Security Basics mailing list archives

Re: Windows 2000 - Invites you


From: pablo gietz <pablo.gietz () nuevobersa com ar>
Date: Mon, 11 Aug 2003 11:52:07 -0300

JM:
Kids don't know how to chage password, and are running with restricted user.

.

JM wrote:

How old are your kids, maybe not so innocent eh?



You probably setup W2000 with all the default options, so have IIS
running on there, with unpatched vulnerabilities.



Check the event log that may give you some info!  If not.......



If you have not done too much work, on the machine, start again,
install with no default options, and then add what you need as you go
along, check MS Security guidelines for setting up that machine.



If you have done a lot of work, I still think you should maybe ack
this up, and rebuild from scratch.  OR, check for Trojans, viruses etc
with one of the freeware scanners.



Also, if the kids were using an account with admin rights, they can
change whatever passwords they want, so maybe restrict them down to a
user account after all the apps they need are installed.



Cheers


--
Pablo A. C. Gietz
Jefe de Seguridad Informática
Nuevo Banco de Entre Ríos S.A.
Te.: 0343 - 4201351
Fax: 0343 - 4201329


La información y archivos contenidos en este mensaje son confidenciales y para utilización exclusiva de los 
destinatarios consignados. Si Usted no reviste ese carácter, no se encuentra autorizado para divulgar, 
copiar,distribuir o retener todo o parte de la informacion y archivos, y deberá notificarlo de inmediato al remitente y 
eliminarlo de su sistema. Muchas gracias.




---------------------------------------------------------------------------
----------------------------------------------------------------------------


Current thread: