OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
RE: Windows/Exchange security auditing tool

From: Bourque Daniel (Daniel.Bourqueloto-quebec.com)
Date: Sun Sep 05 2004 - 15:13:37 CDT


 What about using a reverse Proxy in the DMZ to keep OWA inside?
Better, keep the OWA server inside isolate with access list so it can only
talk to the DC and the Exchange server?

I think you should look at Microsoft ISA server for that role or use
dedicated box like Ciphertrust Ironmail.

-----Message d'origine-----
De: Chad Lorenc
A: focus-mssecurityfocus.com
Date: 9/2/2004 6:00 PM
Objet: RE: Windows/Exchange security auditing tool

I have a quick question, we are rolling out exchange 2003 with OWA. Our
OWA server sits one of our DMZ's, because of the active directory
component the engineers state that OWA must be a part of our internal AD
domain. We currently do not have any servers bridging the internal AD
domain into the DMZ's.

Is there anyway around this requirement?
How significant of a risk does this create, or more importantly are the
feasible exploits past information probing?

We do have multiple layers of protection such as two factor
authentication (AD login + random authenticator), host monitoring,
firewall rules, VLAN's etc. I am just curious, on its own, what kind of
risk we assume with this design.

Chad Lorenc

DISCLAIMER:
The information contained in this email and in any attachments is
intended for the person or entity to which it is addressed and may
contain confidential and/or privileged material. If you have received
this email in error, please notify us immediately by replying to the
message and delete the email from your computer. Use of this information
by persons or entities other than the intended recipient is prohibited.

------------------------------------------------------------------------
---
------------------------------------------------------------------------
---

---------------------------------------------------------------------------
---------------------------------------------------------------------------