OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Steve Robinson (sfrmediaone.net)
Date: Fri Feb 01 2002 - 09:53:29 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to
    majordomoiss.net Contact issforum-owneriss.net for help with any problems!
    ----------------------------------------------------------------------------

    All,

    I just ran Internet Scanner 6.21 against a new Windows 2000 server with
    Active Directory. One of the results was that there were to many users with
    Backup Files and Directories Privileges. The additional user was Server
    Operator. Is there any way to add this into the users that ISS detects?

    Also, after the first run I discovered that both Echo and Chargen ports were
    enabled. When I reviewed the ISS policy for NT Web Server I found that these
    checks were not turned on by default, understandable as these are more for
    Unix than NT. Can anyone explain why would these unnecessary services were
    added? They have registry entries that have to be disabled in order to shut
    them off (Change a 1 to a 0). I have not done any testing to see if any
    other 2000 products have them enabled.

    Steve