Vulnerability Assessment & Audit Questions


Website monitoring suggestions?
Suggestions for website monitoring? Is there something that monitors for security vulnerabilities?

Answer Question   |  December 17, 2010  9:21 PM
Network security, Security management, Vulnerability Assessment & Audit, Website maintenance, Website security
asked by:
1,110 pts.

Security advisories
Does a security research firms track record of vulnerabilities and exploits published make you trust them more, or more likely to hire them?

Answer Question   |  September 24, 2009  2:50 PM
Application security, Vulnerability Assessment & Audit
asked by:
6,893 pts.

Shares Baseline Security Information
Hello, I use the Microsoft Baseline Security Analyser 2.0 to retrive information about shares in some local servers. I can not understand the diference between the information give in the report, about authorizations in the column Share ACL and Directory ACL. If some one can help me, Thank you PPG

Answer Question   |  August 5, 2005  6:02 AM
Auditing, configuration, patching, PEN testing, Platform Security, Security, Security management, Security products, Vulnerability Assessment & Audit, vulnerability management
asked by:
0 pts.

aaa authorization ?
Which of the following authorization commands are valid? (we have to choose 2 correct) A. aaa authentication exec home radius B. aaa accounting exec home radius C. aaa authorization default none D. aaa authorization exec home radius E. aaa authorization network default enable F. aaa authorization network default local

Answer Question   |  July 26, 2005  9:45 AM
Administration, Application security, Architecture/Design, Biometrics, Cabling, Cisco, Data analysis, Database, DataCenter, Desktop vs network-based firewalls, Digital certificates, Documentation, Encryption, Exchange, Features/Functionality, Firewalls, Forensics, Hardware, Hubs, Identity & Access Management, Incident response, Installation, Instant Messaging, Intrusion management, Network security, Networking, Product/Service evaluation, provisioning, Routers, Secure Coding, Security, Security tokens, Service and support, Single sign-on, Switches, VPN, Vulnerability Assessment & Audit, Wireless
asked by:
0 pts.

asked by:
0 pts.

Certificates
I am pretty new to the 2003 Microsoft world, but I am NT 4 MCSE. My setup: 2 W2K3 DC’s 1 Exchange 2K3 member server 1 W2K3 member server–web server about 60 users–single domain some of my users want to use Outlook Web Access to get their mail from home (approx. 10-15) Everything is set [...]

Answer Question   |  July 5, 2005  11:45 AM
Compliance, CRM, DataCenter, Disaster Recovery, Information risk management, Intrusion management, Policies, Risk management, Security, Security management, Security Program Management, VPN, Vulnerability Assessment & Audit
asked by:
0 pts.

Files and directory access loging
one of my clients is asking about a daily report contains all files and directories accessed every day and who is accessing it (time and mode:delete ,read ,write.) on a spicific share. so i tried using a script to filter out all events regarding files access but that looks time consuming method . so please [...]

Answer Question   |  July 20, 2005  12:51 PM
Auditing, IT auditing software, Vulnerability Assessment & Audit
asked by:
0 pts.

asked by:
0 pts.

Data vs. perimeter vs. network security
A short time ago, author Wes Noonan wrote some tips for SearchWindowsSecurity.com about <a href=http://searchwindowssecurity.techtarget.com/originalContent/0,289142,sid45_gci1007026,00.html>deperimeterization</a>. He explained how security is always pitted against business needs, and perimeters have become porous because businesses require traffic from SMTP, HTTP or VPNs to pass through the firewall. He then offered techniques for keeping data safe in spite of [...]

