RE: Newbie General Security Question



On Wed, 14 Dec 2005 11:23:14 -0800, Robarb wrote:

> Thanks for the response. I think I'm actually asking a bigger question.
> If I were to do the maximum I can do (like getting rid of the everyone
> group for my data drive), how secure is SBS? Has a hacker over the
> internet ever gotten through an ISA firewall (without the aid of an
> internal virus, etc.) and accessed data on a drive on the server without
> having an authorized password? If the server is healthy and uninfected in
> any way, has the 'permission' system proven to be completely secure?

The 'security' of your server from the outside depends on how many
services you publish to the internet.

To be really (but never totally) secure:

Ditch the idea of running a website on SBS - put it elsewhere.

Incoming SMTP could be handled by queueing it at your ISP and getting it
via ETRN.

Disable internet access to OWA, RWW, VPN etc.

That way if you have no ports open, they can't be exploited.

But that still leaves ways of being compromised from users inside the LAN
- eg malware, browser exploits etc etc.

Nothing is ever 100% secure - server admins make value judgement of how
the value of a service compares to the risk of providing it. Everything is
a tradeoff - most places would be happy leaving certain services open to
the internet provided they were properly configured and maintained.

--
Cheers
Anton

.



Relevant Pages

  • RE: Help with Internet and Email wizard
    ... Thank you for posting in the SBS newsgroup. ... On SBS Server, run the CEICW, go through "Connection Type" page, on ... Since we don't want to set up an external internet access, ... We can select Option one "Create a new Web server certificate" to ...
    (microsoft.public.windows.server.sbs)
  • Re: Urgent! New router and big disaster
    ... Set the 'external' interface of SBS to get it's IP via DHCP from the router ... If the ws does not get an IP from DHCP check the event log on the server, ... They can go one day with out internet, ...
    (microsoft.public.windows.server.sbs)
  • Re: ICMP error when trying to access OWA on SBS 2003 Premium
    ... The Default Web Site is set to listen on the internal IP of the SBS server ... OWA publish rule or IIS manually. ... entire Web site from the Internet" is selected. ...
    (microsoft.public.windows.server.sbs)
  • Re: SBS 2003 IIS BASED SERVICES FAIL INTERMITTENTLY
    ... If I read your post correctly, you have a switch where the SBS ... Run DHCP server on your SBS, and set all client machine nics to dynamic. ... Once you have your nics configured, run the Connect to the Internet wizard, ... QUESTION1 - what is REFUSING CONNECTIONS? ...
    (microsoft.public.windows.server.sbs)
  • RE: Best way to handle SBS 2003 users who are permanently remote
    ... SBS remote users acces internal resource of the SBS network. ... Internet Connection Wizard -> Configure Remote Access), ... VPN server and when remote users VPN to the SBS network, ...
    (microsoft.public.windows.server.sbs)