F HEPNT/HEPIX Sept, 1999 Use of SPQuery and STAT At FNAL.

Slides:



Advertisements
Similar presentations
AS ICT Finding your way round MS-Access The Home Ribbon This ribbon is automatically displayed when MS-Access is started and when existing tables.
Advertisements

AIMSweb Progress Monitor Online User Training
WSUS Presented by: Nada Abdullah Ahmed.
15.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 15: Configuring a Windows.
14.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
Hands-On Microsoft Windows Server 2003 Chapter 2 Installing Windows Server 2003, Standard Edition.
Cambodia-India Entrepreneurship Development Centre - : :.... :-:-
MCTS Guide to Microsoft Windows Server 2008 Network Infrastructure Configuration Chapter 11 Managing and Monitoring a Windows Server 2008 Network.
Guide to Operating System Security Chapter 2 Viruses, Worms, and Malicious Software.
Windows Anti-virus and Security WNUG Meeting
Patch Management Module 13. Module You Are Here VMware vSphere 4.1: Install, Configure, Manage – Revision A Operations vSphere Environment Introduction.
1 Chapter Overview Creating User and Computer Objects Maintaining User Accounts Creating User Profiles.
11 MAINTAINING THE OPERATING SYSTEM Chapter 5. Chapter 5: MAINTAINING THE OPERATING SYSTEM2 CHAPTER OVERVIEW Understand the difference between service.
1 Computer Security: Protect your PC and Protect Yourself.
16.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 16: Examining Software Update.
11 MAINTAINING THE OPERATING SYSTEM Chapter 5. Chapter 5: MAINTAINING THE OPERATING SYSTEM2 CHAPTER OVERVIEW  Understand the difference between service.
11 WORKING WITH USER ACCOUNTS Chapter 6. Chapter 6: WORKING WITH USER ACCOUNTS2 CHAPTER OVERVIEW Understand the differences between local user and domain.
Chapter 7 Installing and Using Windows XP Professional.
Ch 11 Managing System Reliability and Availability 1.
9.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
This presentation will guide you though the initial stages of installation, through to producing your first report Click your mouse to advance the presentation.
Module 9 Configuring Server Security Compliance. Module Overview Securing a Windows Infrastructure Overview of EFS Configuring an Audit Policy Overview.
Chapter-4 Windows 2000 Professional Win2K Professional provides a very usable interface and was designed for use in the desktop PC. Microsoft server system.
Blackboard Pilot Tasks and Walkthroughs. Bb Test Case Training Pilot with AnswersDarek Sady - 5/4/2004 Goals:  Identify problematic areas our clients.
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory Chapter 12: Deploying and Managing Software with Group Policy.
1 Group Account Administration Introduction to Groups Planning a Group Strategy Creating Groups Understanding Default Groups Groups for Administrators.
© 2010 VMware Inc. All rights reserved Patch Management Module 13.
1 Guide to Novell NetWare 6.0 Network Administration Chapter 13.
Hands-On Microsoft Windows Server 2003 Administration Chapter 2 Managing Windows Server 2003 Hardware and Software.
5 Chapter Five Web Servers. 5 Chapter Objectives Learn about the Microsoft Personal Web Server Software Learn how to improve Web site performance Learn.
Section 2: Using Group Policy Management Tools Local vs. Domain Policies Editing Local Policies Managing Domain Policies Understanding Group Policy Refresh.
