Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Server Security > Re: Security audit tool(s)/scripts for W2K3

Reply
Thread Tools Display Modes

Re: Security audit tool(s)/scripts for W2K3

 
 
Special Access
Guest
Posts: n/a

 
      06-20-2009
On Fri, 19 Jun 2009 01:28:32 -0700 (PDT), Robert Kochem
<> wrote:

>Hi NG.
>
>I am tasked with a security audit of a Windows 2003 server. The
>problem is that I don't get direct access to the server - instead I
>have to provide tool(s) and/or script(s) that gather information on
>the server. Those gathering tools are executed by an admin of the
>machine and I get only the output for auditing the server.
>
>The problem is that the audit is not limited to certain parts of the
>server (users, services, filesystem). Therefore the standard tools I
>know would generate a large amount of data - and finding security
>issuses in this data would be like finding Needle in a Haystack...
>
>Does anybody know good tools or scripts that would help me gathering
>the required information I need in an intelligent way?
>
>Thanks in advance, Robert


Here http://iase.disa.mil/stigs/checklist/index.html is a list of
checklists that the Gov't (should) use to secure their computers. Not
scripts, just checklists.

here http://iase.disa.mil/stigs/SRR/index.html you can download the
Windows Gold disk (link is near the bottom). This has to be run on
the computer (can be local or via RDP) and save the OPEN results only
(the closed, n/a and unknowns are not worth the paper IMO). Do NOT, I
repeat DO NOT use the "mitigate" button on this disk to fix ANY of the
problems or you most likely will find yourself locked out of, or in
control of a non-usable server.

There are SRR (scripts) that you CAN use to look at Windowsn NT (on
the SRR page) but I personally have never used them so I can't vouch
for them.

Mike
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
A New Vista Security Policy on Audit:Force Audit Policy Subcategor Gayle Windows Vista Security 1 10-19-2007 04:51 PM
Is there any audit tool I can use to see who deleted a user in AD nikki@anon.com Active Directory 2 08-24-2007 01:34 PM
Re: Network Software and Hardware Audit/Inventory Tool Kevin Longley Windows Server 0 10-07-2006 12:17 AM
1000's of Security Audit entries in Security Event viewer Tony Girgenti Windows Small Business Server 1 07-20-2006 03:05 AM
Security audit & Domain Controller security Dan Shallbetter Windows Small Business Server 5 08-08-2005 07:42 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59