ISS Security Audit

From: Phil (pmarg_at_charter.net)
Date: 05/17/03


Date: Sat, 17 May 2003 17:24:53 GMT

We recently had a security audit of our network by our corporate network
security department. The software they used was "ISS Internet Scanner v.
6.21."

In the results I am seeing several of these issues relating to Windows 9x
machines:

   Issue: PASSWORD POLICIES
   Level: High
   Vulnerability: Administrator account has a blank password
   Risk: Unauthorized access to system resources
   Recommendation: Set passwords in accordance with Information Security
policies and Procedures

Since these are all Win9x machines, I'm not sure what to do here. There
is no administrator account.

Using LANGuard I get these results on the same machine:

 IP Address : <ip of machine>
  HostName : <hostname of machine>
  Resolved : <hostname of machine>
  Operating System : Windows 95
  Time to live (TTL) : 32 (32) - Same network segment
  Address mask : 255.255.255.0
  Shares (1)
       IPC$ - Remote Inter Process Communication
  Open Ports (2)
       135 [ epmap => DCE endpoint resolution ]
       139 [ Netbios-ssn => NETBIOS Session Service ]

Are the vulnerabilities that the ISS software is picking up correct? If
so, can anyone tell me what should be done in order to secure these 9x
clients? TIA

   -Phil



Relevant Pages

  • Security Audit
    ... recently had a security audit of our network by our corporate network ... The software they used was "ISS Internet Scanner v. ... HostName: ...
    (microsoft.public.win2000.security)
  • Securing Windows 9x
    ... We recently had a security audit of our network by our corporate network ... The software they used was "ISS Internet Scanner v. ... HostName: ...
    (alt.computer.security)
  • Brainstorming needed: impact of changing hostname
    ... Our management has raised that the current naming convention ... of our servers would reveal the organisation name and OS type ... is this truly a security threat among IT security circle ... hostname (across different Solaris versions; ...
    (SunManagers)
  • Re: Internal POP3 users
    ... in your posting, keep them off your corporate network, VLAN, or something. ... This is a major security ... to facilitate one-on-one interaction with one of our expert instructors. ... Attend a course taught by an expert instructor with years of in-the-field ...
    (Security-Basics)
  • RE: HTTP request working via hostname but not via IP address
    ... Sometimes you can get the hostname return the correct IP, ... Concerned about Web Application Security? ... Download FREE whitepaper on how a managed service ... Download FREE whitepaper on how a managed service can ...
    (Pen-Test)