Security Vulnerability Assessment
How to Identify Vulnerabilities and Services Server when Conducting Security Assessment
One method that hackers could go back to the computer / server is to exploit the vulnerability of the operating system or through active service on the server. Do not be surprised there may be other active Windows service running on a PC or server that you do not need. You do not conquer hacking but with this service and operating system patches up to date, it is difficult for hackers to penetrate into your system.
I’ve done Security Assessment for a number of companies have been watching the server and services such as FTP, IIS, SMTP, SQL servers running on them that the administrators are not aware.
Rule of thumb is to make sure the server or PC patched up to date and unnecessary services disabled. If there is a budget for reserves, invest in a reputation IPS (Intrusion Prevention Systems) to complete the firewall.
Intruder with some basic skills that can strike into the server (even remote control the server) to exploit the vulnerability if they are not properly patched. Once the intruder has command line access to the server, he can then rise to superuser status (there are several ways to do that). This is where the real damage can be done. (more…)















































