
Is it Time for a Mainframe Security Model?
Latest Industry News: - Perfecting Project Management
- What's New in R2
- Cisco [Hearts] Dell: We Are Not Enemies, But Friends
- Survey
- Dell, EMC Team on Midrange Storage
- Duke Puts Mouse Brains Online
- Next Generation of MOM to be Unveiled
- NTU, Rice To Tackle Computer Chip Power Problems
- Microsoft Virtual Server 2004 Inches Toward Release
- Cisco and IBM Partner for Contact Centers
- MOM 2005 Feels the Love
- MCDST Ugrade Exam Goes Live
- Analysts: Upgrading to Vista SP1 on Intel Chips? Proceed with Caution
- Researchers Seek Cash for Software Flaws
- Lotus 6
- Windows PowerShell
- StorageX
- Evolutionary in Technology, Revolutionary in Impact
- Exit Interview
- To Protect and Secure the Web
The circumstances in which participated in the Microsoft IIS vulnerability patches help to highlight this week vary between Windows 2000 and there are still big iron mainframes, this day is considered as a reference standard in most areas of enterprise computing.
Vulnerability - which requires not only the presence of illegal immigrants itself, but also optional meta search equipment, it can be effective use - and perhaps should not affect the majority of the W indowsN T4 or .0 W indows2 000 devices. However, eEye Digital Security, and Internet security company said first determine the vulnerability of, it is estimated that as many as 50% of the existing Windows NT 4.0 or Windows 2000 installations may be affected.
How do? The answer is simple: IIS and optional Meta search facility - known as Index Server 2.0, W indowsN T4 .0 space, and called on the simple "Indexing Service", in W indows2 000 speeches -- are enabled by default, the configuration or install any operating system. To be precise, illegal immigrants Index Server 4.0 and 2.0 ship, and has launched a state-of-the box, the option of Windows NT 4.0 pack, and the IIS 5.0 and indexing service is installed by default with Windows 2000 Server / Advanced Server.
Administrator can choose whether they want to install either services, in fact, but based on the tragic prognosis from EEye companies, and from other quarters This view, this option is rarely exercised.
Therefore, industry watchers said that many IT organizations may unwittingly has already deployed Windows NT 4.0 or Windows 2000 system and Web and meta-search services installed - and is seriously risk as a result .
"I doubt, the number is far higher than the 50 percent, I do not know from where the number of eEye be, in fact," avers Mr. Russ Cooper people Editors Note Windows NT mailing list BugTraq. "To test whether or not this matter is there is a difficult process, but there are also some of the default installation ." Needless to say, most of the services and functions are not enabled by default in the mainframe environment. According to Ted macneil, the consultant with IBM Global Services strategic outsourcing services, they are under the Andean Bank in Toronto, mainframe security model in many ways diametrically opposed, that is, Windows NT/2000 and most of the other "open" system.
"I believe that the mainframe model is superior to the medium-term, personal computers, networks and open systems environment, and only because it follows the standard: do not expressly permitted is prohibited," he comments. "Other platforms, from what I have seen, following standards: All is not expressly prohibited is permitted. This allows users responsible for the protection of their own, often without the necessary skills, but little or no help from the supplier, which left a large loophole. " In the mainframe environment, then managers must carefully - hard - configure and customize, and the most system services.
In the same way, suggesting Jimujiou Han, the companys cross-platform, IT consulting company in Levittown, New York, which provides software development expertise, mainframe and other platforms, some mainframe operating environment to make it difficult administrator installation services and features that they would like to actually .
"This is so difficult in the mainframe, especially in the [right] os/390 or secondary vocational schools, what to do, you have the power to do so, so that, trying to do what you can not This difficult to do started to take off, even in the absence security. " Conversely, Windows NT/2000 - and even many U NIX L inux operations System - o odles ship with the system service and other potentially dangerous features, and ensure that the state-of-the straight box .
"With Windows 2000 and Windows NT 4.0, the default is a very Order system, which requires managers to ensure that the system," explained Roger seielstad , senior network administrator for advice and infrastructure management specialist Peregrine Systems, Inc., "its significant that is, the default installation Sun Solaris and Red Hat Linux functions number Similarly, many of the services and potentially dangerous start default . " Microsoft may take us a very long road, the new generation of Windows platform - Windows XP Professional Edition and Windows 2002 Server / Advanced Server - more secure simply limit the companys services and function of the operating system installed by default. But According to the NT Bugtraq Cooper, for example, will be a certain degree of alienation is groups, and promote the Windows NT 4.0 and Windows 2000 passed in the first place.
"What kind of name, the Department of the four guys want to do some printing and file sharing? "He asked rhetorical" the truth of the matter is that no one, it [often] have sufficient resources so that they can start with the complete safety devices. " Yesterday announced the vulnerability - as well as the continued preponderance of Denial of Service (DoS) attacks and attacks procedures literally allow an attacker to take complete control of the key tasks of Information System - made it clear that, the extent to which the Windows nt/2000 behind the large metal box, in other important aspects, as well.
"How many mainframe programmer, do you know who can really achieve decline entire mainframe system"? Sanier MISRA challenge the management main on the worlds security practices for Unisys Systems. ", And open systems is that they are new, and [that] the information on how to compromise, more accessible today." Conversely, DOS and other attacks, is almost impossible to successfully abuses of the mainframe system, the advocate to point out that the metal box.
In fact, IBMs zSeries mainframe launch a technology - known as the L PAR- allows administrators to define logical partitions for different workload (testing, production and Web services, for example) in the mainframe environment . This is a result of the isolation and safety data Another application from a single person - even if they are located in the same system. And zSeries mainframes, but also with the use of a feature called - "Plan implementation of the national" - it can prevent programs or services access or implementation of a pre-determined order.
This function is the closest approximation In "br> Windows 2000 and its space courtesy Unisys ES7000 servers, advanced system and the ability to split the workload, In" br> In addition to enhanced security features .
, In the final analysis, most observers agree that, if change is to occur, it will be driven by end-users and software providers.
"I think there will be change in behaviour [users], then It will also combine to shift to software and documentation," Cooper NT Bugtraq, comments, " As a peoples priorities change functions, security, development, and will change the focus their own software, and methods of their software works to security more functional and more easy to manage. " Peregrine Systems seielstad agreed. "Microsoft is still focused on the development of characteristics, in strengthening the user experience, more than quality. These features one of the reasons why they have become leading software vendors, the market, "he said," more and more will require better quality than flashy features. "- Stephen s woyer
Vulnerability - which requires not only the presence of illegal immigrants itself, but also optional meta search equipment, it can be effective use - and perhaps should not affect the majority of the W indowsN T4 or .0 W indows2 000 devices. However, eEye Digital Security, and Internet security company said first determine the vulnerability of, it is estimated that as many as 50% of the existing Windows NT 4.0 or Windows 2000 installations may be affected.
How do? The answer is simple: IIS and optional Meta search facility - known as Index Server 2.0, W indowsN T4 .0 space, and called on the simple "Indexing Service", in W indows2 000 speeches -- are enabled by default, the configuration or install any operating system. To be precise, illegal immigrants Index Server 4.0 and 2.0 ship, and has launched a state-of-the box, the option of Windows NT 4.0 pack, and the IIS 5.0 and indexing service is installed by default with Windows 2000 Server / Advanced Server.
Administrator can choose whether they want to install either services, in fact, but based on the tragic prognosis from EEye companies, and from other quarters This view, this option is rarely exercised.
Therefore, industry watchers said that many IT organizations may unwittingly has already deployed Windows NT 4.0 or Windows 2000 system and Web and meta-search services installed - and is seriously risk as a result .
"I doubt, the number is far higher than the 50 percent, I do not know from where the number of eEye be, in fact," avers Mr. Russ Cooper people Editors Note Windows NT mailing list BugTraq. "To test whether or not this matter is there is a difficult process, but there are also some of the default installation ." Needless to say, most of the services and functions are not enabled by default in the mainframe environment. According to Ted macneil, the consultant with IBM Global Services strategic outsourcing services, they are under the Andean Bank in Toronto, mainframe security model in many ways diametrically opposed, that is, Windows NT/2000 and most of the other "open" system.
"I believe that the mainframe model is superior to the medium-term, personal computers, networks and open systems environment, and only because it follows the standard: do not expressly permitted is prohibited," he comments. "Other platforms, from what I have seen, following standards: All is not expressly prohibited is permitted. This allows users responsible for the protection of their own, often without the necessary skills, but little or no help from the supplier, which left a large loophole. " In the mainframe environment, then managers must carefully - hard - configure and customize, and the most system services.
In the same way, suggesting Jimujiou Han, the companys cross-platform, IT consulting company in Levittown, New York, which provides software development expertise, mainframe and other platforms, some mainframe operating environment to make it difficult administrator installation services and features that they would like to actually .
"This is so difficult in the mainframe, especially in the [right] os/390 or secondary vocational schools, what to do, you have the power to do so, so that, trying to do what you can not This difficult to do started to take off, even in the absence security. " Conversely, Windows NT/2000 - and even many U NIX L inux operations System - o odles ship with the system service and other potentially dangerous features, and ensure that the state-of-the straight box .
"With Windows 2000 and Windows NT 4.0, the default is a very Order system, which requires managers to ensure that the system," explained Roger seielstad , senior network administrator for advice and infrastructure management specialist Peregrine Systems, Inc., "its significant that is, the default installation Sun Solaris and Red Hat Linux functions number Similarly, many of the services and potentially dangerous start default . " Microsoft may take us a very long road, the new generation of Windows platform - Windows XP Professional Edition and Windows 2002 Server / Advanced Server - more secure simply limit the companys services and function of the operating system installed by default. But According to the NT Bugtraq Cooper, for example, will be a certain degree of alienation is groups, and promote the Windows NT 4.0 and Windows 2000 passed in the first place.
"What kind of name, the Department of the four guys want to do some printing and file sharing? "He asked rhetorical" the truth of the matter is that no one, it [often] have sufficient resources so that they can start with the complete safety devices. " Yesterday announced the vulnerability - as well as the continued preponderance of Denial of Service (DoS) attacks and attacks procedures literally allow an attacker to take complete control of the key tasks of Information System - made it clear that, the extent to which the Windows nt/2000 behind the large metal box, in other important aspects, as well.
"How many mainframe programmer, do you know who can really achieve decline entire mainframe system"? Sanier MISRA challenge the management main on the worlds security practices for Unisys Systems. ", And open systems is that they are new, and [that] the information on how to compromise, more accessible today." Conversely, DOS and other attacks, is almost impossible to successfully abuses of the mainframe system, the advocate to point out that the metal box.
In fact, IBMs zSeries mainframe launch a technology - known as the L PAR- allows administrators to define logical partitions for different workload (testing, production and Web services, for example) in the mainframe environment . This is a result of the isolation and safety data Another application from a single person - even if they are located in the same system. And zSeries mainframes, but also with the use of a feature called - "Plan implementation of the national" - it can prevent programs or services access or implementation of a pre-determined order.
This function is the closest approximation In "br> Windows 2000 and its space courtesy Unisys ES7000 servers, advanced system and the ability to split the workload, In" br> In addition to enhanced security features .
, In the final analysis, most observers agree that, if change is to occur, it will be driven by end-users and software providers.
"I think there will be change in behaviour [users], then It will also combine to shift to software and documentation," Cooper NT Bugtraq, comments, " As a peoples priorities change functions, security, development, and will change the focus their own software, and methods of their software works to security more functional and more easy to manage. " Peregrine Systems seielstad agreed. "Microsoft is still focused on the development of characteristics, in strengthening the user experience, more than quality. These features one of the reasons why they have become leading software vendors, the market, "he said," more and more will require better quality than flashy features. "- Stephen s woyer
Latest Industry News: - Perfecting Project Management
- What's New in R2
- Cisco [Hearts] Dell: We Are Not Enemies, But Friends
- Survey
- Dell, EMC Team on Midrange Storage
- Duke Puts Mouse Brains Online
- Next Generation of MOM to be Unveiled
- NTU, Rice To Tackle Computer Chip Power Problems
- Microsoft Virtual Server 2004 Inches Toward Release
- Cisco and IBM Partner for Contact Centers
- MOM 2005 Feels the Love
- MCDST Ugrade Exam Goes Live
- Analysts: Upgrading to Vista SP1 on Intel Chips? Proceed with Caution
- Researchers Seek Cash for Software Flaws
- Lotus 6
- Windows PowerShell
- StorageX
- Evolutionary in Technology, Revolutionary in Impact
- Exit Interview
- To Protect and Secure the Web
3Com AccessData Acme Packet Adobe Alcatel Lucent American College APC Apple Avaya BEA BICSI BlackBerry Business Objects CheckPoint Cisco Citrix CIW CompTIA Computer Associates CWNP Dell ECcouncil EMC Enterasys Ericsson Exam Express EXIN Extreme Networks File Maker Fortinet Foundry Fujitsu Guidance Software HDI HITACHI Hewlett Packard Huawei Hyperion IBM ICDL IISFA Intel ISACA ISC ISEB Isilon ISM Juniper Legato Lotus LPI McAfee McDATA Microsoft Mile2 Network Appliance Network General Nokia Nortel Novell OMG Oracle PMI Polycom PostgreSQL CE Red Hat RES Software SAIR SAP SAS Institute SCP SeeBeyond SNIA Sniffer Sun Sybase Symantec Teradata The Open Group TIA TIBCO Trusecure Veritas VMware

EnCEGD0-100 GD0-110 $139 Details |
CCI1D0-441 1D0-442 $139 Details |
Sybase Associate510-015 510-050 510-306 510-410 $279 Details |
HCP4H0-002 4H0-020 4H0-028 4H0-110 4H0-200 4H0-435 4H0-533 4H0-712 $549 Details |
CCIP646-611 642-642 642-661 642-691 $279 Details |
Wireless LAN642-586 642-587 646-588 646-590 650-621 $349 Details |
CNSAMK0-201 ML0-220 $139 Details |
TCPTB0-104 TB0-105 TB0-106 TB0-107 $279 Details |
11i AD CRM 8.1 Certified Administrator SCSE 6 CNE TICSA Network+ CA ITIL CEP CDIA+ MCSD .NET CCIA APC TCA V2R5 SCSSSE CATE JNCIS RFID+ Hitachi Certified Professional SAIR Level 2 SCSP CED CCMSE APP eServer CS 9i DBA VCP IBM ED MCDST ASP CRMAM IBM ODB CASA Access Routing & LAN Switching Certified Solution Designer F8CD 8.1 Certified Developer CCIE Voice CNE CTP MCITP EST MCTS ADO.NET Applications NCA MCP CCSA NGX MCDBA SSBB SCTS
642-145 190-701 A00-203 000-060 9A0-031 E20-040 9L0-206 HP0-436 000-438 310-043 MB3-451 190-802 000-134 70-123 000-934 920-252 MD0-235 MB4-535 MB3-214 EW0-200 HP0-A02 1K0-001 MB3-461 70-500 E20-817 E20-060 1D0-442 HP0-K02 642-871 HP0-601 156-705 70-296 1Z0-033 000-741 000-922 350-022 MB7-255 000-190 000-316 000-R06 70-622 920-216 E20-331 HP0-262 70-089 646-362 JN0-531 9L0-508 646-521 000-443 70-552 EX0-105 000-191 E20-870 MB2-185 CCNT 920-167 CT0-101 642-731 1T6-323