Answer Question   |  May 4, 2005  4:36 PM
Administration, Application security, Architecture/Design, backdoors, Biometrics, Compliance, configuration, CRM, Current threats, Database, Desktop vs network-based firewalls, Digital certificates, Disaster Recovery, Documentation, Encryption, Exchange, Features/Functionality, Firewalls, Forensics, Hacking, Host-based IDS/IPS, human factors, Identity & Access Management, IDS vs IPS, IDS/IPS management, Incident response, Installation, Instant Messaging, Intrusion management, Managed security services, Management, Network security, Network-based IDS/IPS, Networking, Outsourcing/Managed services, patching, PEN testing, Platform Security, Policies, Product evaluation, provisioning, Risk management, Secure Coding, Security, Security management, Security products, Security Program Management, Security tokens, Service and support, Signature updating/Management, Single sign-on, Software vs appliance, Spyware, Trojans, Viruses, VPN, Vulnerability Assessment & Audit, vulnerability management, Wireless, worms
asked by:
0 pts.

asked by:
0 pts.

Service.exe Process
I have a w2k pro computer that is experiencing an incredible slowness, when I check the runing processes, I find service.exe is eating up over 90% of the cpu, starving out any other application/process. Has anybody come accross this problem and knows how to fix it? any suggestion would be appreciated. thanks.

Answer Question   |  June 8, 2005  1:02 PM
Application security, Database, DataCenter, Development, Encryption, Exchange, Incident response, Instant Messaging, Secure Coding, Security, Vulnerability Assessment & Audit
asked by:
0 pts.

Internet Explorer vs. Firefox
Hello, I’m the Assistant Editor on SearchWindowsSecurity.com. I’m looking to start a discussion about what browser people are using and why. Also, is anyone considering switching from IE to Firefox, or are your plans to stay with IE? Here’s some food for thought… As of Feb. 2005, an estimated 35 million users had switched from [...]

Answer Question   |  June 29, 2012  2:14 PM
Addamark, Administration, Aladdin Knowledge Systems, Application security, AppSec, Architecture/Design, ArcSight, Bindview, Biometrics, Caymas, CipherTrust, Compliance, Computer Associates, configuration, Courion, CRM, Cylant, Database, DataCenter, Desktop management applications, Desktops, Digital certificates, Disaster Recovery, Documentation, e-Security, Emerging technologies, Encryption, Enterasys Networks, Entrust, Exchange, Features/Functionality, GuardedNet, Hardware, Host-based IDS/IPS, IBM/Tivoli, Identity & Access Management, IDS vs IPS, IDS/IPS management, Imprivata, Installation, Instant Messaging, Intellitactics, Internet Security Systems, Intrusion management, Juniper Networks, KavaDo, M-Tech, Magnifire, Managed security services, Management, Maxware, Microsoft Windows, Netegrity, NetForensics, NetIQ, Network Associates, Network-based IDS/IPS, NFR Security, NGS Software, Novell, Ounce Labs, Outsourcing, Outsourcing/Managed services, Passlogix, patching, PEN testing, Platform Security, Policies, Product evaluation, Product/Service evaluation, provisioning, Risk management, RSA Security, Sana Security, Secure Coding, Security, Security management, Security Program Management, Security tokens, Servers, Service and support, Service contracts, Service evaluation, Single sign-on, Snort/Sourcefire, SPI Dynamics, StillSecure, Tech support, Teros, Thor, Tripwire, TruSecure, Vendors, VeriSign, VPN, VSecure, Vulnerability Assessment & Audit, vulnerability management, Watchfire, Waveset/Sun Micro, Windows, Windows XP
asked by:
0 pts.

I’ve been hacked — I think….
I’m an IT administrator with a little over 500 end users, running Windows 2000 and XP. One of our users is experiencing a problem with her Internet connection suddenly dropping for no apparent reason. When she restarts her computer, everything works fine for awhile, but then the connection drops again. The funny thing is, she’s [...]

