Re: firewall & security recommendation
From: Lik Mai Sak (cuddlybear101_at_yahoo.com)
Date: 05/21/03
- Next message: David: "Re: firewall & security recommendation"
- Previous message: Duane Arnold: "Re: Firewall"
- In reply to: Rob Wahmann: "Re: firewall & security recommendation"
- Next in thread: David: "Re: firewall & security recommendation"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Thu, 22 May 2003 06:42:08 +1000
On Wed, 21 May 2003 13:17:54 GMT
"Rob Wahmann" <dotcomstudio@sbcglobal.net> wrote:
> Thanks for the tips. I have everything up to date with windows update,
> however I wasn't 100% sure if this addressed every security issue. There are
> only a few accounts on the FTP server and it is locked down pretty tight.
> I'm not sure how this person got in and took over. I've been looking at the
> WatchGuard SOHO 6 user and was wondering if anyone would recommend this...
> looks like a solid piece of equipment.
>
> Thanks again!
>
> Rob
The Watchguard Soho tc6 is a great unit. THey only thing to watch for is the licensing and options as they aren't always straightforward. Also the tech support is 24/7 and they are great to deal with if you have any issues.
A free plug in i find useful with these units is kiwisyslogd. see www.kiwisyslog.com
E.
>
> "Leythos" <void@nowhere.com> wrote in message
> news:MPG.1935444caff1e729989a97@news-server.columbus.rr.com...
> > In article <ZPAya.19805$%_3.8659581@newssrv26.news.prodigy.com>,
> > dotcomstudio@sbcglobal.net says...
> > > I used to have a Linksys router/firewall in place and it seemed to do
> the
> > > job, although it's not the ultimate solution. I went to DSL with 5
> static
> > > IP's and they gave me a free Netopia Cayman 3500 router with the
> package.
> > > The router has NAT but that hasn't stopped someone from hacking into my
> FTP
> > > server and taking over the machine. Can anyone recommend a serious
> firewall
> > > and a method of keeping up on patches, fixes, etc. for Win 2k Server
> that is
> > > *reasonably* inexpensive? I greatly appreciate any tips you can provide!
> >
> > The hacking of your server is a standard maintenance issue - where you
> > don't keep up to date with the security patches and where you didn't
> > understand the NT/NTFS permissions settings. Don't open the FTP server
> > for anonymous access, require authentication for all users.
> >
> > The firewall is another great idea - with your service, much like mine,
> > a firewall is an absolute for people that provide service to external
> > users. Check out the WatchGuard SOHO 6tc line of small firewalls - very
> > nice units.
> >
> > As for the updates, you can get the updates using the automated update
> > service that Microsoft provides free - just click on Windows Update and
> > let it run. I should warn you that there are a LOT of things that it
> > will install that are not just security related - Windows Medial Player
> > 9, etc.... You can set the preferences in WU to NOT download those types
> > of things, but they get installed by default.
> >
> > --
> > --
> > spamfree999@rrohio.com
> > (Remove 999 to reply to me)
>
>
- Next message: David: "Re: firewall & security recommendation"
- Previous message: Duane Arnold: "Re: Firewall"
- In reply to: Rob Wahmann: "Re: firewall & security recommendation"
- Next in thread: David: "Re: firewall & security recommendation"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
- [NT] Microsoft Internet Explorer FTP Command Injection Vulnerability
... Get your security news from a reliable source. ... Microsoft Internet Explorer
FTP Command Injection Vulnerability ... possibly steal data and upload malicious files to
an FTP server under the ... (Securiteam) - [NEWS] 3com NBX IP Phone System Denial of Service Attack (CEL)
... Beyond Security would like to welcome Tiscali World Online ... It was possible
to make the remote FTP server crash by issuing this ... a windows client by telneting to
the NBX server on port 21 or by ... call manager located on the outside of their firewall,
... (Securiteam) - Re: Strange response from network
... > to guess what service generally resides at the open port it found. ...
> instance, if I ran my FTP server on port 22, nmap would detect it as an ... Ethical
Hacking at the InfoSec Institute. ... learn to write exploits and attack security infrastructure.
... (Pen-Test) - Re: VFP 9: Help with sending/receiving XML via FTP
... Be prepared to answer the coming questions - I have seen too many setups where security
was slapped on in a hurry. ... FTP server and the risks of someone connecting with
FTP client, ... Technology in itself is so used that "administration" can be handled by
almost anybody - less need for admin knowledge. ... (microsoft.public.fox.programmer.exchange) - iDEFENSE Security Advisory 11.04.02a: Pablo FTP Server DoS Vulnerability
... Pablo FTP Server DoS Vulnerability ... Texonet discovered this vulnerability.
... Get paid for security research ... Subscribe to iDEFENSE Advisories:
... (Bugtraq)