Free Managemnt Baseline Security Analysis (MBSA) Vulnerability Assessment Trustworthy Computing Scanner Misconfigurations Remediation Guidance http://www.onafree.com/Lists/Announcements/DispForm.aspx?ID=13&Source=http%3A%2F%2Fwww%2Eonafree%2Ecom%2Fdefault%2Easpx

 

(888)ITISJob.Net -   Information Technology Information Systems Job Network specializing in Managemnt Baseline Security Analysis (MBSA) Vulnerability Assessment

(888)Nets-Expert.Org - the Network of Experts Organization providing Expert Witness Testimony and Computer Litigation Support Services email@Nets-Expert.Org

(305)6384-397

Dr. A, & S. Rushinek, Ph.D. U. of Miami Professor, eMail@OnAFree.com , 1205 Mariposa Ave. #208, Coral Gables Fl, 33146

Accounting and Computer Information Systems Dept., Business School,  417 Jenkins Bldg, U of Miami, Coral Gables Fl, 33124

 

Checking the standard fare (blank or easily guessed user passwords, auto-admin login, unnecessary services, etc), MBSA also scans for unprotected servers; looking for Web servers that haven't run the lockdown tool or that are still running the IIS sample code. Of particular value is MBSA's ability to scan multiple instances of server, evaluating the authentication mode, looking for blank password and checking for privilege escalation opportunities exposed via the Server service account, among other items. While not many individuals are running full blown installs, how many people are aware that many applications, such as Visio Enterprise, install mini-versions of Server (known as MSDE) with a blank SA password?! MBSA detects each installed instance and provides detailed remediation information.

 

Computer name:

WORKGROUP\GWR

IP address:

127.0.0.1

Security report name:

WORKGROUP - GWR (5-1-2006 12-41 AM)

Scan date:

5/1/2006 12:41 AM

Scanned with MBSA version:

2.0.5029.2

Catalog synchronization date:

2006-04-18T17:28:05Z

Security update catalog:

Microsoft Update (offline)

Security assessment:

Incomplete Scan (Could not complete one or more requested checks.)

 

Security Update Scan Results

 

  Score  

Issue 

Result 

Office Security Updates

3 security updates are missing. 2 service packs or update rollups are missing.

What was scanned      Result details      How to correct this

 

 

Windows Security Updates

71 security updates are missing. 3 service packs or update rollups are missing.

What was scanned      Result details      How to correct this

 

 

 

Windows Scan Results

 

Administrative Vulnerabilities

 

  Score  

Issue 

Result 

Windows Firewall

Windows Firewall tests cannot be done due to an error. (0x8004100a)

               How to correct this

 

 

File System

Not all hard drives are using the NTFS file system.

What was scanned      Result details      How to correct this

 

 

Automatic Updates

The Automatic Updates feature is disabled on this computer.

What was scanned                How to correct this

 

 

Incomplete Updates

No incomplete software update installations were found.

What was scanned                How to correct this

 

 

Local Account Password Test

No user accounts have simple passwords.

What was scanned      Result details

 

 

Guest Account

The Guest account is disabled on this computer.

What was scanned     

 

 

Restrict Anonymous

Computer is properly restricting anonymous access.

What was scanned     

 

 

Administrators

No more than 2 Administrators were found on this computer.

What was scanned      Result details

 

 

Autologon

This check was skipped because the computer is not joined to a domain.

What was scanned     

 

 

Password Expiration

This check was skipped because the computer is not joined to a domain.

What was scanned     

 

 

 

Additional System Information

 

  Score  

Issue 

Result 

Auditing

This check was skipped because the computer is not joined to a domain.

What was scanned                How to correct this

 

 

Services

Some potentially unnecessary services are installed.

What was scanned      Result details      How to correct this

 

 

Shares

No shares are present on your computer.

What was scanned               

 

 

Windows Version

Computer is running Windows 2000 or greater.

What was scanned               

 

 

 

Internet Information Services (IIS) Scan Results

 

Administrative Vulnerabilities

 

  Score  

Issue 

Result 

IIS Lockdown Tool

The IIS Lockdown tool has not been run on the machine.

What was scanned                How to correct this

 

 

Sample Applications

Some IIS sample applications are installed.

What was scanned      Result details      How to correct this

 

 

Parent Paths

Parent paths are enabled in some web sites and/or virtual directories.

What was scanned      Result details      How to correct this

 

 

IISAdmin Virtual Directory

IISADMPWD virtual directory is not present.

What was scanned     

 

 

MSADC and Scripts Virtual Directories

The MSADC and Scripts virtual directories are not present.

What was scanned     

 

 

 

Additional System Information

 

  Score  

Issue 

Result 

IIS Logging Enabled

Some web or FTP sites are not using the recommended logging options.

What was scanned      Result details      How to correct this

 

 

 

SQL Server Scan Results

 

Instance (default)

 

Administrative Vulnerabilities

 

  Score  

Issue 

Result 

CmdExec role

CmdExec is not restricted to sysadmin.

What was scanned                How to correct this

 

 

SQL Server/MSDE Security Mode

SQL Server and/or MSDE authentication mode is set to SQL Server and/or MSDE and Windows (Mixed Mode).

What was scanned                How to correct this

 

 

Service Accounts

SQL Server, SQL Server Agent, MSDE and/or MSDE Agent service accounts should not be members of the local Administrators group or run as LocalSystem.

What was scanned      Result details      How to correct this

 

 

Sysadmin role members

BUILTIN\Administrators group should not be part of sysadmin role.

What was scanned                How to correct this

 

 

Sysadmins

No more than 2 members of sysadmin role are present.

What was scanned     

 

 

Exposed SQL Server/MSDE Password

The 'sa' password and SQL service account password are not exposed in text files.

What was scanned      Result details

 

 

 

SQL Server/MSDE Account Password Test

No SQL user accounts have weak passwords.

What was scanned     

 

 

Guest Account

The Guest account is not enabled in any of the databases.

What was scanned     

 

 

 

Instance MICROSOFTSMLBIZ

 

Administrative Vulnerabilities

 

  Score  

Issue 

Result 

Service Accounts

SQL Server, SQL Server Agent, MSDE and/or MSDE Agent service accounts should not be members of the local Administrators group or run as LocalSystem.

What was scanned      Result details      How to correct this

 

 

Sysadmin role members

BUILTIN\Administrators group should not be part of sysadmin role.

What was scanned                How to correct this

 

 

Sysadmins

No more than 2 members of sysadmin role are present.

What was scanned     

 

 

Exposed SQL Server/MSDE Password

The 'sa' password and SQL service account password are not exposed in text files.

What was scanned      Result details

 

 

SQL Server/MSDE Security Mode

SQL Server and/or MSDE authentication mode is set to Windows Only.

What was scanned     

 

 

Registry Permissions

The Everyone group does not have more than Read access to the SQL Server and/or MSDE registry keys.

What was scanned     

 

 

CmdExec role

CmdExec is restricted to sysadmin only.

What was scanned     

 

 

Folder Permissions

Permissions on the SQL Server and/or MSDE installation folders are set properly.

What was scanned     

 

 

Guest Account

The Guest account is not enabled in any of the databases.

What was scanned     

 

 

SQL Server/MSDE Account Password Test

The check was skipped because SQL Server and/or MSDE is operating in Windows Only authentication mode.

What was scanned     

 

 

 

Desktop Application Scan Results

 

Administrative Vulnerabilities

 

  Score  

Issue 

Result 

IE Zones

Internet Explorer zones have secure settings for all users.

What was scanned     

 

 

Macro Security

4 Microsoft Office product(s) are installed. No issues were found.

What was scanned      Result details

 

 

 


2nd Scan After Connecting to the WWW

 

Computer name:

WORKGROUP\GWR

IP address:

71.196.83.214

Security report name:

WORKGROUP - GWR (5-1-2006 12-44 AM)

Scan date:

5/1/2006 12:44 AM

Scanned with MBSA version:

2.0.5029.2

Catalog synchronization date:

 

Security update catalog:

Microsoft Update

Security assessment:

Incomplete Scan (Could not complete one or more requested checks.)

 

Security Update Scan Results

 

  Score  

Issue 

Result 

Office Security Updates

3 security updates are missing. 2 service packs or update rollups are missing.

What was scanned      Result details      How to correct this

 

 

Windows Security Updates

71 security updates are missing. 4 service packs or update rollups are missing.

What was scanned      Result details      How to correct this

 

 

 

Windows Scan Results

 

Administrative Vulnerabilities

 

  Score  

Issue 

Result 

Windows Firewall

Windows Firewall tests cannot be done due to an error. (0x8004100a)

               How to correct this

 

 

File System

Not all hard drives are using the NTFS file system.

What was scanned      Result details      How to correct this

 

 

Automatic Updates

The Automatic Updates feature is disabled on this computer.

What was scanned                How to correct this

 

 

Incomplete Updates

No incomplete software update installations were found.

What was scanned                How to correct this

 

 

Local Account Password Test

No user accounts have simple passwords.

What was scanned      Result details

 

 

Guest Account

The Guest account is disabled on this computer.

