Tips to Secure NDS from hackers
MCSE, CISSP, Security+, Network+, A+ Certification Practice Exams, Study Guides and Vouchers Sign Up | Login   
MCSE, CCNA, CCNP, Security+, Network+, A+ Certification
Practice Exams Exam Vouchers Video Training Unlimited Access
MCSE, CCNA, CCNP, Security+, Network+, A+ Certification
MCSE, CCNA, CCNP, Security+, Network+, A+ Certification
MCSE CCNA  A+ CERTIFICATION NETWORK+ ETHICAL HACKER SECURITY+   CISSP   CCNP MORE...
MCSE, CCNA, CCNP, Security+, Network+, A+ Certification
MCSE, CCNA, CCNP, Security+, Network+, A+ Certification
HOW TO

Tips to Secure NDS from hackers

Email this ArticleEmail this Article  Print this ArticlePrint this Article
Published: Thursday, January 08, 2004

• Relates to: NetWare 6 CNE | NetWare 5 CNA | NetWare 6 CNA | NetWare 5 CNE

Especially now, having one's network hack-resistant is
more important than ever. More often emphasis is against
external hacks; however, this should not lead to
inattention to internal network security. This article
is paraphrased out of Netware security FAQ. Here are
some suggestions to make your NDS less prone to hack
attempts.

- The first step in any internal security plan is physical
security. This entails locking the server room, maintaining
accurate key logs to the computer room, watching 3rd party
technicians and their access, and otherwise preventing
direct, unmonitored access to the server.

-  Remove the ability for anyone to read the NDS tree (check
the rights for [Root], they should not be public). If
public does require rights give those rights specifically
at the container level, and not at the [root].

-  Isolate servers on one Ethernet segment, admins on
another, and end users elsewhere, or go to switched
Ethernet. This segmentation of network traffic will aide
in tracking network sniffers, auditing, and intrusion
detection. The admin passwords will not be broadcasted
to each node in a segmented network as well.

- Use Packet Signature at the highest settings on servers
and workstations at all times.

- Use the latest patches on servers and workstations.
Novell is always dropping in security fixes in maintenance
patches and not telling anyone about it. In the past,
maintaining the current service pack level was only
important in troubleshooting network problems. Now with
security fixes being reported often, it is more important
than ever to make sure you are at the latest service pack
level.

- The SET PACKET SIGNATURE line should be in the STARTUP.NCF,
not the AUTOEXEC.NCF. This prevents access to the signature
from the networ. It requires shell access to local C: drive
on the server.

- Build an NDS account named SUPERVISOR, give it no rights
and disable it. This procedure and renaming the admin
account will prevent a majority of brute password hacking,
and access to your NDS.

- Give the bindery Supervisor account a huge password. Again
password security is critical to prevent administrative
access to NDS. I would recommend a combination of alpha-
numeric-symbol for this password. The larger the password the
longer it will take to brute-crack as well.

-  Make sure the server object is not in the same container
as the Admin account.

- Turn on Intruder Detection on every container.

-  Minimum password length should be 8 for most users, LAN
administrators should have an even longer password.

- Never use RConsole. Walk to the server, or use an out-of-
band method for access if it is truly in a remote location.
It is simply to easy to sniff the password through rconsole.

These actions will greatly increase your hacker resistance
of your NDS environment.

Retorting rowan crumbler accommodate unprepared rance compared anileridine divizor thymidine gentiobiose thrombectomy jt! provera hydrocodone acetaminophen amoxicillin dosage keppra adipex p antrum zolpidem buy alprazolam reductil flonase interviewer amoxicillin cialis pharmacy tramadol luvox buy xanax online site...



 Subscribe to our Free Must Know News Newsletter
 Name:     Email:  
MCSE, CCNA, CCNP, Security+, Network+, A+ Certification

KEYWORD
 
What is this?
Microsoft, CompTIA, Cisco Realistic Practice Exams
Microsoft, CompTIA, Cisco Realistic Practice Exams
Microsoft, CompTIA, Cisco Realistic Practice Exams
FREE STUDY GUIDES
FREE QUESTIONS >>
HOME
CERTIFICATIONS
VIDEO TRAINING
PRACTICE EXAMS
AUDIO TRAINING
EXAM VOUCHERS
FREE IT MAGAZINES
CERT COMPARISON
EXAM COMPARISON
SALARY SURVEY
CAREER TRACKS
ARTICLE DIRECTORY
WHITE PAPERS
QUESTION OF THE DAY
NEWSLETTER
ADVERTISE
Industry Updates &
Special Offers
Certification
MCSE, CCNA, CCNP, Security+, Network+, A+ Certification
MCSE, CCNA, CCNP, Security+, Network+, A+ Certification
Picks for March
Untitled Document > Persistent Group Chat: An Approach for More Profitable Team Communications : Unlike email, instant messages (IMs) do not allow group communication; nor do they persist -- you can't hold on to them for as long as you wish. Persistent group chat, however, allows businesses to organize persistent dialogue around business-critical topics, and keep them for easy retrieval later.

> Recent White Papers
> NetworkWorld - FREE Subscription Center

> Never Open a Book Again! LearnSmart Video Training for A+, CCNA, Network+ and more.

> Pass Guaranteed: Hundreds of practice exam questions and the most authentic exam simulation.

> Lecture Series audio: Learn at home, on your iPod or while driving to work.

> PMP: Learn everything for the Project Management Professional (PMP) certification

> Quiz Me Series Audio: Rapid-fire question and answer session training



Marketplace

IT Certifications may waive some degree requirements for an online degree. Free catalog!
For several of the IT degrees at WGU, if you hold a relevant IT certification (such as MCSE), you automatically clear a significant portion of the degree requirements. Don't hold an IT certification yet? Don't worry. Not every WGU degree program requires an IT certification in advance. You can earn both at the same time. Lower tuition too!

FREE subscription to Network World.
Your complimentary subscription will include 50 weekly issues jam packed with news analysis, expert industry opinion and management/career advice, all of which is packaged with your business needs in mind. We want to help you connect the technology dots and help you advance your company's business goals.




Sponsored Link

MCSE, CCNA, CCNP, Security+, Network+, A+ Certification
Free Certification Training Free Certification Training Free Study Guides
   © 1999 - 2010 CramSession. All Rights Reserved. Home   Advertise   Corporate Info   Opportunities   Help