Title: Message
Sorry, I don't disclose that kind of information.  Let's just say if you dual-homed a machine and I was scanning your network and found it...  well, it would be a fun time had by all...
 
 


-----Original Message-----
From: MHR(Michael Ross) [mailto:[EMAIL PROTECTED]]
Sent: Tuesday, July 30, 2002 11:43 AM
To: MS-Exchange Admin Issues
Subject: RE: domain

how so?
-----Original Message-----
From: Ely, Don [mailto:[EMAIL PROTECTED]]
Sent: Tuesday, July 30, 2002 10:23 AM
To: MS-Exchange Admin Issues
Subject: RE: domain

Dual-homing is an invite to your internal network...  regardless of gateway or disabling NetBios.
 
 

-----Original Message-----
From: MHR(Michael Ross) [mailto:[EMAIL PROTECTED]]
Sent: Tuesday, July 30, 2002 11:29 AM
To: MS-Exchange Admin Issues
Subject: RE: domain

what if youre dual homed. and your internal nic doesnt have a default gateway assigned to it? and Netbios is disabled on the external nic?
-----Original Message-----
From: Erik Sojka [mailto:[EMAIL PROTECTED]]
Sent: Tuesday, July 30, 2002 10:27 AM
To: MS-Exchange Admin Issues
Subject: RE: domain

True;  I only meant that the attacker doesn't get default or passthru access to other boxes, as one might if all boxes were in the same domain.
-----Original Message-----
From: Ely, Don [mailto:[EMAIL PROTECTED]]
Sent: Tuesday, July 30, 2002 11:15 AM
To: MS-Exchange Admin Issues
Subject: RE: domain

"If that box gets compromised, then the damage is only limited to that box. "
 
Not necessarily...  <VBEG>
 

-----Original Message-----
From: Erik Sojka [mailto:[EMAIL PROTECTED]]
Sent: Tuesday, July 30, 2002 11:19 AM
To: MS-Exchange Admin Issues
Subject: RE: domain

That's a wide open question.  Are you talking for an internal network or just for a DMZ deployment?
 
A box in the DMZ should be in its own separate thing (domain or WG, doesn't matter which).  If that box gets compromised, then the damage is only limited to that box.  The attacker doesn't also get access to the production domain or any other DMZ boxes. 
-----Original Message-----
From: MHR(Michael Ross) [mailto:[EMAIL PROTECTED]]
Sent: Tuesday, July 30, 2002 11:17 AM
To: MS-Exchange Admin Issues
Subject: domain

Can anyone settle a bet?
 
I have a coworker who is saying a workgroup is more secure than a domain, I say its the otherway around.
He is also betting me that any servers setup in your DMZ should be setup in workgoups and not domains...
List Charter and FAQ at:
http://www.sunbelt-software.com/exchange_list_charter.htm
List Charter and FAQ at:
http://www.sunbelt-software.com/exchange_list_charter.htm
List Charter and FAQ at:
http://www.sunbelt-software.com/exchange_list_charter.htm
List Charter and FAQ at:
http://www.sunbelt-software.com/exchange_list_charter.htm
List Charter and FAQ at:
http://www.sunbelt-software.com/exchange_list_charter.htm
List Charter and FAQ at:
http://www.sunbelt-software.com/exchange_list_charter.htm
List Charter and FAQ at:
http://www.sunbelt-software.com/exchange_list_charter.htm
List Charter and FAQ at:
http://www.sunbelt-software.com/exchange_list_charter.htm

Reply via email to