Auditing your network at the packet level is a practice that is not done very often, if at all. The truth of it is that there are untold riches in all those packets flying about on your LAN. All one has to do is log them, and dig into them. One never knows what they will find.
Security is always an important area for IT professionals, and there's no shortage of books on computer and network security coming out these days. Below are five recent titles on various security topics and my take on them.
In this article, we’ll talk about the differences between the built-in and default local account types, and the differences between local and domain user accounts. Then we’ll discuss how you can increase security by creating customized limited user accounts and using Restricted Groups.
In part five we take the IT professional through strategies of offsite recovery and potential solutions that could be recommended to businesses for recovery. The importance of pre-disaster preparation is highlighted and the fact that just basic preparedness is done in the event of disaster proves to be worth the time and cost invested.
The goal of this article is to discuss the concerns and threats that spyware creates for Network Administrators, and to provide information that is helpful in making the general public aware of the spyware threat. Also included in the article is a link to independent studies and comparisons of Anti-spyware software by Eric L. Howes.
Most organizations are either at Windows Active Directory or they are contemplating that move now. If you fall in the latter category, you have some decisions to make. You need to decide how you will get from where you are now, possibly a Windows NT domain(s), to Windows 2000 or Server 2003 Active Directory domain(s).
Although Windows XP Service Pack 2 was designed to make your system more secure, there are some situations in which installing the service pack can actually undermine your existing security. In this article, I will take a look at what these situations are and how you can get around them.
Information security professionals are rarely at a loss for data. Point products—such as firewalls, intrusion prevention systems, antivirus programs, operating systems (OSs) and other elements of the security infrastructure—generate steady streams of data about events and conditions. Security professionals are not in need of data—they need information. Filtering volumes of raw data, correlating events, and reporting actionable information is the role of a security information management (SIM) system.
In this article we will look at how to use a tool called ‘cipher’ which is a command line tool included with Windows 2000 and XP. We will learn how to use its newest functionality – allowing administrators the ability to wipe all deleted (marked for deletion) data on the hard disk. This would overwrite all of the deleted data and provide for better security. If someone steals your system, like a laptop, then the thief would not be able to recover that data. In this article we learn how to perform this procedure.
We shall now actually deface the web server’s web page, and pull off the hack as it were. Furthermore we will peek under the hood, and look at the packets to see just what transpired so that you might recognize it in the future.
Microsoft Operations Manager (MOM) 2005 is a great solution for managing your Exchange, SQL and other servers -- but what about security? In this article, we'll discuss some of the security issues related to MOM 2005, how Microsoft has made this version of MOM more secure, and best practices for deploying MOM in the most secure way possible.
This article demonstrates how IPsec transport mode can be leveraged as one of the best means currently available to protect corporate networks. This protection can minimize losses due to information theft, compromise of credentials, and administrative costs. This solution also clearly contrasts IPsec transport mode from the more widely known IPsec tunnel mode, one of the prevalent VPN technologies today.
Featured Links*
Receive all the latest articles by email!
Receive Real-Time & Monthly WindowSecurity.com article updates in your mailbox. Enter your email below! Click for Real-Time sample & Monthly sample
Become a WindowSecurity.com member!
Discuss your security issues with thousands of other network security experts. Click here to join!