Which security risks can be exploited bij opening a routed port on a windows network

Which security risks can be exploited by opening a routed port on a windows network
Our company is implementing a web application with potential security issues we have never dealt with before. The situation is 
as follows:
Network
•A LAN with internet router and firewall with a port (f.e. 4589) open, which is routed to IIS server address.
•Network with IIS server, Windows clients and server(s)
•MSSQL application Database on a windows client or server
•IIS Server hosts a .NET 4.0 WCF Web service
Purpose of this config:
•Internet users can use IIS web service to read and write application database tables.
•IIS server has a certificate for authenticity, web services are configured to only use https.
•Application exposes 2 web services:
•1. without user authentication: can only read non-essential information from database
•2. with user auth., for reading and writing more essential information.
I have the following questions concerning security:
1.Can I Isolate external access to the IIS server only, and shield access to the rest of the physical (windows) machine ?
2.We have a lot of customers with only 1 windows 7 or 8 PC. What extra security risks arise in case of a combined MSSql Express
database, Windows integrated IIS 7 or 8, and a customer doing its daily business on the windows client on this PC. (Daily  business involves: use of our application (with database), Email, Office, Internet)
3.Can you see any other security vulnerabilities in this scenario, assumed that all machines in the LAN are properly patched ,
shielded with antivirus product and maintained?
Since security is not really my field of expertise, I would be very happy to get some explanation on potential risks of this 
configuration.
Thanx in advance, Oskar Stok
Thanks in advance. Sincerely, Robert Bakker Flexdata

Hi,
1.Can I Isolate external access to the IIS server only, and shield access to the rest of the physical (windows) machine ?
You can configure Windows Firewall rules based on ports.
2.We have a lot of customers with only 1 windows 7 or 8 PC. What extra security risks arise in case of a combined MSSql Express
3.Can you see any other security vulnerabilities in this scenario, assumed that all machines in the LAN are properly patched ,
Honestly, I don’t see vulnerabilities here, if you want to secure the server and clients, place them in a private network, you can also use NAT and hardware firewall.
In addition, you can install System Center Endpoint Protection to prevent virus and spyware.
More information for you:
Configuring Firewall Rules
http://technet.microsoft.com/en-us/library/dd448559(v=WS.10).aspx
Frequently asked questions about malicious software
http://technet.microsoft.com/en-us/library/ff823783.aspx
Best Regards,
Amy
Please remember to mark the replies as answers if they help and un-mark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact [email protected]

Similar Messages

  • Can an advanced action open an image in a seperate window?

    I am wondering if this is possible.
    I am using an advanced action to Show/Hide an image. I would like the image to open in its own window so the user can move it to compare the pop-up image with the other image and instructions on my slide. (I have a TOC so I have limited space on the slide.)   I think the advanced action might be Execute JavaScript because that choice gives me the option to open in new window.  I am not savvy with writing JavaScript so any help would be great. 
    Thanks
    Jeff

    Hi Jeff,
    Welcome to Adobe Forums.
    In order to open an image in its own window you can go to Properties > Action > On Success > Open URL or File, in the URL box type the name of the image and from the drop down select New.
    After publishing the project, copy and paste the image in the output folder and then you can view the output, this will open the image on a new window.
    I hope it helps.
    Thanks
    Vikas

  • Can we use a using a routed port as a gateway instead of SVI on a l3 switch ?

    Hi guys,
    If I have only a L3 switch and a router.
    The common setup would be to have the devices connected to the L3 switch.
    Setup a SVI for the VLAN and have the devices's gateway pointing to the SVI.
    Then create a routed ported that is physically connected to the router as below
    q1) Is there anyway that I can create/use a new routed port as the gateway instead of SVI without adding additional hardware ?
    Reason for asking this because I believe in order to use a routed port I would have to add in a L2 switch between the devices and the L3 switch. Have the devices hook up to the L2 switch and connect the L2 switch to the routed port on the L3 switch. Then set the gateway for the devices as the routed port's IP.
    q2) In that case, does the routed port need to belong to the same VLAN (100) - as I see in the cisco website that routed port does not belongs to any VLAN.
    Please advise.
    Regards,
    Noob

    Hi Reza,
    Thanks for coming back.
    What i meant for Q2 is
    q2) Assuming i am going to use my L3 switch as a gateway as well as for InterVLAN routing - does it mean that the only usage of the routed port is for connecting to the router.
    What else can routed port on L3 switch be use for ; beside connecting to a router ?
    Can I connect a L3 routed port to a L2 switch and have all the devices connecting to the same L2 switch have their gateway as the L3 routed port IP ?
    That I will added in a L2 switch, the L3 switch's routed port will act as the gateway.
    Device --> L2 switch --> (routed ported) on L3 switch --> (another routed port) on L3 switch ---> Router.
    Can it works that way ?
    Regards,
    Noob

  • Which security aspects can be covered with using GG?

    Hi,
    Please explain what are the security aspects which are addressed by GG while doing real-time replication?
    Thanks & Regards,
    Noman.

    Security in what sense? Do you want to encrypt trails? Then use encryption. Do you want to minimize privileges of your GG user? Then follow the chart shown in the installation guide. Do you want to encrypt passwords in parameter files? Use encryption. Do you want to use your own encryption? Then specify that in the scheme/setup.

  • I can not connect to wifi with router WRT54G2 v1 with Windows 7

    Hi everyone: I have a Linksys WRT54G2 V1 and since I bought my new notebook with Windows 7 I can not access the wifi.
     I have another notebooks with Windows Vista and a PC with Windows XP that connect perfectly, but with Windows 7 gives me error when loading the password.
    I Update the firmware to version 1.0.04 (this the latest version I found on the cisco site), but still don't work.
    I Try chatting with Cisco support and was told he was no longer under warranty ....
    Can you tell me how to solve this problem ???
    Thank you for your help !!!
    Solved!
    Go to Solution.

    Sure, disable security on the router completely for now.  Now try to connect with no security.  Once done and verified  go back and add  security back on of WPA2-AES with a new password and try again.

  • Why can't i open a playlist in a new window with itunes 11?

    so i can apparently no longer open a playlist in a new window... how am i supposed to drag & drop songs in the order i want them to play?

    I get your point and I was really just trying to break your sense of despair. It is easy to become overwhelmed when something big and new comes along. We all have our own ways of doing things which we become used to and ...... well you know what I mean.
    Now, lets see if I can help you learn how to use this wonderful iTunes to get a grip on your music at a basic level.
    Start by going to the SONGS pane. This is the workplace, the most powerful place to be for finding stuff, organising and maintaining your music. The other panes are the pretty places to go when you want to play and enjoy your collection after the work is done.
    Make sure that you have the basic columns showing (View Menu, View Options). I suggest that essentially you should tick the following boxes :- Album, Artist, Checked, Genre, Time, Track Number, Year, Plays.
    In the column for Album, if you repeatedly click in the heading, the heading will cycle thru Album/Album-by-Artist/Album-by-Artist-by-Year. Play with that a little and see what it does. Also note that every column can be sorted by clicking in the column heading. The column that you are currently sorted by is shown by a little up or down arrow.
    Then turn on the Column Browser (View Menu) and check Genres, Artists Albums.
    Now you have the tools to find and organise. You have the view-by-genre you wanted. You can select all genres or you can select one or many. Same for Artist. Same for Album. Your selections are reflected in the lower songs pane. The horizontal division between the Column Browser and the Songs can be raised/lowered by grabbing the top of the heading line.
    Turn on the Status Bar (VIew Menu, Show Status Bar). The number of songs, the playtime and the disc space that your selection uses is shown here.
    NOW you should be able to do just about anything. Enjoy

  • How many sockets can be opened to one port

    Hi All,
    There is a service installed on port 4444 of our server. In order to do some work with that service we open sockets to it with socket:localhost:4444. The thing we are finding is that it is quiet expensive to initialise these socket connections per request to our website and I'd like to pool connections. I have implemented a pool but currently this closing the connection when returning to the pool. I would actually like them to stayalive in the pool but I do not know if I can have many sockets open to one port?
    Thanks!

    You are unlikely to get an exact answer.
    The first limit you'll probably run into is the number of file descriptors that can be open at a time. This depends on your OS and configured per-process limits.
    Socket buffers use memory. Amount of memory, allowed process size (if your OS enforces that with in-kernel buffers), and size of send/receive buffers give another limit.
    Other OS-dependent limits, such as a max global file descriptor count, may exist.
    TCP/IPv4 (if you use that) connections are defined by a 4-tuple {source address, source port, destination address, destination port}. As long as source address&port are unique, the same destionation address&port can be used. So theoretically you could have some two hundred trillion connections to a port (32 bit addresses * 16 bit ports minus non-allowed addresses.)
    In practical terms: check max file descriptor count. A few dozen to a few hundred should be ok for web server -class systems. Try and see what works.

  • Macs can let virus enter in a Windows network?

    We have 5 Mac in a Windows network. The IT states that the Mac (which are connected to the internet too) can let enter viruses and trojan horses and infect the windows network.
    Is it true?

    I agree. Your mac is no more or less susceptable to or likely to be a carrier of a virus than the windows or *nix boxes on the same network. Your Mac has or should have the exact same potential to be infected or to spread in fection that the other machines do.
    The only way this policy makes sense is if youre machine isnt being "managed" by IT. meaning youre not behind the same firewall and youre not adhearing to the same security policies (not to be confused with policy objects in a windows domain but rather the rules IT lays down on users and computers). If you arent adhearing to these policies i agree with them. If you are then they are just being lazy/cheap and refusing to learn a system thats foreign to them or hire a consultant to do it for them.

  • Opening a servlet in new browser window

    Does anyone know how you can make a servlet open in a a new browser window when clicking a link for that servlet.
    cheers

    Hi..
    do
    window.open("http://localhost:8080//yourservlet-path//servlet-name");
    you can also set window properties, they are passed as parameters to window.open
    see syntax of window.open. but this thing will open your servlet in a new window with default properties.

  • Opening hyperlinks in the same browser window

    Hey Gang!
    How does one create a hyperlink such that it opens in the
    same browser window and doesn't keep opening a new window each
    time?
    Cheers!
    Gregory

    Do you meant that you want to "open the hyperlinks of your flash file in the same browser window"
    You flash file will be put on the internet and I think you have to configure your brower to achieve this goal.
    We all know that IE can be configured to open the hyperlinks in the same window.
    Thus if you want your flash file achieve this feature you need to write a code to control your brower.
    This code can be a simple JS code. You can just google this to find out the answer.
    good luck
    I love using flash quiz generator

  • Can not open multiple excel 2003 and excel 2007 files in excel 2010 - message says they may be a security risk and wants to do a scan

    We use about 20 excel files to build a consolidated financial statement for our company.  Some of the files were built when  the computers were running 2003 and some when we had 2007.  We are being upgraded to Windows 7 with Office 2010.  In
    2007, we would simply highlight all the files in a folder, right click, and open.  Once they had all refreshed for new data, we would close them all.  Now with Excel 2010, we've highlighted all the files, but when we right click, we get a message
    that says some files may present an internet security risk.  Then it ask if we want to open anyway.  If we say yes, we get a box that asks us to scan the files.  We've done a scan, but at the end it still doesn't open the files.  If we
    say no, it does nothing.  Either way, we're not getting the files open except to open them 1 by 1.  We're not sure how to get rid of this...any suggestions?

    In Excel 2010 setting those documents as trusted documents, or adding the folder containing as a trusted location may do the trick for you. There's a full description of what it does here
    http://blogs.technet.com/b/office2010/archive/2009/09/28/trusted-documents.aspx but if you go into File, Options, Trust Center, Trust Center Settings..., and then Trusted Locations, you'll see the list of currently configured file paths that are considered
    trusted on your machine.
    At the bottom of that window you can check the option to allow trusted locations on the network (so you can trust the files that I assume are stored on a network location) and then add the location of those files to the list.
    Note, this setting is done per machine profile, so if it does the trick for you then each person needing these files would need to do this. Also, keep in mind that by doing this you're removing some of the protections added into Excel, so you should only
    go adding locations you know you can trust (not just the root of a network path where anyone and everyone might go saving spreadsheets they've downloaded form the internet).

  • What are the security risks for opening port 80 on workstations?

    Hello all,
    in our environment, there is an application which open port 80 on workstations when installed, but it is not allowed on preimeter FW
    could you please advise what are the security risks for leaving port 80 opened on the workstations? or it is considered secure unless it is not allowed on the preimeter FW?
    thanks alot & regards

    Hi R.Naguib.
    The 80 port is open by default through the firewall on Windows system, it is used by a http protocol by a browser.
    As for the network or hardware Firewall settings, I suggest to turn to the network administrator for details.
    Regards
    Wade Liu
    TechNet Community Support

  • Is firefox Hello (v36.0) automatically opening a listening port when starting up? Is this a security risk?

    After updating to firefox 36, windows firewall offered to block firefox. That usually happens when a program opens a port to accept INCOMING connections. Currently I have blocked it!
    Is firefox opening a listening port and is that a security risk?
    Have fun

    Mozilla Firefox is very security conscious and privacy aware.
    Some of the connections made are intended to increase security by ensuring everything is updated.
    See
    * https://www.mozilla.org/privacy/websites/ {and follow linked articles)
    * [[How to stop Firefox from automatically making connections without my permission]]
    I am not certain if the Hello & social button do anything, but you can experiment with the settings mentioned in the above article, although generally it would be best if after any experiments you returned to the default settings.

  • "one or more management packs which are ready to install present a security risk are you sure you want to continue"

    Hello
    I am installing the following MP (for Windows Client OS)
    http://www.microsoft.com/en-gb/download/confirmation.aspx?id=15700
    Into a new SCOM 2012 R2 environment
    When I go to import the MPs, I receive the following warning
    "one or more management packs which are ready to install present a security risk are you sure you want to continue"
    Is this normal?
    why am I getting this message?
    Should I continue to install any way?
    Thanks All
    AAnotherUser__
    AAnotherUser__

    It's normal. You will receive a prompt indicating that the management pack presents a security risk. This is due to the management pack’s use of agent proxying. Click
    Yes to allow the import.
    That's happened in Exchange management pack or SQL Management pack to can monitor all virtual hosts.
    Yes, you should continue to install Management pack.
    Please remember, if you see a post that helped you please click "Vote As Helpful" and if it answered your question, please click "Mark As Answer"
    Mai Ali | My blog: Technical

  • I can't use indesign since upgrade, it keeps asking me to upgrade java which I have done and still wont open please help me i have a deadline

    i can't use indesign since upgrade, it keeps asking me to upgrade java which I have done and still wont open please help me i have a deadline

    DL the SE 6 JRE from http://support.apple.com/kb/DL1572.
    27" i7 iMac (Mid 2011) refurb, OS X Yo (10.10.1), Mavs, ML & SL, G4 450 MP w/10.5 & 9.2.2

Maybe you are looking for

  • How does this quicktime pro thing work?

    i bought final cut hd about a year and a half ago and recently had to reinstall it. When i pulled out the disk , I noticed that not only did the final cut hd come with a serial number, but i had a serial number for quicktime pro, which was on the sam

  • Oracle 9.6.0.2.0

    Hi, what is meaning of 9.6.0.2.0 (release version patch version) etc....

  • Keynote3 Crashes when opening .ppt file

    I have just moved to mactel and have found the above-mentioned problem when attempting to open/import any ppt file. The error report I get is as follows...Thanks a million for any insight into this... Date/Time: 2006-02-28 16:57:23.000 -0600 OS Versi

  • Servlet coding - writing file to server

    Hi, I am using IBM's RAD as my IDE. In my servlet, I have coded:                     // set the filename for the server side repository ...                     serverFileName = "/web/UserSource/" + user + "-" + shortFileName;                     // O

  • How to Transfer contacts to one iPhone to another?

    Just bought a new iPhone 4. How can I get my contacts and SMS from my old iPhone 3 into my new iPhone?