Yorkshire Divers

Deep Blue Technical
Go Back   YD Scuba Diving Forums & Community > Non-Diving Related Forums > Technology
User Name
Password

Welcome to the YD Scuba forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions, articles and access our other FREE features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload your own photos and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact contact support.

Technology: Discuss Securing Windows Time service in the Non-Diving Related Forums forums: Any windows folk out there that can assist. We had some penertration tests performed on some servers, one of the ...

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 14-02-08, 11:55 AM
kuki9591's Avatar
kuki9591 kuki9591 is offline
Member
 

Join Date: Oct 2005
Location: Birmingham
Posts: 397
kuki9591 swims in warm waterkuki9591 swims in warm waterkuki9591 swims in warm waterkuki9591 swims in warm waterkuki9591 swims in warm waterkuki9591 swims in warm waterkuki9591 swims in warm waterkuki9591 swims in warm waterkuki9591 swims in warm waterkuki9591 swims in warm waterkuki9591 swims in warm water
Securing Windows Time service

Any windows folk out there that can assist.

We had some penertration tests performed on some servers, one of the few things picked up was the Windows Time Service


Observation: The NTP service running on the server disclosed technical information that would be of use to an attacker in fingerprinting the Operating System on the server.

Recommendation: The configuration of the NTP service should be amended to prevent this type of disclosure

Would anybody have a clue as to how the time service can be secured from this type of scan?

Windows Server 2003 Enterprise SP2
Patched to Jan 2008

Thanks in advance.

Mike
__________________
Every breath you take, every dive you make, I will be watching you!!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 14-02-08, 01:44 PM
MattS's Avatar
MattS MattS is offline
Senior Member
 

Join Date: Jul 2004
Location: Emsworth
Posts: 1,677
MattS is a scuba diver - cold waterMattS is a scuba diver - cold waterMattS is a scuba diver - cold waterMattS is a scuba diver - cold waterMattS is a scuba diver - cold waterMattS is a scuba diver - cold waterMattS is a scuba diver - cold waterMattS is a scuba diver - cold waterMattS is a scuba diver - cold waterMattS is a scuba diver - cold waterMattS is a scuba diver - cold water
Quote:
Originally Posted by kuki9591
Any windows folk out there that can assist.

We had some penertration tests performed on some servers, one of the few things picked up was the Windows Time Service


Observation: The NTP service running on the server disclosed technical information that would be of use to an attacker in fingerprinting the Operating System on the server.

Recommendation: The configuration of the NTP service should be amended to prevent this type of disclosure

Would anybody have a clue as to how the time service can be secured from this type of scan?

Windows Server 2003 Enterprise SP2
Patched to Jan 2008
There are going to be several ways it could be done and the correct method will depend on your risk assessment. Are you worried about systems inside the local network knowing what OS the server is running?

The way I normally go about things is to restrict access at the LAN borders. Only allow NTP between the server/s and the trusted time providers. If you are a bit paranoid, fit an atomic or radio clock to a Domain Controller or two, use those as the source for all other time requests, and completely shut the door to NTP through the perimeter on the firewall.

If that still isn't good enough, happy trawling
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 14-02-08, 01:49 PM
kuki9591's Avatar
kuki9591 kuki9591 is offline
Member
 

Join Date: Oct 2005
Location: Birmingham
Posts: 397
kuki9591 swims in warm waterkuki9591 swims in warm waterkuki9591 swims in warm waterkuki9591 swims in warm waterkuki9591 swims in warm waterkuki9591 swims in warm waterkuki9591 swims in warm waterkuki9591 swims in warm waterkuki9591 swims in warm waterkuki9591 swims in warm waterkuki9591 swims in warm water
Thanks for the response, NTP is already closed on the firewalls, the pentesters ran the scan on the same subnets as the servers.

Google used to be my friend until this little gem came along.

thanks again.

Mike
__________________
Every breath you take, every dive you make, I will be watching you!!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 14-02-08, 02:21 PM
MattS's Avatar
MattS MattS is offline
Senior Member
 

Join Date: Jul 2004
Location: Emsworth
Posts: 1,677
MattS is a scuba diver - cold waterMattS is a scuba diver - cold waterMattS is a scuba diver - cold waterMattS is a scuba diver - cold waterMattS is a scuba diver - cold waterMattS is a scuba diver - cold waterMattS is a scuba diver - cold waterMattS is a scuba diver - cold waterMattS is a scuba diver - cold waterMattS is a scuba diver - cold waterMattS is a scuba diver - cold water
Quote:
Originally Posted by kuki9591
Thanks for the response, NTP is already closed on the firewalls, the pentesters ran the scan on the same subnets as the servers.
You mean they came in, ran a standard automated test suite, handed over the output and charged a fortune

You have to question the validity of the test to your own circumstances. There is usually a lot of other traffic floating around a typical subnet announcing the Windows servers to anyone able to drive Ethereal.

Quote:
Google used to be my friend until this little gem came along.
As far as I know there is no way to change the reply from the time service on Windows servers. Which is what the security experts mean when they say
Quote:
technical information that would be of use to an attacker in fingerprinting the Operating System on the server.
The choice seems to be;
1. Accept that any host able to query the time service can discover it is a Windows server.

2. Completely replace the time syncronisation infrastructure across the Active Directory domain.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 14-02-08, 02:48 PM
thehappychappy's Avatar
thehappychappy thehappychappy is offline
Exile
Recent Blog: Isn?t it ironic?
 

Join Date: Oct 2005
Location: Hamilton, Scotland & Bristol England
Posts: 1,950
thehappychappy is a scuba diver - cold waterthehappychappy is a scuba diver - cold waterthehappychappy is a scuba diver - cold waterthehappychappy is a scuba diver - cold waterthehappychappy is a scuba diver - cold waterthehappychappy is a scuba diver - cold waterthehappychappy is a scuba diver - cold waterthehappychappy is a scuba diver - cold waterthehappychappy is a scuba diver - cold waterthehappychappy is a scuba diver - cold waterthehappychappy is a scuba diver - cold water
If your not allowing NTP traffic outside of your "trusted perimeter" then its not really an issue.

your risk assessment will most likely mitigate the attack chances via internal security mechanisms.

i.e. only authorised personal on-site, only approved equipment allowed to connect to lan.


Time is critical in the AD domain and its just not worth the risk trying to be too paranoid about it.

Time needs to get to all servers and within the AD structure the client machines.

It's the clients that can be the tricky bit.

I'm assuming your clients and some servers in a distributed environment are all over the place.

Davie



P.S there is a decent article on Windows Time Service at technet http://technet2.microsoft.com/Window...0c0181033.mspx
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6 (permalink)  
Old 14-02-08, 03:45 PM
kuki9591's Avatar
kuki9591 kuki9591 is offline
Member
 

Join Date: Oct 2005
Location: Birmingham
Posts: 397
kuki9591 swims in warm waterkuki9591 swims in warm waterkuki9591 swims in warm waterkuki9591 swims in warm waterkuki9591 swims in warm waterkuki9591 swims in warm waterkuki9591 swims in warm waterkuki9591 swims in warm waterkuki9591 swims in warm waterkuki9591 swims in warm waterkuki9591 swims in warm water
Quote:
Originally Posted by MattS
You mean they came in, ran a standard automated test suite, handed over the output and charged a fortune
Well, our customer paid for the test, it's a 6 monthly thing they do.

Quote:
Originally Posted by MattS
You have to question the validity of the test to your own circumstances.
yes, raised the integrity of their testing with the SDM, I have other issues with it.

Thanks again
__________________
Every breath you take, every dive you make, I will be watching you!!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #7 (permalink)  
Old 14-02-08, 03:48 PM
kuki9591's Avatar
kuki9591 kuki9591 is offline
Member
 

Join Date: Oct 2005
Location: Birmingham
Posts: 397
kuki9591 swims in warm waterkuki9591 swims in warm waterkuki9591 swims in warm waterkuki9591 swims in warm waterkuki9591 swims in warm waterkuki9591 swims in warm waterkuki9591 swims in warm waterkuki9591 swims in warm waterkuki9591 swims in warm waterkuki9591 swims in warm waterkuki9591 swims in warm water
Quote:
Originally Posted by thehappychappy
I'm assuming your clients and some servers in a distributed environment are all over the place.
Not quite, it's a webhosting environment, no client machines, 100% server environment.

Thanks for the technet link.

Mike
__________________
Every breath you take, every dive you make, I will be watching you!!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



Sponsored Links

Yorkshire Divers - RSS Feed
All times are GMT +1. The time now is 06:08 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.0.0 RC6
Trademark and all rights reserved : © YD.com Ltd (2006)
YD.com Ltd (Registered in England - 05886696)
Other sites : Golf Clubs | New Premiership Football Kits | MP3 Portable Players | MP3 Players For Sale | Replica Football Kits

Forums Directory