Re: VPN with quarantine: hox to check state of security center in win xp ?

From: Andrew Mitchell (amitchell_at_removecasey.vic.gov.au)
Date: 10/26/04


Date: Tue, 26 Oct 2004 07:34:16 -0700


"Ralf Huelsmann" <ralf.huelsmann@itz-duesseldorf.de> said

> Hi !
>
> playing with this nice VPN-qurantaine, i would see the most use in it if
> i could check the states the security of XP SP2 has discoverd
> - are windows update configured ?
> - is the firewall up ?
> - is the antivirus running and up to date ?
>
> the security center know all this, and i could get the information into
> the vpn-skript (a .cmd), that would be great. microsoft itselfs uses
> example script where it tells you to check that, but not how.
>
> i could get the firewall state i.e. with netsh.. but there must be a
> simpler way ?
>
> any links, expirence, tips, how-too´s ??
>

Have you tried the sample scripts at
http://www.microsoft.com/downloads/details.aspx?FamilyID=a290f2ee-0b55-491e-
bc4c-8161671b2462&displaylang=en

There is one there for the firewall and you can modify the scripts to check
various registry keys etc. to determine WU status and antvirus settings
(antivirus registry keys are vendor specific so you would need to do some
investigating to determine the exact settings to check for)

-- 
Andy.


Relevant Pages

  • Re: Secure shared web hosting using MAC Framework
    ... run the web server and web users shell in a jail, ... Those rights should have priority on any traditional unix file ... This directive allows you to disable certain functions for security reasons. ... Web users and executed web scripts shouldn't be able to read ...
    (FreeBSD-Security)
  • RE: Techniques for Vulneability discovery
    ... "Art & Science of Computer Security" to be published ... to run scripts and nmap (swell..$2-4k to learn this ... hint hint, E&Y, hint hint.. ... How do experts discover vulnerabilities in a ...
    (Vuln-Dev)
  • RE: Techniques for Vulneability discovery
    ... "Art & Science of Computer Security" to be published ... to run scripts and nmap (swell..$2-4k to learn this ... hint hint, E&Y, hint hint.. ... How do experts discover vulnerabilities in a ...
    (Security-Basics)
  • Re: Cain shows DefaultPassword in plain text - LASS writes it
    ... Windows should have no need to decrypt the credentials of other users, ... Without physical security, there is no security. ... > I found that LSASS writes the following registry keys whenever I change ... > Removing DefaultPassword and serveral other registry keys under ...
    (microsoft.public.security)
  • Re: Microsoft Strategic Technology Protection Program
    ... servers and workstations through GPOs. ... that it's impossible for users to inadvertently execute worm scripts. ... and other security patches using startup scripts written in JScript. ...
    (NT-Bugtraq)