Download presentation
Presentation is loading. Please wait.
1
f HEPNT/HEPIX Sept, 1999 Use of SPQuery and STAT At FNAL
2
f SPQuery F SPQuery is a useful tool for: F Reporting Service pack and hotfix information for an entire domain or a select group of machines. F Downloading of hotfixes from Internet for NT, IIS, Exchange, SQL and Site Server to a central repository F Applying Workstation/Server hotfixes to remote machines
3
f Query Systems F Ability to check single machine, entire domains, or use machine list files. F Information on date Service Pack and hotfixes were applied F Information on available hotfixes for applied service pack
4
f Systems Information
5
f Importing Machine Lists
6
f Hotfix Info F Get information on files replaced or added by the hotfix F Query Internet for newest hotfix information F View Knowledge Base Article
7
f Affected Files
8
f Knowledge Base Information
9
f Applying Fixes Three Basic Steps FDownload hot fixes to a local repository u Multiple downloads possible. FInstall u Must have admin rights to install to remote system u Schedules hotfix to be applied at next login. User must have local admin u Hotfix files and an ‘agent’ copied to remote system and run on next login. u Pop up box during login gives user choice to apply patch or not. uOnly visible for 20 seconds u Only supports singular patch application FReboot NOTE: User has the ability to decide if patch is applied!
10
f Downloading Fix
11
f Fix Scheduled
12
f User Login
13
f Hotfix Applied
14
f Profile Creation F Offers the ability to create service pack/hotfix profiles. F Test your NT machine(s) against these profiles to determine if they pass or fail. F We have Profiles for SP4 and SP5 with appropriate security hotfixes.
15
f Profiles
16
f Reporting F Print reports (very detailed) F Save reports for future reference in SPQuery or save them to a csv file and import into Excel
17
f Options
18
f SPQuery Stuff I’d like to see FNotify if user selects ‘Never’ apply patch. FAbility to load patches in correct order. FAbility to apply more than one patch at a time. FMore details when downloading from Internet FCustomization of Report Printing Inexpensive- $595 for a site license! http://www.mtesoft.com
19
f STAT (Security Test and Analysis Tool) F Detects 600 + Vulnerabilities from NT 3.51 to NT4 SP5 F Can Examine specific machine, multiple machines or Entire Domain F Automatic Vulnerability Fix F Configuration Templates available F Password Strength testing
20
f Account requirements F To analyze systems on the network must be Domain Admin. F To analyze workgroups must be in local admin for machines you wish to access
21
f Analysis Overview F Analyze single machine, multiple machines or domains F Machine analysis can be saved and compared to new analysis F Systems must appear in Network Neighborhood F Domain examination is time-consuming FChecking all vulnerabilities takes an average of one gigabyte per minute. F 4 Levels of Vulnerability FHigh- May grant unauthorized administrative access. FMedium- May provide access to sensitive data leading to further exploitation. FLow- May be used for information gathering or preventative security measures that could lead to higher risk levels. FWarning- Recommended good security practices.
22
f 4 Warnings F There are 4 warnings in the STAT database that will always be displayed: F ID# 87 boot enabled (anyone can boot system from floppy) F ID# 403 clipboard ( clear clipboard before logging off or locking computer F ID# 409 emergency repair disk (ERD has compressed version of SAM. Make sure to lock it up!) F ID# 421 administrators group (check administrators group for unknown account names)
23
f Analysis
24
f Vulnerability Info
25
f Fixing Vulnerability
26
f Vulnerability Fixed
27
f Configuration Files F Ability to define ‘templates’ to check for only specific vulnerabilities. F Description field helps identify vulnerability. F Eight ‘templates’ provided: FAll- ~600 vulnerabilities. FAutofix- Check only what can be fixed. FFilechecks- Check only file related vulnerabilities. FHigh- Check only vulnerabilities defined as high. FLow- Check only vulnerabilities defined as low. FMedium- Check only vulnerabilities defined as medium. FNofilechecks- Check only vulnerabilities not related to files. FWarning- Check only vulnerabilities not related to files.
28
f Configuration
29
f Password Cracking F Uses simple text file to check passwords F Cracked passwords not displayed. Just Username. F File can be modified to your requirements. FNote: Software upgrade could overwrite the file.
30
f Report Print Options Executive FPie-chart representing the percentage of vulnerabilities by level of risk found in a selected network or machine. Network FBar chart representing percentages of discovered vulnerabilities with respect to total possible vulnerabilities tested per machine. Vulnerability FBar chart representing each vulnerability detected and how many machines contain that specific vulnerability. F Detailed FReport shows all vulnerabilities found per machine. The report provides a brief description of each vulnerability, along with the applicable risk each represent.
31
f STAT Wish List F Ability to import machine lists F Better documentation F Improve speed of analysis F Problems analyzing domain with 95/98 systems F Canceling a vulnerability assessment takes too long Cost- $1797 per Admin License does not include yearly maintenance http://www.statonline.com
Similar presentations
© 2024 SlidePlayer.com Inc.
All rights reserved.