NetAdminTools.com
 
Categories:
GNU/Linux | Homebrew designs | Perl | Administration | Backup/Recovery | Bugs/Fixes | Certification | Database | Email | File/Print | Hardware | Information Grab Bag | Interoperability | GNU/Linux ABCs | Monitoring | Name Resolution | Network Services | Networking | Remote Control | Security | Desktop | Web | BSD | Solaris | GIAGD | REALbasic

Last 30 Days | Last 60 Days | Last 90 Days | All Articles | RSS | Hail Support


Categories:
·GNU/Linux
·Homebrew designs
·Perl
·Administration
·Backup/Recovery
·Bugs/Fixes
·Certification
·Database
·Email
·File/Print
·Hardware
·Information Grab Bag
·Interoperability
·GNU/Linux ABCs
·Monitoring
·Name Resolution
·Network Services
·Networking
·Remote Control
·Security
·Desktop
·Web
·BSD
·Solaris
·GIAGD
·REALbasic
·All Categories


Baseline Security Analyzer
Topic: Security   Posted:2002-05-19
Printer Friendly: Print

spacerspacer
Do check out the Baseline Security Analyzer tool from Microsoft. Just download the MSI package from the page and install it with a shortcut on the Desktop (default). We ran it against a fresh Windows 2000 install with just SP2 installed. Here is a screenshot of the results. We are alerted to many security issues. A really cool thing about this tool is that it will explain what is wrong and point you to an article that for further details. Here is a screenshot of the explanation about the restrict anonymous warning. Be careful. Remember the fiasco where Microsoft brought up wehavethewayout.com and it was running FreeBSD? Well, MS changed the site quickly after the embarassing revalation; however, when they brought the site back up on IIS it was down for quite a while. Here is a less biased report. There are two things that come from this. First, you need to secure servers exposed to the Internet (duh!). All speculation, but we don't feel the main problem was hackers when Microsoft brought the site back up. There was no defacement, as far as we are aware, and that would be the first thing somebody would do if they did compromise the server. We suspect, that the reason the site was down so long is that the application of security patches and recommendations made the server inaccessible to users that were not authenticated. Websites, at least this type, are viewed by everyone. If you use some wizard to warn you about security holes and blindly fix them, you could very well break things as well.




Please read our Terms of Use
Microsoft, Windows, Windows XP, Windows 2003, Windows 2000, and NT are either trademarks or registered trademarks of Microsoft Corporation. NetAdminTools.com is not affiliated with Microsoft Corporation. Linux is a registered trademark of Linus Torvalds, and refers to the Linux kernel. The operating system of most distributions that contain the Linux kernel is GNU/Linux. All logos and trademarks in this site are property of their respective owner. Copyright 1997-2008 NetAdminTools.com