Channel News and Analysis - Channel Insider
Empowering the next generation Channel
 

Sponsored Links
  • Get up and running in as quickly as 30 days with BI. Learn how today.
  • FREE Securing Smartphones & Tablets for Dummies Book from Sophos
  • 5 New Technologies That Will Change Enterprise ITAdvertisement
  • Build an IT Infrastructure That Delivers the Future

  •  

    Microsoft Tightens Windows Server 2003 Security

    in Channel News and Analysis



    Article Rating:starstarstarstarstar / 0
    Article Views: 2309

    Microsoft ships the first release candidate for Windows Server 2003 Service Pack 1, a security update that makes many of the changes in Windows XP SP2, plus many new network access security enhancements.

    Rate This Article:
    Add This Article To:

    Microsoft Corp. has made available for download the first release candidate of a major security update to Windows Server 2003.

    The 316MB download contains many of the changes that Windows XP Service Pack 2 brought to that operating system against buffer overflows and other common attacks, including specific support for "no execute" processors.

    How has Microsoft's monthly patch release changed the patching habits of enterprises? Find out here.

    It also adds a new Security Configuration Wizard, which uses a role-based approach to remove unnecessary services, diminishing "the attack surface." The wizard asks a series of questions about the tasks performed by the server and disables services unnecessary to those roles. The wizard is not installed by default.

    To further tighten security on new installations, the Post-setup Security Update Wizard blocks all incoming traffic until the latest updates are applied and Automatic Updates are configured.

    The Service Pack adds the Windows Firewall, perhaps the most significant addition to Windows XP SP2. The new firewall is manageable using Windows group policy. Just as with Windows XP SP2, Microsoft acknowledges that the changes in Windows Server 2003 SP1 are basic enough to the behavior of the operating system that they may affect application behavior. The company argues that the improvements are important enough that applications should be changed to accommodate them.

    For insights on security coverage around the Web, check out eWEEK.com Security Center Editor Larry Seltzer's Weblog.

    SP1 enhances authentication for RPC and DCOM interfaces, which have been popular avenues for attack in the past. A new Network Access Quarantine Control delays access to remote networks until the configuration of those networks has been audited. And VPN Quarantine allows the system to require that clients connecting through a virtual private network have the latest security updates. Finally, an auditing capability has been added for the IIS Metabase, the XML-based data store for the Internet Information Server Web server.

    Check out eWEEK.com's for the latest security news, reviews and analysis.




    comments dic


     
     
    >>> More Channel News and Analysis Articles          >>> More By Larry Seltzer
     


     



    channel chatter


    HTML PLAIN TEXT

    Keep on top of news for VARs and Resellers with CI's Weekly Newsletter and Alerts.


    [ci] feeds
    XML
    Add Channel News, Product Reviews, Trends and Analysis to your RSS newsreader or My Yahoo!


     


    CHANNEL SPONSORED RESOURCE CENTER
     
     
     
    Start the New Year with business intelligence—it’s a smart move
    Join us on February 1 for an encore rebroadcast at either 5 am or 12 noon EST and discover how business intelligence (BI) supports companies in uncertain business and economic climates. Get expert advice on how to create a strategy that fits your organization's needs and budget and see how quickly it can pay for itself.
    Click Here
     
    Security and Availability Essentials for Running Your Business in the Cloud
    Are you moving to the cloud? Find out what every IT professional should know about security and availability before moving to the cloud. Hear what a security provider’s own CSO has to say.
    Watch Video
    A new algorithm automatically identifies relationships between variables to help reduce researcher prejudice.
    Click HereAdvertisement