Re: Security Testing Question

From: Jam Live (Jam_at_jam.org)
Date: 03/23/04

  • Next message: Bubba Paris: "Any Help with Migrating Permissions from NDS to NTFS?"
    Date: Tue, 23 Mar 2004 22:42:04 -0000
    
    

    GX. Thanks for taking time out to help

    In particular penitration / network access testing (From an external source)
    since the users a trustworthy, All this is due to me having various open
    ports on my router / firewall. I dont use NAT either so i am more worried
    since "an sbs2k box" is directly connected to the net.

    I've heard its bad from some trusted people but i have not actuially been
    able to prove / disprove them

    Thanks again

    Chat soon i hope

    Jam

    "HG" <none@none.com> wrote in message
    news:ubY7c.282764$B81.4311438@twister.tampabay.rr.com...
    > Jam,
    >
    > Start by testing yourself right now, then if all your test ar not
    consistent
    > with each other look for a vendor to try to address these issues.
    >
    > What is it that you want to test? Website only? Network Access? Firewall
    > penetration, IDS?
    >
    > Let me know....
    >
    > GX
    >
    >
    > "Jam Live" <Jam@jam.org> wrote in message
    > news:zbp6c.24526$Y%6.2507446@wards.force9.net...
    > > Firstly......thanks for taking time to read this
    > >
    > > I have been lookin to find some form of testing on my companys site,, Im
    > > only a junior and not very clue'd up on testing security.
    > >
    > > I have noticed some sites selling this service doing such tasks as
    Network
    > > Security Assessment, Im sceptical to have this done as you can imagine
    it
    > > cost some serious expense.. The compay i work for is relativley small <
    30
    > > users,, however this still is a concern of mine.
    > >
    > > They mention things like Arp poisoning Dns poisoning (The site does host
    > its
    > > own website / SBS server for the full domain....) so im worried.. Should
    i
    > > pay for this security probing OR should be trying to test it myself. If
    so
    > > how should i do this,, Mostly im trying to find out how i can probe and
    > > thoughrly test the issues i have with my site. (If any) ok SBS hosting
    DNS
    > > WEB AD WINS ISA is not reported to be secure but how can 1) i prove it
    > aint
    > > 2) test it to find out for sure ?
    > >
    > > Can anyone help me on this in a legitamate fashion ?
    > >
    > > Jam
    > >
    > >
    > >
    >
    >


  • Next message: Bubba Paris: "Any Help with Migrating Permissions from NDS to NTFS?"

    Relevant Pages

    • Re: Finding out admin username
      ... locate Network Access Policy under Security Options..or am I checking out ... I guess a small setting in the security policy makes it disables, ... > The administrator account has a set SID no matter what you rename the ...
      (microsoft.public.win2000.security)
    • RE: How to securing endpoints - PRODUCTS
      ... We looked at this a while back and have details on every Endpoint Security ... We also broke out the Network Access Control products here: ... Symantec Network Access Control ...
      (Security-Basics)
    • Re: XP SP2 configuration
      ... SOunds like you may be bitten by a security setting. ... Uner Network Access, Sharing and security model... ... > `set impersonation level to impersonate ... When trying to connect to a XP SP2 ...
      (microsoft.public.win32.programmer.wmi)
    • Re: Printers dont assign after GPO Security changes...
      ... user was a member of. ... get a print mapping via their proper security group - then what good is the ... Let Everyone permissions apply to anonymous users. ... Network access: ...
      (microsoft.public.security)
    • Re: Local Security Policy
      ... I have not tried the sceregvl.inf at runtime but I am pretty sure it has many XP security policies in it. ... I'm able to see "Local Security Policy" in Control Panel. ... I can see popup window called "Local Security Settings". ... > -- Network Access: let Everyone permissions apply to anonymous users ...
      (microsoft.public.windowsxp.embedded)