Wednesday, March 7, 2012

really isolated

Hi
i read microsoft.com
that "web servers do not require netbios or smb" (sic)
then MS recomends to disable smb by this way:
1) "Clear the Client Microsoft Networks box"
2) "Clear the File and Printer Sharing for Microsoft Networks box"
by this way, web server stays really isolated from the intranet
is this a good practice?
because, by this way
i cant move development files to webserver
and cant do replication
thanks
(this is the link
http://msdn.microsoft.com/library/d...
d89.asp)
atte,
Hernn Castelo
UTN Buenos Aires
. . . . . . . . . . . . . . . . . . . . . . . . .
.The article dicusses;
"Disable all unnecessary protocols, including NetBIOS and SMB. Web servers
do not require NetBIOS or SMB on their Internet-facing network interface
cards (NICs). Disable these protocols to counter the threat of host
enumeration."
So, this is assuming that the web server has multiple nics installed, and
that one is internet facing. I think what's more important is to limit
the number of ports open on the box to 80 and/or 443.
Thanks,
Kevin McDonnell
Microsoft Corporation
This posting is provided AS IS with no warranties, and confers no rights.|||hmm...i see
ok thanks for the reply
atte,
Hernn Castelo
UTN Buenos Aires
. . . . . . . . . . . . . . . . . . . . . . . . .
.
"Kevin McDonnell [MSFT]" <kevmc@.online.microsoft.com> escribi en el mensaje news:rHLgU
nZHEHA.660@.cpmsftngxa06.phx.gbl...
> The article dicusses;
> "Disable all unnecessary protocols, including NetBIOS and SMB. Web servers
> do not require NetBIOS or SMB on their Internet-facing network interface
> cards (NICs). Disable these protocols to counter the threat of host
> enumeration."
> So, this is assuming that the web server has multiple nics installed, and
> that one is internet facing. I think what's more important is to limit
> the number of ports open on the box to 80 and/or 443.
>
> Thanks,
> Kevin McDonnell
> Microsoft Corporation
> This posting is provided AS IS with no warranties, and confers no rights.
>
>

No comments:

Post a Comment