How to Prepare for Microsoft Certifications Earning a Microsoft Certification could be the beginning or continuation of an enduring career that will include the strengthening of their technical skills, collaboration with other professionals ...

Readmore

Prometric offers vouchers of up to 25% off ... Hello people, I just received an email from Prometric informing a discount of up to 25% on Microsoft Certifications. The promotion is valid until December 31, 2009 or even last for the ...

Readmore

50% discount on Microsoft Certifications to ... Hello guys, Prometric is providing for students a 50% discount on Microsoft certifications. The promotion is valid until June 30, 2010. For more details visit the ...

Readmore

Book - Administration and Maintenance Environment ... Hello people, For those who are preparing for the exam 70-290 book Administration and Maintenance Environment Microsoft Windows Server 2003 is a great material. I recommend.

Readmore

Prometric offers vouchers of up to 25% off ... Hello people, I just received an email from Prometric informing a discount of up to 25% on Microsoft Certifications. The promotion is valid until December 31, 2009 or even last for the ...

Readmore

twitter

Twitter Facebook

Vulnerability Alert - FTP Server in Windows 2000, XP and 2003

Category: Security , Windows 7 , Windows Server 2008 , Windows Vista

Microsoft announced yesterday (1st September) the Security Advisory 975191 on a vulnerability in the service FTP (File Transfer Protocol) Internet Information Server 5.0, 5.1 and 6.0. This vulnerability allows an attacker to execute remote code with administrator permission on systems that are running these versions of the FTP service and where the attacker has write access.

The vulnerable versions of the FTP service are found in Windows 2000 Server, Windows XP and Windows Server 2003, and in the last two this service is not installed by default. In no case the FTP service is installed with anonymous users with write permission. Newer versions of Windows (Vista, Server 2008 and Windows 7 ) are not affected.

Microsoft is actively working on a fix for this vulnerability. While a fix is ​​not available if you use the FTP service in the versions mentioned you can protect yourself by adopting one of the following measures:

Disable the creation of new directories for the FTP service - The vulnerability is exploited by the attacker listing a folder name specially crafted FTP service, you can protect yourself and prevent the creation of new directories in the area used for this service using the NTFS permissions :

1. Go to the root folder of your FTP service (by default% systemroot% \ inetpub \ ftproot).
2. Right-click on the folder and select Properties.
3. Select the Security tab and click Advanced.
4. Click Change permissions.
5. Select each user group and click Edit.
6. Uncheck Create Folders / Append Data.

Note that ordinary users will no longer have permissions to create new folders using the FTP service, but still be able to write files in folders.

■ Do not allow writing files via FTP service - No writable FTP vulnerability can not be exploited. Anonymous users by default no longer have write permission, and you can remove permission for all users by editing the service properties as shown below:

image thumb Alerta de Vulnerabilidade – Servidor FTP no Windows 2000, XP e 2003

Disable the FTP service - The FTP service is installed by default in Windows 2000 Server. If you do not need this service, you can disable it by following the steps in article 321141 .

Microsoft also recommends that all users keep their software antivirus active and updated, and if they use system for detecting and preventing network attacks that they update their software. For software snort rules to detect this attack are already available in http://www.snort.org/vrt/docs/ruleset_changelogs/changes-2009-09-01.html .

More information about this vulnerability are available (in English) on the blogs of the Microsoft Security Response Center and the Microsoft Security Research and Defense .

Installing Service Pack 2 on Windows Server 2008

Category: Articles , TechNet WIKI , Windows Server 2008

Goal

This article aims to demonstrate how to install Service Pack 2 on Windows Server 2008 quickly and easily.

Applies to

  • Windows Server 2008 all versions.

Read the full article at: http://social.technet.microsoft.com/wiki/contents/articles/2423.aspx

Luciano Lima
[Enterprise Security MVP] - [MCSA Security] - [Security MCSE]


www.guiamcitp.com.br
www.ticlassificados.com (New)

Configuring the Security Configuration Wizard (SCW) in Windows Server 2008

Category: Articles , Security , Windows Server 2008

Goal

This article aims to demonstrate how to perform the configuration of the Security Configuration Wizard (SCW) in Windows Server 2008 .