What was scanned     

 

 

Restrict Anonymous

Computer is properly restricting anonymous access.

What was scanned     

 

 

Administrators

No more than 2 Administrators were found on this computer.

What was scanned      Result details

 

 

Autologon

This check was skipped because the computer is not joined to a domain.

What was scanned     

 

 

Password Expiration

This check was skipped because the computer is not joined to a domain.

What was scanned     

 

 

 

Additional System Information

 

  Score  

Issue 

Result 

Auditing

This check was skipped because the computer is not joined to a domain.

What was scanned                How to correct this

 

 

Services

Some potentially unnecessary services are installed.

What was scanned      Result details      How to correct this

 

 

Shares

No shares are present on your computer.

What was scanned               

 

 

Windows Version

Computer is running Windows 2000 or greater.

What was scanned               

 

 

 

Internet Information Services (IIS) Scan Results

 

Administrative Vulnerabilities

 

  Score  

Issue 

Result 

IIS Lockdown Tool

The IIS Lockdown tool has not been run on the machine.

What was scanned                How to correct this

 

 

Sample Applications

Some IIS sample applications are installed.

What was scanned      Result details      How to correct this

 

 

Parent Paths

Parent paths are enabled in some web sites and/or virtual directories.

What was scanned      Result details      How to correct this

 

 

IISAdmin Virtual Directory

IISADMPWD virtual directory is not present.

What was scanned     

 

 

MSADC and Scripts Virtual Directories

The MSADC and Scripts virtual directories are not present.

What was scanned     

 

 

 

Additional System Information

 

  Score  

Issue 

Result 

IIS Logging Enabled

Some web or FTP sites are not using the recommended logging options.

What was scanned      Result details      How to correct this

 

 

 

SQL Server Scan Results

 

Instance (default)

 

Administrative Vulnerabilities

 

  Score  

Issue 

Result 

CmdExec role

CmdExec is not restricted to sysadmin.

What was scanned                How to correct this

 

 

SQL Server/MSDE Security Mode

SQL Server and/or MSDE authentication mode is set to SQL Server and/or MSDE and Windows (Mixed Mode).

What was scanned                How to correct this

 

 

Service Accounts

SQL Server, SQL Server Agent, MSDE and/or MSDE Agent service accounts should not be members of the local Administrators group or run as LocalSystem.

What was scanned      Result details      How to correct this

 

 

Sysadmin role members

BUILTIN\Administrators group should not be part of sysadmin role.

What was scanned                How to correct this

 

 

Sysadmins

No more than 2 members of sysadmin role are present.

What was scanned     

 

 

Exposed SQL Server/MSDE Password

The 'sa' password and SQL service account password are not exposed in text files.

What was scanned      Result details

 

 

SQL Server/MSDE Account Password Test

No SQL user accounts have weak passwords.

What was scanned     

 

 

Guest Account

The Guest account is not enabled in any of the databases.

What was scanned     

 

 

 

Instance MICROSOFTSMLBIZ

 

Administrative Vulnerabilities

 

  Score  

Issue 

Result 

Service Accounts

SQL Server, SQL Server Agent, MSDE and/or MSDE Agent service accounts should not be members of the local Administrators group or run as LocalSystem.

What was scanned      Result details      How to correct this

 

 

Sysadmin role members

BUILTIN\Administrators group should not be part of sysadmin role.

What was scanned                How to correct this

 

 

Sysadmins

No more than 2 members of sysadmin role are present.

What was scanned     

 

 

Exposed SQL Server/MSDE Password

The 'sa' password and SQL service account password are not exposed in text files.

What was scanned      Result details

 

 

SQL Server/MSDE Security Mode

SQL Server and/or MSDE authentication mode is set to Windows Only.

What was scanned     

 

 

Registry Permissions

The Everyone group does not have more than Read access to the SQL Server and/or MSDE registry keys.

What was scanned     

 

 

CmdExec role

CmdExec is restricted to sysadmin only.

What was scanned     

 

 

Folder Permissions

Permissions on the SQL Server and/or MSDE installation folders are set properly.

What was scanned     

 

 

Guest Account

The Guest account is not enabled in any of the databases.

What was scanned     

 

 

SQL Server/MSDE Account Password Test

The check was skipped because SQL Server and/or MSDE is operating in Windows Only authentication mode.

What was scanned     

 

 

 

Desktop Application Scan Results

 

Administrative Vulnerabilities

 

  Score  

Issue 

Result 

IE Zones

Internet Explorer zones have secure settings for all users.

What was scanned     

 

 

Macro Security

4 Microsoft Office product(s) are installed. No issues were found.

What was scanned      Result details