Click here to get back home

Best practices regarding anti-virus software on production webserver

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Best practices regarding anti-virus software on production webserver bostonguy 09-12-2007
Posted by Leythos on September 13, 2007, 12:56 pm
Please log in for more thread options
says...
> Hello,
>
> i wouldn't go so straight...
> Web servers can be protected by isa reverse proxy, so there won't be any
> direct tcp connection.
> They may be more protected through:
> -renamed admin account with strong password
> -netbios disabled if possible
> -no direct connection to outside
> -pass the MBSA test at least
> -Remove default website
> -hisec gpo template
> -disable unused service (remote registry...)
> -never surf from these servers

I wasn't suggesting that AV was the entire solution, but it's part of
the solution.

--

Leythos
- Igitur qui desiderat pacem, praeparet bellum.
- Calling an illegal alien an "undocumented worker" is like calling a
drug dealer an "unlicensed pharmacist"
spam999free@rrohio.com (remove 999 for proper email address)

Posted by S. Pidgorny on September 18, 2007, 4:39 am
Please log in for more thread options
G'day:


> If it's windows it need AV protection if it's got any exposure to
> external access by any means.

No. User access (most often, internal), more like it. The rule of thumb: if
those not considered system administrators can upload data and open
documents/run programs on the system - it probably needs an antivirus. If
it's a file or application server (files can be uploaded but not run) - need
a way to clean up stores.

Just external access is nothing. Besides, the very notion of "external" v
"internal" doesn't make much sense in enterprise environments where network
connections are not effectively controlled.

--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-

* http://sl.mvps.org * http://msmvps.com/blogs/sp *



Similar ThreadsPosted
antivirus software questions September 19, 2006, 2:25 pm
OWA and antivirus software for Exchange October 24, 2006, 9:00 pm
Local Logon Access to Production Servers September 13, 2007, 12:04 pm
User can't connect to particular webserver from his PC. December 22, 2005, 6:08 pm
Antivirus System July 30, 2005, 7:09 pm
antivirus for 64 bit windows April 29, 2007, 9:10 am
Affordable Antivirus for servers? August 23, 2005, 10:11 am
File Server Permissions - Best Practices August 10, 2006, 4:56 am
"Best Practices" Guidelines for New Network Admins December 26, 2006, 1:59 pm
Antivirus+Firewall for Windows Server 2003 May 25, 2006, 9:59 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap