USA India
Home Articles UserTV Press Releases Dictionary Books Education Careers B-Channels Resources Forums Blogs Classifieds
Friday 29 Aug, 2008 eNewsletter Register Login
My Profile
Harry
Blogs
Today in Blogs
Recent Blogs
Popular Blogs
Most Viewed Blogs
Community Recommended
Blogs by Category
Networking / Security
Communications
Electronics
Hardware
Operating Systems
Software
Programming
Opensource
Database
Internet
Wireless
Mobile Computing
Graphics
Multimedia
Gadgets
Adobe
Apple Mac
Autodesk
Cisco
Citrix
Google
IBM
Microsoft
Oracle
PHP
SUN
Others
 
  Post a Blog blogs Home
Category >> Networking / Security
Black Hat Thyself - SBS 2003
Posted by : Harry | Mon,14 Jul 2008 | 7:18:56
Tags : sbs,smb,harry brelsford
Rating :
Comments (0) Views (163) Email Blog Forums Save to Favourites
More from this user Print Blog Bookmarks
Add to
 

g'day mates - I am harry brelsford, the author of Windows Small Business Server 2003 Best PRactices (the infamous purple book). I amposting up a few pages per day of this book until SBS 2008 ships for all of us SMB consultants, SBSers, and Microsoft Small Business Specialists (SBSC). Enjoy the read!

Today I speak towards black htting thyself including packet sniffing!

harrybbbbb

Harry Brelsford, ceo at smb nation, www.smbnation.com

###

Black Hat Thyself

So, you think you’re an SBS security hot shot? Perhaps you are. One way to validate whether you’re “hot or not” is to black hat yourself on the inside and outside. That’ll tell you exactly how super you are. In a nutshell, you’d download a port scanner such as GFI’s LANGuard Network Security Scanner (www.gfi.com) and run it against yourself. Figure 5-13 shows how such a scan on the internal LAN might look (revealing tons of information) and Figure 5-14 shows how such a scan might look when run over the Internet, showing only the ports you opened via the EICW. (Talk about a great way to validate your work!)

Figure 5-13

Black hattin’ on the inside.

Notes:

 Visit www.microsoft.com/technet for the latest updates for any Microsoft product.

Figure 5-14

Black hattin’ on the outside.

BEST PRACTICE: Perform this activity on each SBS network you work on (even if it’s only one). Hopefully, you won’t be too surprised by the outcome (in general, SBSers don’t like to be surprised in this area). If you’re a consultant, share the outcome of this black hat exercise with your clients.

Packet Sniffing

Talk about an MCSE-level exercise that works for us SBSers as well: packet sniffing. Here you would install the Network Monitor tool that is native to the underlying Windows Server 2003 operating system, but not installed by default, and then sniff around. To install the tool, perform the following procedure:

1         &nbs p;          Log on as Administrator on SPRINGERS1 (password is Husky9999!).

2         &nbs p;          Click Start, Control Panel, Add or Remove Programs.

3         &nbs p;          Select Add/Remove Windows Components.

 

 

1         &nbs p;          Select Management and Monitoring Tools in the Windows Com­ponents Wizard.

2         &nbs p;          Select Network Monitor Tools and click OK.

3         &nbs p;          Click Next.

4         &nbs p;          Insert Disc #1 when requested.

 

8. Click Finish. In Figure 5-15, you can see what the results of a packet sniffing session might look like. This tool can be used to troubleshoot network problems (such as logon problems) and to search for rogue devices (such as another server running network monitoring on your network without your knowledge).

Figure 5-15

The three-finger salute of TCP/IP session establishment is shown here in a Network Monitor session. Look closely at the source and destination address columns (packets 31-33).

BEST PRACTICE: I used this tool once in early 2003 to investigate whether Microsoft automatic update sessions were actually going out into the ether. A client, a well-known Seattle-based author (not me!),

 Visit www.microsoft.com/technet for the latest updates for any Microsoft product.

believed said updates where going to an offshore site not controlled by Microsoft. The packet analysis facilitated by the Network Monitor tool showed the fears were unfounded. The client then rested easy and allowed his workstation to be automatically updated. I kinda felt like one of the central characters in an old US movie called Ghosbusters and Network Monitor was my tool!

Spam Blocking

Spam blocking fits in the security chapter as well. The malady of “spam” is well known to readers of this book as unwanted e-mail traffic. In fact, the perception of excessive spam on an SBS 2003 network can create unwarranted criticism about SBS 2003 itself, which just isn’t fair.

Spam blocking can be divided into two discussion areas: content filtering and attachment blocking.

Content Filtering

I’ve enjoyed great success using the GFI’s MailEssentials spam blocking program, which more than anything else flexes its muscles in the content filtering department. For example, e-mails with the word “Viagra” are treated as spam and processed accordingly, which might include deletion, move to another folder, etc. MailEssentials is shown in Figure 5-16.

Notes:

Figure 5-16

Meet MailEssentials from GFI. Note that this product is very aggressive out of the box and will sometimes go too far, filtering out legitimate messages.

