Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Secure by Default
Tim Mullen, 2003-04-27

With Windows Server 2003, Microsoft has finally produced an operating system that isn't begging to be hacked on the first boot.

Comments Mode:
Secure by Default - READ BEFORE YOU POST. 2003-04-28
Anonymous (2 replies)
Secure by Default - READ BEFORE YOU POST. 2003-04-28
Anonymous (1 replies)
Secure by Default - READ BEFORE YOU POST. 2003-04-29
Anonymous (2 replies)
Secure by Default - READ BEFORE YOU POST. 2003-04-30
Anonymous (2 replies)
Secure by Default - READ BEFORE YOU POST. 2003-05-01
Anonymous (3 replies)
Secure by Default - READ BEFORE YOU POST. 2003-05-02
Penguinisto (1 replies)
Secure by Default - Learn something (before you reply again). 2003-05-06
Anonymous (1 replies)
"2) IPSec encrypts packets (mostly for VPN nets*), and does not "secure services" (else that nasty ol' Messenger Service spam would've been dealt with a long time ago by simply using IPSec instead of registry hacks, eh?) I'm also curious about this new and mysterious "protocol layer" you mention as well."

LMFAO, uhm yes IPSec DOES secure services, this shows how clueless you are. IPSec is not just for encryption, it is also port management (somewhat like iptables). I'm not going to waste too much time on this but to make it simple for you, you can block requests to specified ports, ips, etc. Take some time one day and create your own IPSec security rule - you'll see the traffic management options there for you.

"It would be fun to see how basic Win2k/3 security involves securing Exchange when most folks use a real mail server instead... "

Like sendmail right? There are not that many vulnerabilities for Exchange... so I'm not sure where you are getting this from (perhaps, your mind?).

"I'll believe that IIS is finally somewhat secure when all the infected IIS box out there quit polluting my Apache logs with Nimda scans."

Sure, blame worms on the web server type - not incompetent admins like yourself who can't properly configure IIS (i.e. see remove scripts and keep patched for starters).


As for everything else you mentioned, I'm not going to bother responding to it because I don't feel you are capable of understanding... I thought you were somewhat intelligent but apparently I was mistaken. But, what do you expect from a *nix admin, I guess.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/157/19798#19798
Secure by Default, Insecure by Birth 2003-04-28
Drek Software Inc. (2 replies)
Secure by Default, Insecure by Birth 2003-05-03
Anonymous (2 replies)
Secure by Default 2003-04-28
alexbal
Secure by Default 2003-04-28
Anonymous
Secure by Default 2003-04-28
xenophi1e <oliver.lavery@sympatico.ca> (1 replies)
Well, I'll give you this much, Timster... 2003-04-28
Penguinisto (4 replies)
Well, I'll give you this much, Timster... 2003-04-28
Anonymous (6 replies)
Well, I'll give you this much, Timster... 2003-04-29
Anonymous (2 replies)
Well, I'll give you this much, Timster... 2003-04-29
Penguinisto (1 replies)
Well, I'll give you this much, Timster... 2003-05-03
Anonymous (1 replies)
Well, I'll give you this much, Timster... 2003-04-29
xenophi1e <oliver.lavery@sympatico.ca>
Well, I'll give you this much, Timster... 2003-04-29
Anonymous (2 replies)
Zealotry comes in all forms. 2003-04-29
matt@beatlab.org (2 replies)
Zealotry comes in all forms. 2003-04-29
blacklight (1 replies)
Zealotry comes in all forms. 2003-05-02
Penguinisto
Zealotry comes in all forms. 2003-05-06
Noran Rad
Well, I'll give you this much, Timster... 2003-04-30
Anonymous (1 replies)
Secure by Default 2003-04-29
blacklight
Secure by Default (Pathetic) 2003-04-29
Anonymous (3 replies)
Secure by Default (Pathetic) 2003-04-30
Th. Klein
Secure by Default (Pathetic) 2003-05-02
blacklight (2 replies)
Secure by Default (Pathetic) 2003-05-02
Anonymous
Secure by Default (Pathetic) 2003-05-03
Anonymous
Secure by Default 2003-04-29
Anonymous (1 replies)
Secure by Default 2003-04-29
Doug Sibley (3 replies)
Secure by Default 2003-04-29
Anonymous
Secure by Default 2003-04-30
Anonymous
Secure by Default 2003-05-03
Anonymous
Secure by Default 2003-04-29
Anonymous (1 replies)
Secure by Default 2003-05-01
Anonymous
Hrm 2003-04-30
DC0 (1 replies)
Hrm 2003-05-02
Ryan Lambert
Secure by Default 2003-05-02
Ryan Lambert







 

Privacy Statement
Copyright 2009, SecurityFocus