Re: [ActiveDir] How Secure is a Domain Controller?

2006-04-30 Thread Al Mulnick
-Weidner *Sent:* 05 March 2006 08:35 *To:* ActiveDir@mail.activedir.org mailto:ActiveDir@mail.activedir.org *Subject:* RE: [ActiveDir] How Secure is a Domain Controller? I've written down some related thoughts once: http://msmvps.com/blogs/ulfbsimonweidner/archive/2004/10

RE: Re: [ActiveDir] How Secure is a Domain Controller?

2006-04-30 Thread Jef Kazimer
I'm really interested to see how this pans out. Date: Sun, 30 Apr 2006 12:33:45 -0400 From: [EMAIL PROTECTED] To: ActiveDir@mail.activedir.org Subject: Re: [ActiveDir] How Secure is a Domain Controller? The answer to that last isn't terribly difficult. Just ask yourself what

RE: Re: [ActiveDir] How Secure is a Domain Controller?

2006-04-30 Thread Jef Kazimer
: [ActiveDir] How Secure is a Domain Controller? Date: Sun, 30 Apr 2006 11:44:55 -0500 Thishasbeenmakingtheroundsasoflate,soIamnotsureifithasbeenpostedhere: SecurityMythsandPasswordsbyProf.Spafford andsomethingfrom2002: TenWindowsPasswordMyths Now...whereIam

RE: [ActiveDir] How Secure is a Domain Controller?

2006-04-28 Thread joe
] [mailto:[EMAIL PROTECTED] On Behalf Of Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP] Sent: Monday, April 03, 2006 10:06 PM To: ActiveDir@mail.activedir.org Subject: Re: [ActiveDir] How Secure is a Domain Controller? Sorry one more thing.. in a Center for Internet Security project to set Baseline

Re: [ActiveDir] How Secure is a Domain Controller?

2006-04-04 Thread Al Mulnick
:* RE: [ActiveDir] How Secure is a Domain Controller?I've written down some related thoughts once: http://msmvps.com/blogs/ulfbsimonweidner/archive/2004/10/24/16568.aspx Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book Windows XP - Die Expertentipps: http://tinyurl.com/44zcz Weblog: http

Re: [ActiveDir] How Secure is a Domain Controller?

2006-04-03 Thread Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP]
2006 08:35 *To:* ActiveDir@mail.activedir.org mailto:ActiveDir@mail.activedir.org *Subject:* RE: [ActiveDir] How Secure is a Domain Controller? I've written down some related thoughts once: http://msmvps.com/blogs/ulfbsimonweidner/archive/2004/10/24/16568.aspx

RE: [ActiveDir] How Secure is a Domain Controller?

2006-04-03 Thread Steve Linehan
Ebitz - SBS Rocks [MVP] Sent: Monday, April 03, 2006 9:06 PM To: ActiveDir@mail.activedir.org Subject: Re: [ActiveDir] How Secure is a Domain Controller? Sorry one more thing.. in a Center for Internet Security project to set Baseline Operational Security Standards for protecting sensititive data

RE: [ActiveDir] How Secure is a Domain Controller?

2006-04-02 Thread joe
To: ActiveDir@mail.activedir.org Subject: Re: [ActiveDir] How Secure is a Domain Controller? Myrick, Todd (NIH/CC/DNA) [E] wrote: Okay for you Susan, I will modify my statement... Add IPsec filter that only allows http traffic to update.microsoft.com. Also, in the future MS will probably bake

Re: [ActiveDir] How Secure is a Domain Controller?

2006-04-02 Thread Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP]
] [mailto:[EMAIL PROTECTED] On Behalf Of Al Lilianstrom Sent: Tuesday, March 07, 2006 8:18 AM To: ActiveDir@mail.activedir.org Subject: Re: [ActiveDir] How Secure is a Domain Controller? Myrick, Todd (NIH/CC/DNA) [E] wrote: Okay for you Susan, I will modify my statement... Add IPsec filter

RE: [ActiveDir] How Secure is a Domain Controller?

2006-04-02 Thread Brian Desmond
] [mailto:ActiveDir- [EMAIL PROTECTED] On Behalf Of Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP] Sent: Sunday, April 02, 2006 4:49 PM To: ActiveDir@mail.activedir.org Subject: Re: [ActiveDir] How Secure is a Domain Controller? Good thing you don't work at my office. No Kung Pao Chicken has ever been

RE: [ActiveDir] How Secure is a Domain Controller?

2006-04-02 Thread joe
: RE: [ActiveDir] How Secure is a Domain Controller? I know SBS and Datacenter are mutually exclusive, but, being able to talk on the phone and hear the other party while in a datacenter are also mutually exclusive. Thanks, Brian Desmond [EMAIL PROTECTED] c - 312.731.3132 -Original

Re: [ActiveDir] How Secure is a Domain Controller?

2006-03-07 Thread Al Lilianstrom
PROTECTED] Sent: Mon 3/6/2006 2:27 PM To: ActiveDir@mail.activedir.org Subject: Re: [ActiveDir] How Secure is a Domain Controller? Question? On a DC ...why do you need anti spyware? If spyware enters via web browsing and email...and IE should never be used/launched on a DC... why do you need

Re: [ActiveDir] How Secure is a Domain Controller?

2006-03-07 Thread Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP]
From: Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP] [mailto:[EMAIL PROTECTED] Sent: Mon 3/6/2006 2:27 PM To: ActiveDir@mail.activedir.org Subject: Re: [ActiveDir] How Secure is a Domain Controller? Question? On a DC ...why do you need anti spyware? If spyware

RE: [ActiveDir] How Secure is a Domain Controller?

