|
|
 |
RE: FN-FORUM Securing win2k for dummies?
date posted 13th December 2001 16:46
This message is in MIME format. Since your mail reader does not understand
this format, some or all of this message may not be legible.
------_=_NextPart_001_01C183F3.FD1296B0
Content-Type: text/plain; charset="iso-8859-1"
First point of call has to be rename cmd.exe to something obsure. Command
prompts can be a backers best friend.
Virus scanner. Get one, install, run a complete scan before doing anything.
You dont know what trojans are on there.
Service packs and hot fixes. Goto the windows update site and grab them
from there but its pointles to do so before a system scan.
Make sure that all your shares are passworded at the very least. Stick to
the replacing o with 0 and I with 1 just to make it a little harder for
them.
That should just about stop 90% of the kiddies... and then you get to deal
with the determined ones. Hope this is of help. If you need any more
advice then feel free to contact me off list.
Mark
-----Original Message-----
From: Rick [Kitty5] [EMAIL REMOVED]
Sent: Thursday, December 13, 2001 1:26 PM
To: [EMAIL REMOVED]
Subject: FN-FORUM Securing win2k for dummies?
Hi all,
One of my clients hosts has just been hacked (running 2k svr). The host is a
Linux guy with little NT experience, which is probably why he failed to
secure the box. Its doubtful my client will want to find a better more
security aware host.
can anyone recommend a step by step guide to locking down win2k that I can
send to the host, essentially enough to keep the kiddies out.
Rick
Kitty5 WebDesign - http://Kitty5.com
POV-Ray News & Resources - http://Povray.co.uk
TEL : +44 (01270) 501101 - FAX : +44 (01270) 251105 - ICQ : 15776037
PGP Public Key
http://pgpkeys.mit.edu:11371/pks/lookup?op=get
&search=0x231E1CEA
Email Disclaimer
The information in this email is confidential and may be legally privileged.
It is intended solely for the addressee. Access to this email by anyone else
is unauthorised.
If you are not the intended recipient, any disclosure, copying, distribution
or any action taken or omitted to be taken in reliance on it, is prohibited
and may be unlawful. When addressed to our clients any opinions or advice
contained in this email are subject to the terms and conditions expressed in
the governing KPMG client engagement letter.
------_=_NextPart_001_01C183F3.FD1296B0
Content-Type: text/html; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
First=20
point of call has to be rename cmd.exe to something obsure. Command=
prompts can be a backers best friend.
Virus=20
scanner. Get one, install, run a complete scan before doing anything. =
You=20
dont know what trojans are on there.
Service packs and hot fixes. Goto the wind=
ows=20
update site and grab them from there but its pointles to do so before a sys=
tem=20
scan.
Make=20
sure that all your shares are passworded at the very least. Stick to =
the=20
replacing o with 0 and I with 1 just to make it a little harder for=20
them.
That=20
should just about stop 90% of the kiddies... and then you get to deal with =
the=20
determined ones. Hope this is of help. If you need any more adv=
ice=20
then feel free to contact me off list.
Mark
-----Original Message-----From: Rick [Kitty5]=20
[EMAIL REMOVED] Thursday, December 13, 2001 1:26=
PMTo: [EMAIL REMOVED] FN-FORUM=
Securing win2k for dummies?
Hi all,
One of my clients hosts has just been hac=
ked=20
(running 2k svr). The host is a Linux guy with little NT experience, which =
is=20
probably why he failed to secure the box. Its doubtful my client will want =
to=20
find a better more security aware host.
can anyone recommend a step by step guide=
to=20
locking down win2k that I can send to the host, essentially enough to keep =
the=20
kiddies out.
Rick
Kitty5 WebDesign - http://Kitty5.comPOV-Ray News & Reso=
urces -=20
http://Povray.co.ukTEL : +44 (01270=
)=20
501101 - FAX : +44 (01270) 251105 - ICQ : 15776037
PGP Public Keyhttp://pgpkeys.mit.edu:11371/pks/lookup?op=3Dget&search=3D0x231E=
1CEA
Email Disclaimer
The information in this email is confidential and may be legally privileged=
.
It is intended solely for the addressee. Access to this email by anyone el=
se
is unauthorised.
If you are not the intended recipient, any disclosure, copying, distributio=
n
or any action taken or omitted to be taken in reliance on it, is prohibited=
and may be unlawful. When addressed to our clients any opinions or advice
contained in this email are subject to the terms and conditions expressed i=
n
the governing KPMG client engagement letter.
------_=_NextPart_001_01C183F3.FD1296B0--
|
 |
|