Intrusion Detection Systems mailing list archives

RE: IDS for Win2k


From: FMartins () pt imshealth com (Martins, Fernando (Lisbon))
Date: Tue, 28 Mar 2000 12:29:24 +0100


Archive: http://msgs.securepoint.com/ids
FAQ: http://www.ticm.com/kb/faq/idsfaq.html
IDS: http://www-rnks.informatik.tu-cottbus.de/~sobirey/ids.html
UNSUBSCRIBE: email "unsubscribe ids" to majordomo () uow edu au
Hi2all

'On Earth' i would want to run a IDS on win2k for the same reasons i do it
for other OS's ... not too hard to understand...
I'll not use the win2k box in question to be a DNS server, so for what i
need it handle DNS enough.
And no, i didn't heard enough horror stories already, and i allways look for
new ones, else i get bored. Plus, i was even receiving trainning at Dracula
Castle (aka MC trainning), so when horror comes, i run to it, not run from
it. 

Now ... what about practical solutions? dear vendor list colleges? =]

Kind Regards
Fernando Martins
fmartins () pt imshealth com
http://www.imshealth.com

-----Original Message-----
From: Greg Shipley [SMTP:gshipley () neohapsis com]
Sent: Monday, March 27, 2000 23:21
To:   Martins, Fernando (Lisbon)
Cc:   ids () uow edu au
Subject:      Re: IDS: IDS for Win2k



On Mon, 27 Mar 2000, Martins, Fernando (Lisbon) wrote:

I wonder if there is allready available IDS's for Windows 2000 Servers? 
Any known NT version of a IDS tested on win2k?
It doesn't matter if it is freeware, shareware or comercial ... anything
that can work in win2k is wellcome =)
(info on other win2k security apps will be appreciated too)


Ok, I've got to ask - why on earth would you want to run an IDS on win2k?

Have you not heard enough horror stories already?  Hell, win2k can't even
handle DNS properly!!!!  Or at least, from a network perspective. 

If you are forced to deploy win2k I guess maybe having a host-based
product might be helpful.

Quivering at the thought,

-Greg




Current thread: