Registered users    
MembershipMembership:
Latest New UserLatest:John Smith
New TodayNew Today:8
New YesterdayNew Yesterday:11
User CountOverall:22877

Private messaging    
You must be logged in to use this module.
Top 10 posters    
NamePosts
Mariette Knap12481
Marina Roos11720
Eriq Neale2071
Michael Patrick1901
Stan Guinn1806
Robert Pearman1717
Nick Pieters1425
Stewart Brown609
Kevin D.563
Eddie Kerr534
Welcome unauthorized visitor    
If you want to join us in the discussions on this forum you need to register first. Registration is free! If you are already a registered user please login to join the forum.
Small Business Server Support Forum    
Subject: MBSA report
Prev Next
You are not authorized to post a reply.

Author Messages
Simon Weel User is Offline
The Netherlands
Member since
1/16/2006

Registered Users
Posts: 39

7/07/2008 03:27 PM  
Hi,
 
I suspect we have/had an unwanted visitor on our server. So I'm running all kind of security-checks to find malware. So far, the program's I ran haven't found anything, except MBSA (MIcrosoft Baseline Security Analyser) - it reports several things to examine.
 
I wonder if MBSA takes the differences between 'normal' Windows Server 2003 and SBS 2003 into account? Therefore, I would to know your opinion about the MBSA log, my comment in bold:
 
 Scanned with MBSA version: 2.1.2104.0
    Administrative Vulnerabilities
    Issue:  Administrators
    Score:  Check failed (non-critical)
    Result: More than 2 Administrators were found on this computer.
    Detail:
   | User |
   | \Administrator |
   | \Ondernemingsadministrators |

Is Ondernemingsadministrators a valid account?
 
    Issue:  Windows Firewall
    Score:  Best practice
    Result: Windows Firewall is not installed or configured properly, or is not available on this version of Windows.
Is the firewall by default disabled in SBS 2003?
    Issue:  Shares
    Score:  Best practice
    Result: nn share(s) are present on your computer.
    Detail:
   | Share | Directory
   | ADMIN$ | C:\WINDOWS
   | Address | C:\Program Files\Exchsrvr\address
   | C$ | C:\
   | ClientApps | D:\ClientApps
   | D$ | D:\
   | .LOG | C:\Program Files\Exchsrvr\.log
   | NETLOGON | C:\WINDOWS\SYSVOL\sysvol\.lan\SCRIPTS
   | REMINST | d:\RemoteInstall
   | Resources$ | C:\Program Files\Exchsrvr\res
   | SYSVOL | C:\WINDOWS\SYSVOL\sysvol
   | UpdateServicesPackages | S:\WSUS-updates\UpdateServicesPackages
   | Users | D:\Users Shared Folders
   | WSUSTemp | C:\Program Files\Update Services\LogFiles\WSUSTemp
   | WsusContent | S:\WSUS-updates\WsusContent
   | clients | C:\Programs\SBS\ClientSetup\Clients
   | gebruikers | D:\sys\gebruikers
   | print$ | C:\WINDOWS\system32\spool\drivers
   | prnproc$ | C:\WINDOWS\system32\spool\PRTPROCS
   | profielen | D:\sys\profielen
   | tsclient | C:\WINDOWS\system32\clients\tsclient
  | tsweb | C:\WINDOWS\web\tsweb
I removed shares I made myself; are the above valid?

  SQL Server Scan Results
   Instance (default)
    Administrative Vulnerabilities
 
    Issue:  SQL Server/MSDE Account Password Test
    Score:  Check not performed
    Result: The check was skipped because SQL Server and/or MSDE is operating in Windows Only authentication mode.

    Issue:  Service Accounts
    Score:  Best practice
    Result: SQL Server, SQL Server Agent, MSDE and/or MSDE Agent service accounts should not be members of the local Administrators group or run as LocalSystem.
    Detail:
   | Instance | Service | Account | Issue |
   | (default) | MSSQLServer | SYSTEM | LocalSystem account. |
   | (default) | SQLServerAgent | SYSTEM | LocalSystem account. |
If I'm right, SQL Server / MSDE service accounts are set to LocalSystem by default?

   Instance BKUPEXEC
    Administrative Vulnerabilities
 
    Issue:  SQL Server/MSDE Account Password Test
    Score:  Check not performed
    Result: The check was skipped because SQL Server and/or MSDE is operating in Windows Only authentication mode.

    Issue:  Service Accounts
    Score:  Best practice
    Result: SQL Server, SQL Server Agent, MSDE and/or MSDE Agent service accounts should not be members of the local Administrators group or run as LocalSystem.
    Detail:
   | Instance | Service | Account | Issue |
   | BKUPEXEC | MSSQL$BKUPEXEC | SYSTEM | LocalSystem account. |
   | BKUPEXEC | SQLAgent$BKUPEXEC | SYSTEM | LocalSystem account. |
As above