Applies to

  • Windows Server 2008 all versions.

Introduction

With the Security Configuration Wizard (SCW), you can reduce the attack surface of the PC s running Windows Server 2008 by customizing the security settings.

What is SCW?

SCW guides you through the process of creating, editing, applying, or removing a security policy. It provides an easy way to create or modify a security policy for your server based on its role. You can use Group Policy to apply security policies to multiple servers that perform the same function. You can also use the SCW to do a rollback of a security policy. With SCW, you can compare the security settings of a server with a security policy you want to check the possible vulnerability 's settings on the server.

Note

A security policy created with SCW on a computer running Windows Server 2008 can be applied only to computers running Windows Server 2008 . SCW can not be used with client operating systems or Windows Small Business Server.

 

Installation

SCW is installed automatically with Windows Server 2008 is not necessary any action by the administrator. The installation also includes the SCW command line tool Scwcmd.

 

Creating a security policy with SCW

To start creating an SCW security policy follow the steps below:

1 - Click Start, All Programs, Administrative Tools and select Security Configuration Wizard. It will carry a window as shown in Figure 1.1.

figura1 Configurando o Security Configuration Wizard (SCW) no Windows Server 2008

Figure 1.1

2 - Click the Next button to continue. Carries a window will be as shown in Figure 1.2.

figura2 Configurando o Security Configuration Wizard (SCW) no Windows Server 2008

Figure 1.2

3 - On the Configuration Action window you have the options to create a new security policy, edit an existing security policy, apply an existing security policy or to roll back the last applied security policy. In our example we choose the Create a new security policy to create a new security policy. Then click the Next button to continue. Carries a window will be as shown in Figure 1.3.

figura3 Configurando o Security Configuration Wizard (SCW) no Windows Server 2008

Figure 1.3

4 - In the Select Server window you select the server that will be used as a baseline to create the security policy. You can select the server by DNS name, NetBIOS name or IP address. In our example we will use the local server with the name WIN-X9E5TL3GBSF. After selecting the server click the Next button to continue. Carries a window will be as shown in Figure 1.4.

figura4 Configurando o Security Configuration Wizard (SCW) no Windows Server 2008

Figure 1.4

5 - In the Processing Security Configuration Database window you have the option of viewing the configuration database, which contains information about server roles, client features, administration options, services, windows firewall and other settings. Click the View Configuration Database for details. Carries a window will be as shown in Figure 1.5.

figura5 Configurando o Security Configuration Wizard (SCW) no Windows Server 2008

Figure 1.5

6 - Click the links in the window above for more details spare the server roles, client features, administration options, services and windows firewall. After consulting with the options mentioned above close the SCW Viewer and then in the wizard window SCW. On the Processing Security Configuration Database window click the Next button to continue. Carries a window will be as shown in Figure 1.6.

figura6 Configurando o Security Configuration Wizard (SCW) no Windows Server 2008

Figure 1.6

7 - From this point you should be careful with the answers you will provide to the wizard SCW, because if you answer the questions incorrectly services or features may be disabled or enabled improperly. Make sure you have the necessary knowledge about the roles of servers that will receive this security policy so you do not cause any downtime in your production environment. Therefore, always take the tests in environmental approval. Click the Next button to continue. Carries a window will be as shown in Figure 1.7.

figura7 Configurando o Security Configuration Wizard (SCW) no Windows Server 2008

Figure 1.7

8 - In the Select Server Roles you have the option to enable or disable the server roles that you receive the security policy. Based on your choice services and ports are enabled. On the View menu you have options:

  • All roles (displays all roles available for configuration).
  • Installed roles (displays all roles installed).
  • Uninstalled roles (displays all roles uninstalled).
  • Selected roles (displays all selected papers).

In our example we'll select the roles File Server and Print Server and then choose the Selected roles. The Select Server Roles window will look similar to Figure 1.8.

figura8 Configurando o Security Configuration Wizard (SCW) no Windows Server 2008

Figure 1.8

9 - Click Next to continue. Carries a window will be as shown in Figure 1.9.

figura9 Configurando o Security Configuration Wizard (SCW) no Windows Server 2008

Figure 1.9

10 - In the Select Client Features you have the option to enable or disable the features of client server that will receive the security policy, because the servers also act as clients. Based on your choice services and ports are enabled. On the View menu you have options:

  • All roles (displays all roles available for configuration).
  • Installed roles (displays all roles installed).
  • Uninstalled roles (displays all roles uninstalled).
  • Selected roles (displays all selected papers).

In our example we will select the client features: Background Intelligent Transfer Service (BITS), DNS Client, Domain Member, Microsoft Networking Client, Network Discovery, Time Synchronization, Windows Update, and then choose Selected roles. The Select Server Roles window will look like Figure 1.10.

figura10 Configurando o Security Configuration Wizard (SCW) no Windows Server 2008

Figure 1.10

11 - Click Next to continue. Carries a window will be as shown in Figure 1.11.

figura11 Configurando o Security Configuration Wizard (SCW) no Windows Server 2008

Figure 1.11

12 - In the Select Administration and Other Options select options and other administration. On the View menu you have options:

  • All options (displays all available options for configuration).
  • Installed options (displays all installed options).
  • Uninstalled options (displays all options uninstalled).
  • Selected options (displays all the selected options).
  • Remote Administration options (displays all the options for remote administration).
  • Domain Member options (options displays all domain members).
  • Background Intelligent Transfer Service (BITS) options (displays all options BITS).
  • Microsoft Networking Client options (all options displays the Client for Microsoft Networks).
  • Volume Shadow Copy options (options displays all of the Volume Shadow Copy).

In our example we'll select the options Browse Master, Local Application Installation, Microsoft Fibre Channel Platform Registration Service, Offline Files, Remote Desktop and then choose Selected options. Window Select Administration and Other Options will look like Figure 1.12.

figura12 Configurando o Security Configuration Wizard (SCW) no Windows Server 2008

Figure 1.12

13 - Click Next to continue. Carries a window will be as shown in Figure 1.13.

figura13 Configurando o Security Configuration Wizard (SCW) no Windows Server 2008

Figure 1.13

14 - In the Select Additional Services is informing the additional services that are installed on the server. In our example, how we are using a virtual machine Virtual Machine Additions Services Application Services and Virtual Machine Addtions Shared Folder Service are listed. Depending on the configuration of your server will be listed and other services you need to decide if this service will be present in your security policy. Make your picks and then click the Next button to continue. Carries a window will be as shown in Figure 1.14.

figura14 Configurando o Security Configuration Wizard (SCW) no Windows Server 2008

Figure 1.14

15 - On the Handling Unspecified Services window you define the treatment of unexpected services that are not listed on the selected server and are not listed in database security configuration. You have two options:

  • Do not change the startup mode of the service
  • Disable the service

In our example we will select the Disable the service and then click Next to continue. Carries a window will be as shown in Figure 1.15.

16 - On the Confirm Service Changes window displays a list of services in its current state and how they will look after the security policy is applied. Before continuing, confirm that the changes are correct services to meet the roles that your server will perform. Click the Next button to continue. Carries a window will be as shown in Figure 1.16.

