Re: Security network audit

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Hi,

you described Disaster recovery plan, but I need security audit, which means
check my server (HW + SW) issues and investigate for black holes, if some
ports are accessible from Internet, how to check port 25 (is it just mail or
someone wich hacking knowledge could entire there....).....

Thnx!



"Coraleigh Miller" <coraleighmiller@xxxxxxxxx> wrote in message
news:OA8W0hcBIHA.1184@xxxxxxxxxxxxxxxxxxxxxxx

Hi Marc,

Also document physical access, such as whether or not your servers are in
a secure room and who has keys to that room. Also if you use backup
media, you could document the process it goes through, such as if its
encrypted or not, if a security company picks it up at the end of the day
for storage, or if it just goes home with you.
Also.. perhaps more of a DR documentation but you could document your
environmental situation in your server room like if you have UPS power
ample for your servers and equiptment, and if there is a proper air
temperature in the room, etc.

Coraleigh Miller


"Marc" <marc@_REMOVE_THIS_> wrote in message
news:eUE1Z3XBIHA.1204@xxxxxxxxxxxxxxxxxxxxxxx
Hi,



I want to create official document for my company (I'm a system
administrator) for currently security status. Can explain somebody
further what should contain that document? As I heard I must check
windows updates on all computers, check for open ports (from outside),
check network traffic through critical ports (25).. What else?



Thnx!






.



Relevant Pages

  • Re: LISTENING, ESTABLISHED, CLOSE_WAIT TCP Ports & UDP Ports?
    ... properties of a process and it will show you what tcp/ip ports and services ... Beyond that I suggest you read the Windows 2003 Server Security Guide to see ...
    (microsoft.public.windows.server.security)
  • Re: Source Code to Filter out WindowsMessenger POP-UPS
    ... > time to get the details I did get about the ports and none ... It does not act as a relay server - at least ... To that I will just add that REAL security - ... > port 80 inbound ...
    (microsoft.public.inetserver.iis.security)
  • Re: Dropping syn+fin replies, but not really?
    ... Now we're required to run external security scans on some of the hosts, and they constantly come back with a "high" or "medium" severity problem: The host replies to TCP packets with SYN+FIN set. ... Since when did "pound ssl proxy" equal "aladdin web server"? ... You can let tcpdump only show specific ports and source/destination ...
    (FreeBSD-Security)
  • Re: DMZ & Security
    ... > yes, deployement price, security level (depending what ... > open ports... ... > case what sense has my DMZ? ... if I have a web server on DMZ that have to access sqlserver database ...
    (microsoft.public.security)
  • Re: OWA in DMZ
    ... security substantially by opening ports that allow malware access into your ... AD and security infrastructure. ... Exchange 2003 server in your DMZ is tantamount to militarizing it. ...
    (microsoft.public.exchange.admin)