   Instance MICROSOFT##SSEE
    Administrative Vulnerabilities
 
    Issue:  Folder Permissions
    Score:  Check failed (critical)
    Result: Permissions on the SQL Server and/or MSDE installation folders are not set properly.
    Detail:
   | Instance | Folder | User |
   | MICROSOFT##SSEE | C:\WINDOWS\SYSMSI\SSEE\MSSQL.2005\MSSQL\Binn | INGEBOUWD\Prestatielogboekgebruikers |
   | MICROSOFT##SSEE | C:\WINDOWS\SYSMSI\SSEE\MSSQL.2005\MSSQL\Binn | INGEBOUWD\Prestatiemetergebruikers |
   | MICROSOFT##SSEE | C:\WINDOWS\SYSMSI\SSEE\MSSQL.2005\MSSQL\Binn | \SQLServer2005MSSQLUser$$MICROSOFT##SSEE |
   | MICROSOFT##SSEE | C:\WINDOWS\SYSMSI\SSEE\MSSQL.2005\MSSQL\Binn | \MAKER EIGENAAR |
   | MICROSOFT##SSEE | C:\WINDOWS\SYSMSI\SSEE\MSSQL.2005\MSSQL\Data | \SQLServer2005MSSQLUser$$MICROSOFT##SSEE |
   | MICROSOFT##SSEE | C:\WINDOWS\SYSMSI\SSEE\MSSQL.2005\MSSQL\Data | \SQLServer2005MSSQLUser$$MICROSOFT##SSEE |
   | MICROSOFT##SSEE | C:\WINDOWS\SYSMSI\SSEE\MSSQL.2005\MSSQL\Data | \MAKER EIGENAAR |
Do I need to correct this?

    Issue:  Sysadmins
    Score:  Check failed (non-critical)
    Result: More than 2 members of sysadmin role are present.

    Issue:  Service Accounts
    Score:  Unable to scan
    Result: SQL Server, SQL Server Agent, MSDE and/or MSDE Agent service accounts should not be members of the local Administrators group or run as LocalSystem.
    Detail:
   | Instance | Service | Account | Issue |
   | MICROSOFT##SSEE | MSSQL$MICROSOFT##SSEE | NT AUTHORITY\NetworkService | This is a Domain Account. Baseline Security Analyzer cannot determine whether it belongs to the Domain Admins group due to the following error:  1212 De notatie van de opgegeven domeinnaam is ongeldig.
. |
As above
    Issue:  Password Policy
    Score:  Check failed (critical)
    Result: Enable password expiration for the SQL server accounts.
If I do this, I have to change them regularly, or things won't work?

    Issue:  Sysdtslog
    Score:  Best practice
    Result: Do not create sysdtslogs90 in the Master or MSDB database.It is recommended to create a seperate logging database.
??
 
   Instance SBSMONITORING
    Administrative Vulnerabilities
 
    Issue:  SQL Server/MSDE Account Password Test
    Score:  Check not performed
    Result: The check was skipped because SQL Server and/or MSDE is operating in Windows Only authentication mode.

    Issue:  Service Accounts
    Score:  Best practice
    Result: SQL Server, SQL Server Agent, MSDE and/or MSDE Agent service accounts should not be members of the local Administrators group or run as LocalSystem.
    Detail:
   | Instance | Service | Account | Issue |
   | SBSMONITORING | MSSQL$SBSMONITORING | SYSTEM | LocalSystem account. |
   | SBSMONITORING | SQLAgent$SBSMONITORING | SYSTEM | LocalSystem account. |
As above
 
   Instance SHAREPOINT
    Administrative Vulnerabilities
 
    Issue:  SQL Server/MSDE Account Password Test
    Score:  Check not performed
    Result: The check was skipped because SQL Server and/or MSDE is operating in Windows Only authentication mode.
    Issue:  Service Accounts
    Score:  Best practice
    Result: SQL Server, SQL Server Agent, MSDE and/or MSDE Agent service accounts should not be members of the local Administrators group or run as LocalSystem.
    Detail:
   | Instance | Service | Account | Issue |
   | SHAREPOINT | MSSQL$SHAREPOINT | SYSTEM | LocalSystem account. |
   | SHAREPOINT | SQLAgent$SHAREPOINT | SYSTEM | LocalSystem account. |
As above
 
  Desktop Application Scan Results
 
 Administrative Vulnerabilities
 
    Issue:  IE Zones
    Score:  Check failed (critical)
    Result: Internet Explorer zones do not have secure settings for some users.
    Detail:
   | User | Zone | Level | Recommended Level |
   | \SBS Backup User | Internet | High | High |
   Sub-Detail:
    | Setting | Current | Recommended |
    | Run components not signed with Authenticode | Enable | Disable |
    | Run components signed with Authenticode | Enable | Disable |
   | \Telefonie | Internet | High | High |
   Sub-Detail:
    | Setting | Current | Recommended |
    | Run components not signed with Authenticode | Enable | Disable |
    | Run components signed with Authenticode | Enable | Disable |
   | \administrator | Internet | Medium | High |
I have to log in as the user to change this?
 
**** End **** 
Kevin Da Silva User is Offline
Mississauga, Canada
Member since
1/12/2008

Registered Users
Posts: 563

7/14/2008 10:17 PM  
Why not try to run the SBS BPA it should give you more SBS specific results...

MCSE:Messaging, MCTIP, SBS Specialist
You are not authorized to post a reply.



ActiveForums 3.7
Forum policy    
These Discussion Forums are dedicated to the discussion of the Small Business Server and related server and client software. For the benefit of the community please observe the following posting guidelines:
  1. No Advertising. This includes promotion of commercial products and non-commercial products which are not directly related to Small Business Server and related server and client software.
  2. No Flaming or Trolling.
  3. No Profanity, Racism, or Prejudice.
  4. Site Moderators have the final word on approving/removing a thread or post or comment.