15 - On the Handling Unspecified Services window you define the treatment of unexpected services that are not listed on the selected server and are not listed in database security configuration. You have two options:

  • Do not change the startup mode of the service
  • Disable the service

In our example we will select the Disable the service and then click Next to continue. Will load a window as shown in Figure 1.15.

figura15 Configurando o Security Configuration Wizard (SCW) no Windows Server 2008

Figure 1.15

16 - On the Confirm Service Changes window displays a list of services in its current state and how they will look after the security policy is applied. Before continuing, confirm that the changes are correct services to meet the roles that your server will perform. Click the Next button to continue. Carries a window will be as shown in Figure 1.16.

figura18 Configurando o Security Configuration Wizard (SCW) no Windows Server 2008

Figure 1.16

17 - In the Network Security section you can set the rules for Windows Firewall with Advanced Security based on rules and administrative options. If you do not want to set up this section just select the Skip this section and then click the Next button. In our example we'll skip this section. Carries a window will be as shown in Figure 1.17.

figura17 Configurando o Security Configuration Wizard (SCW) no Windows Server 2008

Figure 1.17

18 - In the Registry Settings section you have the option to configure protocos to be used for communication with other computers. If you do not want to set up this section just select the Skip this section and then click the Next button. In our example we'll skip this section. Carries a window will be as shown in Figure 1.18.

figura18 Configurando o Security Configuration Wizard (SCW) no Windows Server 2008

Figure 1.18

19 - Audit Policy section you have the option to configure the audit policy for the server. If you do not want to set up this section just select the Skip this section and then click the Next button. In our example we will configure this section. Carries a window will be as shown in figure 1.19.

figura19 Configurando o Security Configuration Wizard (SCW) no Windows Server 2008

Figure 1.19

20 - In the System Audit Policy window select one of three options:

  • Do not audit (this option does not perform any audit).
  • Audit successfull activities (this option audits successfully settings changes to the system and configured for audit files).
  • Audit and unsuccessfull succefull activities (this option audits configuration changes with success and failure for the system and configured for audit files).

In our example, select the Audit succefull unsuccessfull and Activities and then click Next. Carries a window will be as shown in Figure 1.20.

figura20 Configurando o Security Configuration Wizard (SCW) no Windows Server 2008

Figure 1.20

21 - Audit Policy Summary In the window you have an overview of the current audit settings and audit settings as the following will apply the security policy. Before continuing, confirm that the audit settings are correct and then click Next. Carries a window will be as shown in Figure 1.21.

figura21 Configurando o Security Configuration Wizard (SCW) no Windows Server 2008

Figure 1.21

22 - On the Save Security Policy section you can save the security policy that you created and also apply the security policy for the selected server now, or apply for another server later. Click the Next button to continue. Carries a window will be as shown in Figure 1.22.

figura22 Configurando o Security Configuration Wizard (SCW) no Windows Server 2008

Figure 1.22

23 - In the Security Policy File Name window you define the name of security policy and a description to identify the policy. You also have the option to view the security policy by clicking the View Security Policy and include a security template by clicking the Include Security Templates. Define a name and description for your security policy and then click Next. Carries a window will be as shown in Figure 1.23.

figura23 Configurando o Security Configuration Wizard (SCW) no Windows Server 2008

Figure 1.23

24 - On the Apply Security Policy window you have the option of applying the security policy for the selected server now or later. In our example we apply now. Apply now Select and then click Next. After the security policy will be applied carries a window as shown in Figure 1.24.

figura24 Configurando o Security Configuration Wizard (SCW) no Windows Server 2008

Figure 1.24

25 - Applying Security Policy In the window click the Next button. Carries a window will be as shown in Figure 1.25.

figura25 Configurando o Security Configuration Wizard (SCW) no Windows Server 2008

Figure 1.25

In the window Completing the Security Configuration Wizard SCW is informed that it has successfully closed. It is also reported where the security policy has been saved and that to apply the same security policy to other servers just run the wizard again. Click the Finish button to finish.

Luciano Lima
[Enterprise Security MVP] - [MCSA Security] - [Security MCSE]

www.ticlassificados.com (New)
www.guiamcse.com.br
www.guiamcse.com.br / forum (new)
www.guiamcitp.com.br
www.guiacissp.com.br
www.guiacissp.com.br / forum (new)

pixel Configurando o Security Configuration Wizard (SCW) no Windows Server 2008