BEST PRACTICE: Because of the false positives and positive negatives in the world of filtering junk e-mails, the oft-cited security author Roberta Bragg insists that I tell you to send filtered mail to a junk mailbox, instead of deleting it! Right on, Roberta!

Another way to easily engage in a form of content filtering is to utilize the junk mail feature in Outlook 2003. This is a MAJOR IMPROVEMENT in Outlook 2003 and is discussed in Chapter 6.

Attachment Blocking

Of course, the simplest way to invoke attachment blocking is to complete the 15th page of the EICW titled “Remove E-mail Attachments.” I’ll discuss that more in Chapter 6 when you and I look deeper at Exchange Server 2003.

But meet GFI’s MailEssentials once again. Assuming you own this application for its effectiveness in the content filtering area, then consider using it as your attachment blocking tool.

 Visit www.microsoft.com/technet for the latest updates for any Microsoft product.

BEST PRACTICE: The above statement raises the question about which attachment types to block if you’re using a third party tool such as MailEssentials. This list is easily created by looking at and copying the list from the Remove E-mail Attachments page in the EICW.

And yet another attachment blocking tool is contained within Outlook 2003 itself. Since I don’t want to spill the beans on Chapter 6 yet, I’ll wait to discuss it there. Similarly, you can use the SMTP application filter in ISA Server 2000 to engage in both content filtering and attachment blocking (discussed in Chapter 13).

BEST PRACTICE: I only cite GFI’s spam fighting tool because I know it. The infamous Stu at Sunbelt Software in Tampa FL (www.w2knews.com) markets effective spam blocking tools (“I Hate Spam”) that deserve your purchasing consideration. The SBS-related newsgroups are also a source of information for third-party spam fighting applications (see Appendix A for this information).

Virus Protection

So, would you consider virus protection a germane security topic? You betcha! I’ll discuss this much more in Chapter 11 with some step-by-step procedures using Trend Micro’s OfficeScan suite solution, but I’d be remiss to have a security chapter without emphasizing the importance of virus protection as part of your comprehensive approach to security on your SBS 2003 network.

BEST PRACTICE: I’ll say it here and again later on. Virus protection

is only valid when the data files are up-to-date. More later.

SpyWare

If you want to be humbled in a hurry, download the spyware detection applications from www.BulletProofSoft.com. Install its SpyWatch and SpyWare Remover programs and then, when no one is your witness, run these programs. You might be shocked to see what’s been camping out on your SBS network without your knowledge. Thanks to a student from the Louisville, KY hands-on lab for that tip! Many apparently harmless Web sites accessed by your users are

 Visit www.smbnation.com for additional SMB and SBS book, newsletter and conference resources.

really implementing click counters and other spyware nasties. One of the all time greats (or “worsts”) was Gator. An instructor with whom I’ve previously worked on another tour had actually worked for Gator during the dot-com boom and he sends his profound apologies!

FTP Site Notification

And now from the hallowed halls of the Harvard Law School! Did you know that if you dig deep enough into the legal treatise of USA jurisprudence system, you’ll find that long ago, a hacker got off the hook because an FTP site at a company said “Welcome!” Apparently the hacker claimed that he felt invited in to poke around and destroy things. The legal lesson learned here? Prevention! Make the introductory screen of your FTP site say “Authorized Users Only!” or something just as strong.

 
Comments (0) Views (163) Email Blog Forums Save to Favourites
More from this user Print Blog Bookmarks
Add to
 Comments
Sorry!! There are no records to display
Comments
Your Name * E-mail Address * Your Website
 
Your Comments *
Enter code shown below
 
View all | Recent | Popular | Community Recommended | Most Viewed | Today in Blog
 
 
Recent Posts
Early Bird Rate for SMB N...
SBS 2003 Faxing Detailed...
Faxing in SBS 2003...
Beyond Remote Desktop in ...
Advanced Mobility in SBS ...
Comments By
Sorry!! There are no comments posted for this blog
My Important Tags
sbs (74Blogs)
smb (29Blogs)
smb nation (27Blogs)
harry brelsford (27Blogs)
brelsford (13Blogs)
WSS (11Blogs)
exchange (10Blogs)
outlook (7Blogs)
sbs 2008 (5Blogs)
 (5Blogs)
Top 99 Tags
Sponsored Links
Copyright © 2001-2008 ComputerUser, Inc., All Rights Reserved
About us | Terms of use | Privacy Policy | Legal | Trademark/Copyright | Awards | Advertise | Writer guidelines | Sitemap | Contact | FAQ's | Feedback  | Link to us