Answer Question   |  August 2, 2009  9:52 AM
Administration, Application security, Architecture/Design, Bigfix, Biometrics, Cisco, Citadel, Compliance, Computer Associates, configuration, Configuresoft, CRM, Cylant, Database, DataCenter, Desktop antivirus, Desktop management applications, Digital certificates, Disaster Recovery, Documentation, Ecora, Encryption, Enterasys Networks, Exchange, Features/Functionality, Firewalls, Forensics, GFI, Hewlett-Packard, Host-based IDS/IPS, Identity & Access Management, IDS vs IPS, IDS/IPS management, Incident response, Installation, Instant Messaging, Internet Security Systems, Intrusion management, Juniper Networks, Managed security services, Management, Microsoft Windows, Network Associates, Network Elements, Network security, Network-based IDS/IPS, NFR Security, Outsourcing, Outsourcing/Managed services, patching, Patchlink, PEN testing, Platform Security, Policies, Product evaluation, Product/Service evaluation, provisioning, Redundancy, Risk management, Sana Security, Secure Coding, Security, Security Program Management, Security tokens, Service and support, Service contracts, Service evaluation, Shavlink Technologies, Single sign-on, Snort/Sourcefire, St. Bernard Software, StillSecure, Symantec, Tripwire, Vendors, VPN, VSecure, Vulnerability Assessment & Audit, vulnerability management, Wireless
asked by:
0 pts.

asked by:
0 pts.

trojan horse downloader
hi i have a win NT4.0 sp6 server.its a DNS and web server. from few days the IE was redirecting the sites to some search engines.when i scaned with AVG it detected some trojan horse downloader.i healed the trojan and restarted the DNS.the problem was solved.but after some hours the problem arise again.since then i [...]

Answer Question   |  November 2, 2011  3:57 AM
backdoors, Backup & recovery, configuration, Current threats, DataCenter, Hacking, Hardware, Help Desk, human factors, Installing/upgrading operating systems, Intrusion management, patching, PEN testing, Platform Security, Security, Server management, Servers, Spyware, Tech support, Trojans, Viruses, Vulnerability Assessment & Audit, vulnerability management, Windows, Windows on Intel, Windows Server 2003, worms
asked by:
0 pts.

ID Theft and National Security
If it turns out, as I believe, that enemies of the United States are behind a lot of the major ID thefts in the US, that would mean that a lot of money is going to our enemies. Can we therefore surmise that those who mishandle our identity information, by means of their poor stewardship [...]

Answer Question   |  September 21, 2010  10:35 PM
Application security, Auditing, Biometrics, Business/IT alignment, California Security Breach Information Act, Can Spam Act, Compliance, CRM, Database, Digital certificates, Disaster Recovery, E-business, Encryption, Exchange, Gramm-Leach-Bliley Act, HIPAA, Identity & Access Management, Incident response, Information risk management, Instant Messaging, ISO 17799, Laws, Policies, provisioning, Regulations, Risk management, Sarbanes-Oxley Act, Secure Coding, Security, Security management, Security products, Security Program Management, Security tokens, Single sign-on, standards, USA Patriot Act, Vulnerability Assessment & Audit
asked by:
75 pts.

Reporting domain/workgroup membership on your LAN using PERL
This is more of an FYI. I just posted a perl script that I use to generate a daily report of all Workstations and Servers located on our LAN. This report is sorted by domain/workgroup membership and includes any visible shares on the machine. If anyone is interested you can read it here: http://frankenrouter.homeip.net/System+Admin+Articles/111.aspx Thanks, [...]

Answer Question   |  August 23, 2005  12:13 PM
Active Directory, Compliance, CRM, Desktops, DHCP, Disaster Recovery, DNS, Ethernet, IPv4, Lotus Domino, NetBIOS, Networking, Networking services, Policies, Risk management, Security, Security Program Management, Vulnerability Assessment & Audit
asked by:
0 pts.

Security Forensics with Niksun or CA or Sandstorm
Does any have experience recording and tracking traffic with playback using any of these venders. I am looking for the best solution to provide Forensics on my network. Niksun or CA or Sandstorm Also on a side not I am lookign for a product to do secure email delivery. Please let me know if anyone [...]

Answer Question   |  March 27, 2005  9:28 AM
Application security, Bandwidth, Database, Encryption, Exchange, IDS/IPS management, Instant Messaging, Intrusion management, IT architecture, Network monitoring, Networking, Secure Coding, Security, Security management, Vulnerability Assessment & Audit
asked by:
0 pts.

asked by:
0 pts.

asked by:
0 pts.