Re: Failed login attempts, anything else I can do?



Homer Jay wrote:

Recently I have started noticing failed login attempts to my server, these
are the usual attemps at trying to login with various usernames (local,
consumer, admin etc). I am not hugely stressed over these as I believe
that since I can see them as failed, the hacker is not able to get into
the server.

But, I am wondering if there is anything else I can do to secure the
server. I have changed the admin name, the only services/ports that are
open are ones needed for RWW, OWA etc, I have it set to lock users after 3
failed logins, turned on auditing and implemented a (hopefully) pretty
decent password policy (although I need to do some user educating on
this).

Are there any others tips/tricks that I can use to help make my server
just that bit extra secure?

Thanks.
Do you know if the attempts are internal or external?
What type of perimeter security do you have? ISA Installed?Hardware
firewall?
Also make sure your password complies with the complex guidelines, add a
little bit to that as suggested in the past threads here, something like 15
characters. Firefox has a nice extension called secure password which can
generate some nice passwords.

--
:-)
.



Relevant Pages

  • Re: getting me ducks in a row - concepts
    ... Don't create local login accounts for users, ... >> admin types know the local administrator credentials on all PCs. ... You don't load QB on the server - the registry keys or files/folders would ...
    (microsoft.public.windows.server.sbs)
  • Re: Secure host newbie - fun - humm
    ... decision, as the admin, whether or not to take down the server. ... Listen, as a security specialist, I *know* that every single box that I, ... some level of risk and that there is no "100% I'm secure" level. ...
    (Security-Basics)
  • Public Authentication Problem on Batch Job using SCP2 when SSH Client Reboot
    ... to a SSH server, HOST2. ... for secure ftp login. ... The login ID is a local user account ... we found that scp2 run failed every time the SSH client ...
    (comp.security.ssh)
  • Re: Failed login attempts, anything else I can do?
    ... are the usual attemps at trying to login with various usernames (local, ... the server. ... I am wondering if there is anything else I can do to secure the ... I have changed the admin name, ...
    (microsoft.public.windows.server.sbs)
  • RE: Linked server issue
    ... SQL Server logins to the Admin account of the Access database. ... Add a new linked server using SQL Server Enterprise Manager. ... Remote login: Admin ...
    (microsoft.public.sqlserver.tools)