Here are the topics we cover computer certification computer careers computer training computer games consulting data recovery data security digital entertainment emerging technology gadget reviews handheld computers hardware reviews home automation home networks home office how-to advice internet linux local companies local news local profiles macintosh mp3 players network security online music online security open-source small-business technology soho software reviews technology books technology dictionary vpn web site reviews wi-fi windows wireless technology tech articles tech news press releases tech dictionary education resources career solutions create your personal blog upload your videos become a writer usergroups special interest group SIG 3com cipts adobe adobe certified expert apc ncpi apple achds acpt acsa actc avaya bea 8.1 certified administrator 8.1 certified architect 8.1 certified developer 9 certified administrator bicsi rcdd checkpoint ccmse ccsa ccsa ngx ccse ccse ng plus with ai ccse ngx cisco access routing and lan switching ccda ccdp ccie ccip ccna ccnp ccnp old ccsp ccvp crmam ip communications optical proctored exams for validating knowledge sales specialist storage networking vpn and security wireless lan citrix cca 3.0 cca 4.0 cca 4.5 cca xp ccea 3.0 ccea 4.0 ccea xp ccia ciw ciw associate ciw certified instructor master ciw admin master ciw designer master ciw enterprise developer security analyst comptia a+ network+ security+ server+ computer associates ca cusa cuse cwna cwna cwsp dell eccouncil cea cep certified ethical hacker chfi e-commerce architect emc emc specialist implemenation technology foundations enterasys ese eta exam express exin exin itil extreme networks ena ens filemaker f7cd f8cd fortinet fortigate foundry cne fujitsu fujitsu guidance software ence hdi css hda hdm hdsa hitachi hitachi certified professional hp ais apc app aps ase certified systems developer csa cse master ase huawei hcne hyperion hcp ibm advanced deployment professional advanced technical expert application developer business process analyst certified administrator certified advanced system administrator certified advanced technical expert certified associate developer certified enterprise developer certified solution designer certified specialist certified systems expert database administrator db2 deployment professional enterprise developer eserver certified specialist ibm on demand business solution advisor solution designer solutions developer solutions expert storage administrator system administator iisfa cifi intel isaca cisa isc cissp sscp iseb itil ism cpm juniper jncia jncis legato lcaa lcea lotus clp lpi lpic level 1 lpic level 2 lpic level 3 macromedia mcafee mcdata csnd microsoft crm mbs mcad .net mcdba mcdst mcitp mcp mcpd mcsa longhorn mcsa 2003 mcsa 2008 mcsd .net mcse mcse 2000 security mcse 2000 to mcse 2003 upgrade mcse 2003 mcse 2003 messaging mcse 2003 security mcse 2008 mcts microsoft business solutions microsoft partner competency mile2 cnsa network appliance nac-na nac-nie naca nace nacp network general sniffer certified professional nokia nokia security administrator nortel ncde ncds ncse ncss ncts novell5 cna 5 cne 6 cna 6 cne 6.5 cne cne upgrade omg ocup oracle 10g dba 10g oca 11i 8i dba 9i dba 9i internet application developer oca ocp8 to ocp8i dba upgrade exam pmi project management professional polycom pcve redhat rhce rhct sair sas institute sas scp saas scp snia snia certified architect snia certified professional snia certified systems engineer snia storage networking certification program administrator professional associate symantec scse scsp scta scts teradata tca v2r5 tcad v2r5 tcda v2r5 tcis v2r5 tcm v2r5 tcp v2r5 tia ccnt ctp tibco tcp trusecure ticsa veritas infraguard chamber of commerce vcp vmware certified professional webex linkedin facebook myspace Professional page layout, image editing, vector illustration, and print production Website design, development, prototyping, and blogging Creation of rich interactive content Industry-standard visual effects and motion graphics Video capture, editing, and production; DVD titling; and digital audio, Adobe Photoshop CS3 extended, Adobe illustrator CS3,Adobe indesign CS3,Adobe Acrobat 8 Professional, Adobe Flash CS3 Professional, Adobe Dreamweaver CS3,Adobe Contribute CS3,Adobe Fireworks CS3,Adobe After Effects CS3 Professional, Adobe Premiere Pro CS3,Adobe Soundbooth CS3,Adobe Encore CS3,Adobe OnLocation,Adobe Bridge CS3,Adobe Version Cue CS3,Adobe Device Central CS3,Adobe Stock Photos, Intel Pentium 4 (1.4GHz processor for DV; 3.4GHz processor for HDV), Intel Centrino, Intel Xeon, (dual 2.8GHz processors for HD), or Intel Core, Duo (or compatible) processor; SSE2-enabled processor required for AMD systems Microsoft Windows XP with Service Pack 2 or Microsoft Windows Vista Home Premium, Business, Ultimate, or Enterprise (certified for 32-bit editions) 1GB of RAM for DV; 2GB of RAM for HDV and HD; more RAM recommended when running multiple components 10GB of available hard-disk space (additional free space required during installation) Dedicated 7,200 RPM hard drive for DV and HDV editing; striped disk array storage (RAID 0) for HD; SCSI disk subsystem preferred Microsoft DirectX compatible sound card (multichannel ASIO-compatible sound card recommended),1,280x1,024 monitor resolution with 32-bit color adapter Blu-ray burner required for Blu-ray Disc creation OHCI compatible IEEE 1394 port for DV and HDV capture, export to tape, and transmit to DV device QuickTime 7.1.2 software required to use QuickTime features Broadband Internet connection required for Adobe Stock Photos* and other services