2006-03-06 Thread neil.ruston
: ActiveDir@mail.activedir.orgSubject: RE: [ActiveDir] How Secure is a Domain Controller? I've written down some related thoughts once: http://msmvps.com/blogs/ulfbsimonweidner/archive/2004/10/24/16568.aspx Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book "Windows XP - Die Expertentipps&qu

RE: [ActiveDir] How Secure is a Domain Controller?

2006-03-06 Thread Tim Vander Kooi
as to be using 7 character passwords you are still very insecure. From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of [EMAIL PROTECTED]Sent: Monday, March 06, 2006 2:25 AMTo: ActiveDir@mail.activedir.orgSubject: RE: [ActiveDir] How Secure is a Domain Controller? The use of 20 char

RE: [ActiveDir] How Secure is a Domain Controller?

2006-03-06 Thread neil.ruston
@mail.activedir.orgSubject: RE: [ActiveDir] How Secure is a Domain Controller? Based on the subject of this discussion: if you have those regular users, who can't comprehend or remember a password over 7 characters, signing on to your domain controllers I would say that your domain controllers

RE: [ActiveDir] How Secure is a Domain Controller?

2006-03-06 Thread Tim Vander Kooi
AMTo: ActiveDir@mail.activedir.orgSubject: RE: [ActiveDir] How Secure is a Domain Controller? You mis-understand :) Ulf was suggesting that in order to protect the AD data on a poorly protected DC, that strong passwords should be used that are harder to crack. In the event that the disks were

RE: [ActiveDir] How Secure is a Domain Controller?

2006-03-06 Thread neil.ruston
, March 06, 2006 9:52 AMTo: ActiveDir@mail.activedir.orgSubject: RE: [ActiveDir] How Secure is a Domain Controller? You mis-understand :) Ulf was suggesting that in order to protect the AD data on a poorly protected DC, that strong passwords should be used that are harder to crack. In the event

RE: [ActiveDir] How Secure is a Domain Controller?

2006-03-06 Thread Myrick, Todd \(NIH/CC/DNA\) [E]
, March 06, 2006 11:23 AM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] How Secure is a Domain Controller? I understand/stood what you were saying, just was hoping to bring out a clearer answer for some of the lurker/newbies on the list (of which there are many). And you provided

RE: [ActiveDir] How Secure is a Domain Controller?

2006-03-06 Thread Ulf B. Simon-Weidner
9:25 AMTo: ActiveDir@mail.activedir.orgSubject: RE: [ActiveDir] How Secure is a Domain Controller? The use of 20 char passwords caught my eye. In previous discussions with MS et al, it was suggested that the majority of users would simply repeat a (at most ( 7 char password n times, so as

Re: [ActiveDir] How Secure is a Domain Controller?

2006-03-06 Thread Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP]
*From:* [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] *Sent:* Monday, March 06, 2006 11:23 AM *To:* ActiveDir@mail.activedir.org *Subject:* RE: [ActiveDir] How Secure is a Domain Controller? I understand/stood what you were saying, just was hoping to bring out a clearer answer

RE: [ActiveDir] How Secure is a Domain Controller?

2006-03-06 Thread Myrick, Todd \(NIH/CC/DNA\) [E]
. Todd From: Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP] [mailto:[EMAIL PROTECTED] Sent: Mon 3/6/2006 2:27 PM To: ActiveDir@mail.activedir.org Subject: Re: [ActiveDir] How Secure is a Domain Controller? Question? On a DC ...why do you need anti spyware

RE: [ActiveDir] How Secure is a Domain Controller?

2006-03-05 Thread Ulf B. Simon-Weidner
I've written down some related thoughts once: http://msmvps.com/blogs/ulfbsimonweidner/archive/2004/10/24/16568.aspx Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book "Windows XP - Die Expertentipps": http://tinyurl.com/44zcz Weblog: http://msmvps.org/UlfBSimonWeidner Website:

RE: [ActiveDir] How Secure is a Domain Controller?

2006-03-05 Thread Edwin
To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] How Secure is a Domain Controller? I've written down some related thoughts once: http://msmvps.com/blogs/ulfbsimonweidner/archive/2004/10/24/16568.aspx Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book Windows XP - Die Expertentipps: http

RE: [ActiveDir] How Secure is a Domain Controller?

2006-03-05 Thread Molkentin, Steve
I always find locking the server in a box with the network cable pulled out makes it most secure (as long as I don't lose my keys)... ;) themolk. From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of EdwinSent: Sunday, 5 March 2006 1:17 PMTo:

RE: [ActiveDir] How Secure is a Domain Controller?

2006-03-05 Thread joe
Secure from what? Pick your risks and then make an assessment based on that. I have personally found that a fully patched Domain Controller is not secure from Denial of Service Attacks that involve alarge truckrunning the DC over. May sound extreme but only you can really start to guess

Re: [ActiveDir] How Secure is a Domain Controller?

2006-03-04 Thread Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP]
Boy that's an open question isn't it? Books and white papers have been written on this issue alone. I'd recommend that you grab the Threats and Countermeasures guide and look at the Security Configuration Wizard.

RE: [ActiveDir] How Secure is a Domain Controller?

2006-03-04 Thread deji
See: http://www.cisecurity.org/tools2/win2000/CIS_Win2003_DC_Benchmark_v1.2.pdf Happy reading. Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCT Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the Tomorrow you were worried

RE: [ActiveDir] How Secure is a Domain Controller?

2006-03-04 Thread Tony Murray
] [mailto:[EMAIL PROTECTED] On Behalf Of Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP] Sent: Sunday, 5 March 2006 4:55 p.m. To: ActiveDir@mail.activedir.org Subject: Re: [ActiveDir] How Secure is a Domain Controller? Boy that's an open question isn't it? Books and white papers have been written