Re: Security Audit

From: Phil (pmarg_at_charter.net)
Date: 05/23/03


Date: Fri, 23 May 2003 08:15:22 GMT


I have found out that their answer to this security vulnerability was to
delete all *.pwl files on the Windows 9x machines.

"Steven L Umbach" <n9rou@attbi.com> wrote in
news:sgzxa.622836$OV.580812@rwcrnsc54:

> You are correct. There are no administrator accounts on W95
> machines. Possibly they are detecting that there is no password set to
> log onto the W95 operating system, just network log on. I would say -
> hey, you guys are right and we need to upgrade all those old systems
> to XP Pro ASAP to be in compliance. About the only thing you can do
> to improve securing W9X computers is to make sure they have Active
> Directory Client installed on them so that they can use ntlmv2
> authentication and smb signing if desired - otherwise they are using
> lm which any script kiddie could crack sniffing password hashes off
> the network. But I am sure you already using ADC or else the
> corporate security guys would have caught that. --- Steve
>
> http://www.petri.co.il/ad_client_for_win98_nt.htm - Active Directory
> Client link.
>
> "Phil" <pmarg@charter.net> wrote in message
> news:Xns937E9C086FD7pmargcharternet@65.82.44.187...
>> We are running a Windows 2000 AD domain with 2k, XP, and 9x clients.
>> We recently had a security audit of our network by our corporate
>> network security department. The software they used was "ISS Internet
>> Scanner v. 6.21."
>>
>> In the results I am seeing several of these issues relating to
>> Windows 9x machines:
>>
>> Issue: PASSWORD POLICIES
>> Level: High
>> Vulnerability: Administrator account has a blank password
>> Risk: Unauthorized access to system resources
>> Recommendation: Set passwords in accordance with Information
>> Security
>> policies and Procedures
>>
>> Since these are all Win9x machines, I'm not sure what to do here.
>> There is no administrator account.
>>
>> Using LANGuard I get these results on the same machine:
>>
>> IP Address : <ip of machine>
>> HostName : <hostname of machine>
>> Resolved : <hostname of machine>
>> Operating System : Windows 95
>> Time to live (TTL) : 32 (32) - Same network segment
>> Address mask : 255.255.255.0
>> Shares (1)
>> IPC$ - Remote Inter Process Communication
>> Open Ports (2)
>> 135 [ epmap => DCE endpoint resolution ]
>> 139 [ Netbios-ssn => NETBIOS Session Service ]
>>
>> Are the vulnerabilities that the ISS software is picking up correct?
>> If so, can anyone tell me what should be done in order to secure
>> these 9x clients? TIA
>>
>> -Phil
>>
>
>



Relevant Pages

  • Re: the exploit that wasnt
    ... The other Mac Book Pro? ... brought Microsoft into a security discussion about Mac OS X. ... The number of security patches, ... if you were to scan random machines on the internet for a week, how many Unix machines do you believe you would hit? ...
    (comp.sys.mac.advocacy)
  • Re: Cryptogram Comment
    ... Or had to go through setting up basic security for their ... > bother me with Windows questions. ... > machines are broken. ... and Linux and other open OS's make all patches FREE to redistribute. ...
    (sci.crypt)
  • Re: Temporary Ban On Links In Posts To SRI
    ... understand that there is a risk when clicking ... low)" in the general case does not apply to SRI. ... implement the security measures recommended. ... update" even with machines that are restricted to only applications ...
    (soc.religion.islam)
  • Re: the exploit that wasnt
    ... The other Mac Book Pro? ... brought Microsoft into a security discussion about Mac OS X. ... The number of security patches, ... if you were to scan random machines on the internet for a week, ...
    (comp.sys.mac.advocacy)
  • Re: Small Business Server Networking Wizard was not installed
    ... IE browser helper toolbar with some sort of security features enabled. ... WINSOCK fix, all these things were done on both of these machines, nothing ... Server Networking Wizard would not run on and nothing helped. ... ActivX garbage to install on either of these two machines. ...
    (microsoft.public.windows.server.sbs)