User Manager Pro Suite Taking Control of Your Systems Joe Vachon Sales Engineer November 8, 2007.
Network Management Tool Amy Auburger. 2 Product Overview Made by Ipswitch Affordable alternative to expensive & complicated Network Management Systems.
The Microsoft Baseline Security Analyzer A practical look….
DIT314 ~ Client Operating System & Administration CHAPTER 5 MANAGING USER ACCOUNTS AND GROUPS Prepared By : Suraya Alias.
Introduction to Test Director
Module 1: Installing Microsoft Windows XP Professional.
A+ Guide to Managing and Maintaining Your PC Fifth Edition Chapter 13 Understanding and Installing Windows 2000 and Windows NT.
NT4 SP4 Security Jack Schmidt - Fermilab
Module 14: Securing Windows Server Overview Introduction to Securing Servers Implementing Core Server Security Hardening Servers Microsoft Baseline.
Tour Overview Introduction Collage Basics Collage Basics (Templates and Tools) Computer Configuration Bookmark Collage Getting Started Tour Collage Terminology.
Module 4 Planning for Group Policy. Module Overview Planning Group Policy Application Planning Group Policy Processing Planning the Management of Group.
Microsoft Management Seminar Series SMS 2003 Change Management.
Retina Network Security Scanner
TrainingRegister® Training Management Software Maintain Permanent Training Records for Each Individual Monitor and Track Required Training Know Who Needs.
Enigma Mutiara Sdn Bhd Computer Based Learning (CBL) HSE Procedures.
SQL SERVER 2008 Installation Guide A Step by Step Guide Prepared by Hassan Tariq.
1 Chapter Overview Monitoring Access to Shared Folders Creating and Sharing Local and Remote Folders Monitoring Network Users Using Offline Folders and.
Automating Installations by Using the Microsoft Windows 2000 Setup Manager Create setup scripts simply and easily. Create and modify answer files and UDFs.
Integrity Check As You Well Know, It Is A Violation Of Academic Integrity To Fake The Results On Any.
Quick Reference Guide The Multi-Vendor Backup Manager allows you to manage backup software settings on multiple agents in one place for Acronis, AppAssure,
1 BCS 4 th Semester. Step 1: Download SQL Server 2005 Express Edition Version Feature SQL Server 2005 Express Edition SP1 SQL Server 2005 Express Edition.
Unit 9 ITT TECHNICAL INSTITUTE NT1330 Client-Server Networking II Date: 2/17/2016 Instructor: Williams Obinkyereh.
CACI Proprietary Information | Date 1 PD² SR13 Client Upgrade Name: Semarria Rosemond Title: Systems Analyst, Lead Date: December 8, 2011.
11 DEPLOYING AN UPDATE MANAGEMENT INFRASTRUCTURE Chapter 6.
Lecture 19 Page 1 CS 236 Online 6. Application Software Security Why it’s important: –Security flaws in applications are increasingly the attacker’s entry.
1 Remote Installation Service Windows 2003 Server Prof. Abdul Hameed.
Patch Management Module 13.
Create setup scripts simply and easily.
Documentation & Troubleshooting Guide
Setting-Up and Securing a Server
Objectives Differentiate between the different editions of Windows Server 2003 Explain Windows Server 2003 network models and server roles Identify concepts.
5.0 : Windows Operating System
Unit 9 NT1330 Client-Server Networking II Date: 8/9/2016
Lesson 16-Windows NT Security Issues
Configuring Internet-related services
Security through Group Policy
Advantages of Networking
Designing IIS Security (IIS – Internet Information Service)
6. Application Software Security
Presentation transcript:

f HEPNT/HEPIX Sept, 1999 Use of SPQuery and STAT At FNAL

f SPQuery F SPQuery is a useful tool for: F Reporting Service pack and hotfix information for an entire domain or a select group of machines. F Downloading of hotfixes from Internet for NT, IIS, Exchange, SQL and Site Server to a central repository F Applying Workstation/Server hotfixes to remote machines

f Query Systems F Ability to check single machine, entire domains, or use machine list files. F Information on date Service Pack and hotfixes were applied F Information on available hotfixes for applied service pack

f Systems Information

f Importing Machine Lists

f Hotfix Info F Get information on files replaced or added by the hotfix F Query Internet for newest hotfix information F View Knowledge Base Article

f Affected Files

f Knowledge Base Information

f Applying Fixes Three Basic Steps FDownload hot fixes to a local repository u Multiple downloads possible. FInstall u Must have admin rights to install to remote system u Schedules hotfix to be applied at next login. User must have local admin u Hotfix files and an ‘agent’ copied to remote system and run on next login. u Pop up box during login gives user choice to apply patch or not. uOnly visible for 20 seconds u Only supports singular patch application FReboot NOTE: User has the ability to decide if patch is applied!

f Downloading Fix

f Fix Scheduled

f User Login

f Hotfix Applied

f Profile Creation F Offers the ability to create service pack/hotfix profiles. F Test your NT machine(s) against these profiles to determine if they pass or fail. F We have Profiles for SP4 and SP5 with appropriate security hotfixes.

f Profiles

f Reporting F Print reports (very detailed) F Save reports for future reference in SPQuery or save them to a csv file and import into Excel

f Options

f SPQuery Stuff I’d like to see FNotify if user selects ‘Never’ apply patch. FAbility to load patches in correct order. FAbility to apply more than one patch at a time. FMore details when downloading from Internet FCustomization of Report Printing Inexpensive- $595 for a site license!

f STAT (Security Test and Analysis Tool) F Detects Vulnerabilities from NT 3.51 to NT4 SP5 F Can Examine specific machine, multiple machines or Entire Domain F Automatic Vulnerability Fix F Configuration Templates available F Password Strength testing

f Account requirements F To analyze systems on the network must be Domain Admin. F To analyze workgroups must be in local admin for machines you wish to access

f Analysis Overview F Analyze single machine, multiple machines or domains F Machine analysis can be saved and compared to new analysis F Systems must appear in Network Neighborhood F Domain examination is time-consuming FChecking all vulnerabilities takes an average of one gigabyte per minute. F 4 Levels of Vulnerability FHigh- May grant unauthorized administrative access. FMedium- May provide access to sensitive data leading to further exploitation. FLow- May be used for information gathering or preventative security measures that could lead to higher risk levels. FWarning- Recommended good security practices.

f 4 Warnings F There are 4 warnings in the STAT database that will always be displayed: F ID# 87 boot enabled (anyone can boot system from floppy) F ID# 403 clipboard ( clear clipboard before logging off or locking computer F ID# 409 emergency repair disk (ERD has compressed version of SAM. Make sure to lock it up!) F ID# 421 administrators group (check administrators group for unknown account names)

f Analysis

f Vulnerability Info

f Fixing Vulnerability

f Vulnerability Fixed

f Configuration Files F Ability to define ‘templates’ to check for only specific vulnerabilities. F Description field helps identify vulnerability. F Eight ‘templates’ provided: FAll- ~600 vulnerabilities. FAutofix- Check only what can be fixed. FFilechecks- Check only file related vulnerabilities. FHigh- Check only vulnerabilities defined as high. FLow- Check only vulnerabilities defined as low. FMedium- Check only vulnerabilities defined as medium. FNofilechecks- Check only vulnerabilities not related to files. FWarning- Check only vulnerabilities not related to files.

f Configuration

f Password Cracking F Uses simple text file to check passwords F Cracked passwords not displayed. Just Username. F File can be modified to your requirements. FNote: Software upgrade could overwrite the file.

f Report Print Options Executive FPie-chart representing the percentage of vulnerabilities by level of risk found in a selected network or machine. Network FBar chart representing percentages of discovered vulnerabilities with respect to total possible vulnerabilities tested per machine. Vulnerability FBar chart representing each vulnerability detected and how many machines contain that specific vulnerability. F Detailed FReport shows all vulnerabilities found per machine. The report provides a brief description of each vulnerability, along with the applicable risk each represent.

f STAT Wish List F Ability to import machine lists F Better documentation F Improve speed of analysis F Problems analyzing domain with 95/98 systems F Canceling a vulnerability assessment takes too long Cost- $1797 per Admin License does not include yearly maintenance