Steve McLaughlin [mailto:Steve.McLaughlin@aggreko.co.uk]
    Sent: Monday, September 19, 2005 10:46 AM
    To: pen-test@securityfocus.com; security-basics@securityfocus.com
    Subject: Windows XP SP2 and Security Tools

    Hi List,
     
    We are currently in the stage of rolling out Windows XP SP2. I know that
    this had some problems with winpcap a while back.
    we use all the good open source security tools we can with windows, cos
    its easier than putty to the linux box.
     
    Des anyone know of any issues, or problems that SP2 may pose from what a
    security pen-testing box is concerned.
    Will it affect any Windows based security tools, or are there any other
    issues it has from a security point of view?
    Considering it is also my workstation, and hence we have to use windows
    for it.
     
    Thankyou in Advance,
    Steve

    Visit us at http://www.aggreko.com

    Confidentiality Notice: This communication and any accompanying
    attachments contain confidential information intended for a specific
    individual and purpose. This communication is private and protected by
    law. If you are not the intended recipient, you are hereby respectfully
    notified that any disclosures, copying, forwarding or distribution, or
    the taking of any action based on the contents of this communication is
    strictly prohibited.

    _____________________________________________________________________
    This email has been scanned by the MessageLabs Email Security System.
    For more information please visit http://www.messagelabs.com/email
    ______________________________________________________________________


  • Next message: Henrik Becker: "Re: Log Analyzer Tool"

    Relevant Pages

    • [NT] Cumulative Security Update for Internet Explorer (MS04-025)
      ... Get your security news from a reliable source. ... * Microsoft Windows NT Workstation 4.0 Service Pack 6a ... Navigation Method Cross-Domain Vulnerability ...
      (Securiteam)
    • [NT] Vulnerability in HTML Help Allows Code Execution (MS05-001)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... * Microsoft Windows XP Service Pack 1 and Microsoft Windows XP Service ...
      (Securiteam)
    • Re: The Myth of the secure Mac
      ... OEM Windows XP Home goes for a bit under $100. ... >> secure than Home. ... Though this really has nothing to do with security. ... Microsoft counts on third-party developers to provide more ...
      (comp.sys.mac.advocacy)
    • SecurityFocus Microsoft Newsletter # 149
      ... MICROSOFT VULNERABILITY SUMMARY ... EveryBuddy Long Message Denial Of Service Vulnerability ... Intellitactics Network Security Manager ... Windows operating systems. ...
      (Focus-Microsoft)
    • SecurityFocus Microsoft Newsletter #120
      ... Strengthening Network Security: FREE Guide Network security is a ... MICROSOFT VULNERABILITY SUMMARY ... Microsoft Windows File Protection Signed File Replacement... ... PlatinumFTPServer Information Disclosure Vulnerability ...
      (Focus-Microsoft)