View Single Post
  #2 (permalink)  
Old 14-02-08, 01:44 PM
MattS's Avatar
MattS MattS is offline
Senior Member
 

Join Date: Jul 2004
Location: Emsworth
Posts: 1,731
MattS communes with fishMattS communes with fishMattS communes with fishMattS communes with fishMattS communes with fishMattS communes with fishMattS communes with fishMattS communes with fishMattS communes with fishMattS communes with fishMattS communes with fish
Quote:
Originally Posted by kuki9591
Any windows folk out there that can assist.

We had some penertration tests performed on some servers, one of the few things picked up was the Windows Time Service


Observation: The NTP service running on the server disclosed technical information that would be of use to an attacker in fingerprinting the Operating System on the server.

Recommendation: The configuration of the NTP service should be amended to prevent this type of disclosure

Would anybody have a clue as to how the time service can be secured from this type of scan?

Windows Server 2003 Enterprise SP2
Patched to Jan 2008
There are going to be several ways it could be done and the correct method will depend on your risk assessment. Are you worried about systems inside the local network knowing what OS the server is running?

The way I normally go about things is to restrict access at the LAN borders. Only allow NTP between the server/s and the trusted time providers. If you are a bit paranoid, fit an atomic or radio clock to a Domain Controller or two, use those as the source for all other time requests, and completely shut the door to NTP through the perimeter on the firewall.

If that still isn't good enough, happy trawling
__________________
www.divesearch.co.uk
www.bluewaterscuba.co.uk

"Give a man a fish and he will eat for a day. Teach him how to fish, and he will sit in a boat and drink beer all day." - anon
"If you resolve to give up smoking, drinking and sex, you don't actually live longer; it just seems longer." - Clement Freud
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote