Home > Ask the Networking Experts > Network security with Puneet Mehta Questions & Answers > What are some common security vulnerabilities related to Windows NT?
Ask The Networking Expert: Questions & Answers
EMAIL THIS

What are some common security vulnerabilities related to Windows NT?

Puneet Mehta EXPERT RESPONSE FROM: Puneet Mehta

Pose a Question
Other Networking Categories
Meet all Networking Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 09 April 2004
What are some common security vulnerabilities related to Windows NT?

>
EXPERT RESPONSE
Windows NT is rich in features and that's what makes it more vulnerable. But no matter what NOS you choose to deploy, security should always be the primary concern. It's not possible to list out all of the vulnerabilities here, but sure I can list out some of the common ones. They are:
  • Using IPC$ to make anonymous connections.
  • Unrestricted Registry Access
  • Open Shares
  • Weak password (No password policy enforced)
  • Unrestricted user Permissions
  • Local Administrator account
  • Un-encrypted password database.
  • Unrestricted Trust relationships
  • Enabling DCOM support
  • Enabling IP Packet forwarding (even when it's not required)
  • Running MDAC in unsafe mode.
  • Running RPC
  • LocalSystem account does not have a password (most of the privileged services run with the same account)
  • Using Anonymous, Guest or default Administrator account.
  • NT uses NetBIOS as an abstration layer from the underlying network transport protocol. This helps an attacker gather information about the hosts (NetBIOS information)
  • The remote procedure call (RPC) Endpoint Mapper and Distributed Component Object Model (DCOM) Service Control Manager (SCM) listen on TCP and UDP port 135. Any user who can connect to port 135 can obtain information about which dynamic RPC and DCOM services are running and what ports they are listening on. To stop the Endpoint Mapper and SCM from listening on this port, you must disable the RPC Server service, which cripples NT.

    I recently responded to a similar question. Below is the link to the same.
    http://searchnetworking.techtarget.com/ateQuestionNResponse/0,289625,sid7_cid554727_tax287058,00.html


  • Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Network Security Monitoring
    Networking data visualization not just for pointy-headed bosses
    Visual Security Analysis -- 'Applied Security Visualization,' Chapter 5
    SIEM platform secures university's open network
    Network forensics appliance gets storage boost and 10 GbE support
    Tracking NetFlow over MPLS helps airline with compliance
    Securing the new network architecture: Security for distributed, dynamic networks
    When it comes to data loss prevention, networking should be part of the conversation
    What is data loss prevention? -- An introduction to DLP
    What are the best methods for handling rogue access points?
    Internet monitoring vendor adds throttling, filtering, to its appliance

    Network security with Puneet Mehta
    What network security threat does a QM FSM error pose in IPsec VPNs?
    How to block porn with ISA-server firewalls
    Who is responsible for updating network firewalls?
    How to locate the lost IP address of an Access Point (AP)
    What HIPPA-compliant software would you recommend for online medicine?
    To simulate voice over IPSec VPNs which simulators work?
    How to set passwords on folders in Windows 2003 servers
    What commands allow network traffic to pass through PIX firewalls?
    For an SMB firewall, what features should I look at?
    Can users on my LAN view my computer from other machines?

    Windows Network Administration
    More remote scripting tricks: Managing Windows networks using scripts, Part 11
    Understanding remote scripting -- Managing Windows networks using scripts, part 9
    Network mapping in Vista for Windows XP
    How to set passwords on folders in Windows 2003 servers
    How to configure Windows Server 2008 advanced firewall MMC snap-in
    Recovering domain controllers after a server disk failure
    Recovering from a server disk failure: The shortcomings of NTBCKUP
    Troubleshooting remote scripting using Network Monitor 3.0 -- Managing Windows networks using scripts, part 8
    Remote Desktop troubleshooting
    Enabling Windows Vista's Network Mapping feature on domain networks

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    deep packet inspection (DPI)  (SearchNetworking.com)
    FCAPS  (SearchNetworking.com)
    Nessus  (SearchNetworking.com)
    netstat  (SearchNetworking.com)
    port mirroring  (SearchNetworking.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Expert networking advice and tips for IT professionals
    Visit KnowledgeStorm's comprehensive and easy to use business white paper directory.
    HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersNetworking Product Trials
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2000 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts