Вы находитесь на странице: 1из 8

Security assessment: Severe Risk

Computer name: WORKGROUP\ISS-FC09F97E756


IP address: 10.64.110.184
Security report name: WORKGROUP - ISS-FC09F97E756 (2-7-2011 1-02 PM)
Scan date: 2/7/2011 1:02 PM
Scanned with MBSA version: 2.2.2170.0
Catalog synchronization date:
Security update catalog: Microsoft Update

Security Updates Scan Results

Issue: SQL Server Security Updates


Score: Check passed
Result: No security updates are missing.

Current Update Compliance

| MS06-061 | Installed | MSXML 6.0 RTM Security Update (925673) | Critical |

Issue: Windows Security Updates


Score: Check passed
Result: No security updates are missing.

Current Update Compliance

| MS09-071 | Installed | Security Update for Windows Server 2003 (KB974318) |


Important |
| MS10-097 | Installed | Security Update for Windows Server 2003 (KB2443105)
| Important |
| MS10-007 | Installed | Security Update for Windows Server 2003 (KB975713) |
Critical |
| MS08-046 | Installed | Security Update for Windows Server 2003 (KB952954) |
Critical |
| MS10-029 | Installed | Security Update for Windows Server 2003 (KB978338) |
Moderate |
| 2443685 | Installed | Update for Windows Server 2003 (KB2443685) | |
| MS10-083 | Installed | Security Update for Windows Server 2003 (KB979687) |
Important |
| MS09-010 | Installed | Security Update for Windows Server 2003 (KB923561) |
Important |
| MS10-096 | Installed | Security Update for Windows Server 2003 (KB2423089)
| Important |
| MS10-070 | Installed | Security Update for Microsoft .NET Framework 1.1
SP1, Windows Server 2003, and Windows Server 2003 R2 x86 (KB2416451) | Important |
| MS10-041 | Installed | Microsoft .NET Framework 3.5 SP1 and .NET
Framework 2.0 SP2 Security Update for Windows 2000, Windows Server 2003, and Windows XP x86
(KB979909) | Important |
| MS09-051 | Installed | Security Update for Windows Media Format Runtime
9.5 for Windows Server 2003 (KB954155) | Critical |
| MS08-007 | Installed | Security Update for Windows Server 2003 (KB946026) |
Important |
| MS10-090 | Installed | Cumulative Security Update for Internet Explorer 7 for
Windows Server 2003 (KB2416400) | Critical |
| MS10-082 | Installed | Security Update for Windows Server 2003 (KB2378111)
| Important |
| MS08-071 | Installed | Security Update for Windows Server 2003 (KB956802) |
Critical |
| MS09-037 | Installed | Security Update for Windows Server 2003 (KB973815) |
Critical |
| MS07-067 | Installed | Security Update for Windows Server 2003 (KB944653) |
Important |
| MS09-012 | Installed | Security Update for Windows Server 2003 (KB956572) |
Important |
| MS09-061 | Installed | Microsoft .NET Framework 1.1 Service Pack 1 Security
Update for Windows Server 2003 x86 and Windows Server 2003 R2 x86 (KB953298) | Important |
| MS08-008 | Installed | Security Update for Windows Server 2003 (KB943055) |
Moderate |
| MS07-020 | Installed | Security Update for Windows Server 2003 (KB932168) |
Moderate |
| MS09-041 | Installed | Security Update for Windows Server 2003 (KB971657) |
Important |
| MS09-056 | Installed | Security Update for Windows Server 2003 (KB974571) |
Important |
| MS10-013 | Installed | Security Update for Windows Server 2003 (KB975560) |
Critical |
| MS10-021 | Installed | Security Update for Windows Server 2003 (KB979683) |
Important |
| MS09-046 | Installed | Security Update for Windows Server 2003 (KB956844) |
Moderate |
| MS10-019 | Installed | Security Update for Windows Server 2003 (KB979309) |
Critical |
| MS10-033 | Installed | Security Update for Windows Media Format Runtime
9.5 for Windows Server 2003 (KB978695) | Critical |
| MS10-042 | Installed | Security Update for Windows Server 2003 (KB2229593)
| Low |
| MS09-061 | Installed | Microsoft .NET Framework 2.0 Service Pack 1 Security
Update for Windows 2000, Windows Server 2003, and Windows XP (KB953300) | Critical |
| MS09-057 | Installed | Security Update for Windows Server 2003 (KB969059) |
Important |
| 914961 | Installed | Windows Server 2003 Service Pack 2 (32-bit x86) | |
| MS07-039 | Installed | Security Update for Windows Server 2003 (KB926122) |
Important |
| MS09-052 | Installed | Security Update for Windows Server 2003 (KB974112) |
Critical |
| MS09-037 | Installed | Security Update for Windows Server 2003 (KB973507) |
Critical |
| MS10-070 | Installed | Security Update for Microsoft .NET Framework 2.0 SP2
and 3.5 SP1 on Windows Server 2003 and Windows XP x86 (KB2418241) | Important |
| MS07-017 | Installed | Security Update for Windows Server 2003 (KB925902) |
Critical |
| MS09-062 | Installed | Security Update for Windows Server 2003 (KB958869) |
Critical |
| MS10-098 | Installed | Security Update for Windows Server 2003 (KB2436673)
| Important |
| MS09-045 | Installed | Security Update for Jscript 5.7 for Windows Server 2003
(KB971961) | Critical |
| MS09-048 | Installed | Security Update for Windows Server 2003 (KB967723) |
Important |
| MS09-037 | Installed | Security Update for Windows Server 2003 (KB973869) |
Critical |
| MS09-073 | Installed | Security Update for Windows Server 2003 (KB973904) |
Important |
| MS10-081 | Installed | Security Update for Windows Server 2003 (KB2296011)
| Important |
| 940767 | Installed | Windows Internet Explorer 7 for Windows Server 2003 | |
| MS10-060 | Installed | Security Update for .NET Framework 2.0 SP2 and 3.5
SP1 on Windows Server 2003 and Windows XP x86 (KB983583) | Critical |
| MS08-037 | Installed | Security Update for Windows Server 2003 (KB951748) |
Important |
| MS10-052 | Installed | Security Update for Windows Server 2003 (KB2115168)
| Critical |
| MS10-001 | Installed | Security Update for Windows Server 2003 (KB972270) |
Low |
| MS10-022 | Installed | Security Update for Windows Server 2003 (KB981349) |
Important |
| MS10-049 | Installed | Security Update for Windows Server 2003 (KB980436) |
Critical |
| MS10-070 | Installed | Security Update for Microsoft .NET Framework 3.5 SP1
on Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008 x86 (KB2416473) |
Important |
| MS09-023 | Installed | Security Update for Windows Server 2003 (KB963093) |
Moderate |
| MS08-069 | Installed | Security Update for Microsoft XML Core Services 6.0
Service Pack 2 (KB954459) | Important |
| MS08-036 | Installed | Security Update for Windows Server 2003 (KB950762) |
Important |
| MS10-013 | Installed | Security Update for Windows Server 2003 (KB977914) |
Critical |
| MS08-067 | Installed | Security Update for Windows Server 2003 (KB958644) |
Critical |
| MS08-020 | Installed | Security Update for Windows Server 2003 (KB945553) |
Important |
| MS10-033 | Installed | Security Update for Windows Server 2003 (KB975562) |
Critical |
| MS09-012 | Installed | Security Update for Windows Server 2003 (KB952004) |
Important |
| MS09-013 | Installed | Security Update for Windows Server 2003 (KB960803) |
Critical |
| 951847 | Installed | Microsoft .NET Framework 3.5 Service Pack 1 and .NET
Framework 3.5 Family Update (KB951847) x86 | |
| MS06-078 | Installed | Security Update for Windows Media Player 6.4
(KB925398) | Critical |
| MS09-022 | Installed | Security Update for Windows Server 2003 (KB961501) |
Moderate |
| 951847 | Installed | Microsoft .NET Framework 3.5 Service Pack 1 and .NET
Framework 3.5 Family Update for .NET versions 2.0 through 3.5 (KB951847) x86 | |
| MS10-033 | Installed | Security Update for Windows Server 2003 (KB979482) |
Critical |
| MS08-076 | Installed | Security Update for Windows Server 2003 (KB952069) |
Important |
| MS10-011 | Installed | Security Update for Windows Server 2003 (KB978037) |
Important |
| MS09-042 | Installed | Security Update for Windows Server 2003 (KB960859) |
Important |
| MS09-059 | Installed | Security Update for Windows Server 2003 (KB975467) |
Important |
| MS07-040 | Installed | Security Update for Microsoft .NET Framework,
Version 1.1 Service Pack 1 (KB933854) | Critical |
| MS09-069 | Installed | Security Update for Windows Server 2003 (KB974392) |
Important |
| MS10-063 | Installed | Security Update for Windows Server 2003 (KB981322) |
Critical |
| MS09-040 | Installed | Security Update for Windows Server 2003 (KB971032) |
Important |
| MS10-005 | Installed | Security Update for Windows Server 2003 (KB978706) |
Moderate |
| MS09-044 | Installed | Security Update for Windows Server 2003 (KB958469) |
Critical |
| MS10-019 | Installed | Security Update for Windows Server 2003 (KB978601) |
Critical |
| MS10-069 | Installed | Security Update for Windows Server 2003 (KB2121546)
| Important |
| MS10-091 | Installed | Security Update for Windows Server 2003 (KB2296199)
| Important |
| MS10-020 | Installed | Security Update for Windows Server 2003 (KB980232) |
Critical |
| MS10-026 | Installed | Security Update for Windows Server 2003 (KB977816) |
Critical |
| MS07-068 | Installed | Security Update for Windows Server 2003 (KB941569) |
Critical |
| MS08-066 | Installed | Security Update for Windows Server 2003 (KB956803) |
Important |
| MS10-034 | Installed | Cumulative Security Update for ActiveX Killbits for
Windows Server 2003 (KB980195) | Critical |
| MS10-054 | Installed | Security Update for Windows Server 2003 (KB982214) |
Important |
| MS09-015 | Installed | Security Update for Windows Server 2003 (KB959426) |
Moderate |
| MS10-074 | Installed | Security Update for Windows Server 2003 (KB2387149)
| Moderate |
| MS10-062 | Installed | Security Update for Windows Server 2003 (KB975558) |
Critical |
| MS10-061 | Installed | Security Update for Windows Server 2003 (KB2347290)
| Important |
| MS07-050 | Installed | Security Update for Internet Explorer 7 for Windows
Server 2003 (KB938127) | Critical |
| MS10-041 | Installed | Microsoft .NET Framework 1.1 SP1 Security Update for
Windows Server 2003 x86 and Windows Server 2003 R2 x86 (KB979907) | Important |
| MS10-051 | Installed | Security Update for Windows Server 2003 (KB2079403)
| Moderate |
| MS09-051 | Installed | Security Update for Windows Server 2003 (KB975025) |
Critical |
| MS10-067 | Installed | Security Update for Windows Server 2003 (KB2259922)
| Important |
| MS10-046 | Installed | Security Update for Windows Server 2003 (KB2286198)
| Critical |
| MS09-037 | Installed | Security Update for Windows Server 2003 (KB973540) |
Critical |
| MS11-002 | Installed | Security Update for Windows Server 2003 (KB2419635)
| Important |
| MS08-049 | Installed | Security Update for Windows Server 2003 (KB950974) |
Important |
| MS10-084 | Installed | Security Update for Windows Server 2003 (KB2360937)
| Important |
| MS10-076 | Installed | Security Update for Windows Server 2003 (KB982132) |
Critical |
| MS07-034 | Installed | Cumulative Security Update for Outlook Express for
Windows Server 2003 (KB929123) | Low |
| 890830 | Installed | Windows Malicious Software Removal Tool - January 2011
(KB890830) | |
| MS10-099 | Installed | Security Update for Windows Server 2003 (KB2440591)
| Important |
| MS10-030 | Installed | Security Update for Windows Server 2003 (KB978542) |
Critical |

Operating System Scan Results

Administrative Vulnerabilities
Issue: Local Account Password Test
Score: Check passed
Result: Some user accounts (1 of 3) have blank or simple passwords, or could not be
analyzed.
Detail:
| User | Weak Password | Locked Out | Disabled |
| Guest | Weak | - | Disabled |
| SUPPORT_388945a0 | - | - | Disabled |
| Administrator | - | - | - |

Issue: File System


Score: Check passed
Result: All hard drives (1) are using the NTFS file system.
Detail:
| Drive Letter | File System |
| C: | NTFS |

Issue: Password Expiration


Score: Check failed (non-critical)
Result: Some user accounts (2 of 3) have non-expiring passwords.
Detail:
| User |
| Administrator |
| Guest |
| SUPPORT_388945a0 |

Issue: Guest Account


Score: Check passed
Result: The Guest account is disabled on this computer.

Issue: Autologon
Score: Check passed
Result: Autologon is not configured on this computer.

Issue: Restrict Anonymous


Score: Check passed
Result: Computer is properly restricting anonymous access.

Issue: Administrators
Score: Check passed
Result: No more than 2 Administrators were found on this computer.
Detail:
| User |
| Administrator |

Issue: Windows Firewall


Score: Best practice
Result: Windows Firewall is not installed or configured properly, or is not available on this
version of Windows.

Issue: Automatic Updates


Score: Check passed
Result: Updates are automatically downloaded and installed on this computer.

Issue: Incomplete Updates


Score: Best practice
Result: No incomplete software update installations were found.

Additional System Information

Issue: Windows Version


Score: Best practice
Result: Computer is running Microsoft Windows Server 2003.

Issue: Auditing
Score: Best practice
Result: Logon Success auditing is enabled, however Logon Failure auditing should also be
enabled.

Issue: Shares
Score: Best practice
Result: 2 share(s) are present on your computer.
Detail:
| Share | Directory | Share ACL | Directory ACL |
| ADMIN$ | C:\WINDOWS | Admin Share | BUILTIN\Users - RX,
BUILTIN\Power Users - RWXD, BUILTIN\Administrators - F, NT AUTHORITY\SYSTEM - F |
| C$ | C:\ | Admin Share | BUILTIN\Administrators - F, NT
AUTHORITY\SYSTEM - F, BUILTIN\Users - RX, Everyone - RX |

Issue: Services
Score: Best practice
Result: Some potentially unnecessary services are installed.
Detail:
| Service | State |
| Telnet | Stopped |

Internet Information Services (IIS) Scan Results


IIS is not running on this computer.

SQL Server Scan Results


SQL Server and/or MSDE is not installed on this computer.

Desktop Application Scan Results


Administrative Vulnerabilities

Issue: IE Zones
Score: Check failed (critical)
Result: Internet Explorer zones do not have secure settings for some users.
Detail:
| User | Zone | Level | Recommended Level |
| ISS-FC09F97E756\Administrator | Trusted sites | Medium-Low | Medium |
| ISS-FC09F97E756\Administrator | Internet | Custom | High |
Sub-Detail:
| Setting | Current | Recommended |
| Run components not signed with Authenticode | Enable | Disable |
| Run components signed with Authenticode | Enable | Disable |
| File download | Enable | Disable |

Issue: IE Enhanced Security Configuration for Administrators


Score: Check passed
Result: The use of Internet Explorer is restricted for administrators on this server.

Issue: IE Enhanced Security Configuration for Non-Administrators


Score: Check passed
Result: The use of Internet Explorer is restricted for non-administrators on this server.

Issue: Macro Security


Score: Check not performed
Result: No supported Microsoft Office products are installed.

Вам также может понравиться