Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Secure by Default
Tim Mullen, 2003-04-27

With Windows Server 2003, Microsoft has finally produced an operating system that isn't begging to be hacked on the first boot.

Comments Mode:
Secure by Default - READ BEFORE YOU POST. 2003-04-28
Anonymous (2 replies)
Secure by Default - READ BEFORE YOU POST. 2003-04-28
Anonymous (1 replies)
Secure by Default - READ BEFORE YOU POST. 2003-04-29
Anonymous (2 replies)
Secure by Default - READ BEFORE YOU POST. 2003-04-30
Anonymous (2 replies)
Secure by Default - READ BEFORE YOU POST. 2003-05-01
Anonymous (3 replies)
Secure by Default - READ BEFORE YOU POST. 2003-05-02
Anonymous
=================================
Uhm, actually, I am a network administrator for a company of 150 users (Toronto) and 58 (Montreal) and I have never seen an MCSE study book in my life.
=================================

Most of my experience is on Wall Street, and financial houses have quite a bit more users than 208. Not that any of that means anything in this discussion.




=================================
Now, the things I listed above are the basic requirements for setting up a secure Windows 2000/3 AD environment, and I (and my team) have implemented all of these measures. Not being a windows administrator, this may sound like really complex stuff for you, but its really the basics.
=================================

I've administered NT 3.51/4.0 systems and you're right, it is the basics. But take your "How would you configure your domain trusts..." question; is that a one-size fits all configuration, or do you take into consideration actual business requirements?

I haven't touched a production Windows server since about 1997, but if I were configuring a trust relationship between two divisions I'd set it up differently than a trust relationship with a business partner. Also the sensitivity of data would dictate, wouldn't it? You wouldn't want M&A data to float out to a domain that doesn't have users authorized to view that data, would you?




=================================
Anyone with any experience would have an answer to the questions (one liners, I'm not expecting a speech).
=================================

Wow, if one line answers are all that's required to keep anything secure, I'm going back to operations!


[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/157/19750#19750
Secure by Default, Insecure by Birth 2003-04-28
Drek Software Inc. (2 replies)
Secure by Default, Insecure by Birth 2003-05-03
Anonymous (2 replies)
Secure by Default 2003-04-28
alexbal
Secure by Default 2003-04-28
Anonymous
Secure by Default 2003-04-28
xenophi1e <oliver.lavery@sympatico.ca> (1 replies)
Well, I'll give you this much, Timster... 2003-04-28
Penguinisto (4 replies)
Well, I'll give you this much, Timster... 2003-04-28
Anonymous (6 replies)
Well, I'll give you this much, Timster... 2003-04-29
Anonymous (2 replies)
Well, I'll give you this much, Timster... 2003-04-29
Penguinisto (1 replies)
Well, I'll give you this much, Timster... 2003-05-03
Anonymous (1 replies)
Well, I'll give you this much, Timster... 2003-04-29
xenophi1e <oliver.lavery@sympatico.ca>
Well, I'll give you this much, Timster... 2003-04-29
Anonymous (2 replies)
Zealotry comes in all forms. 2003-04-29
matt@beatlab.org (2 replies)
Zealotry comes in all forms. 2003-04-29
blacklight (1 replies)
Zealotry comes in all forms. 2003-05-02
Penguinisto
Zealotry comes in all forms. 2003-05-06
Noran Rad
Well, I'll give you this much, Timster... 2003-04-30
Anonymous (1 replies)
Secure by Default 2003-04-29
blacklight
Secure by Default (Pathetic) 2003-04-29
Anonymous (3 replies)
Secure by Default (Pathetic) 2003-04-30
Th. Klein
Secure by Default (Pathetic) 2003-05-02
blacklight (2 replies)
Secure by Default (Pathetic) 2003-05-02
Anonymous
Secure by Default (Pathetic) 2003-05-03
Anonymous
Secure by Default 2003-04-29
Anonymous (1 replies)
Secure by Default 2003-04-29
Doug Sibley (3 replies)
Secure by Default 2003-04-29
Anonymous
Secure by Default 2003-04-30
Anonymous
Secure by Default 2003-05-03
Anonymous
Secure by Default 2003-04-29
Anonymous (1 replies)
Secure by Default 2003-05-01
Anonymous
Hrm 2003-04-30
DC0 (1 replies)
Hrm 2003-05-02
Ryan Lambert
Secure by Default 2003-05-02
Ryan Lambert







 

Privacy Statement
Copyright 2009, SecurityFocus