Hi All,
I’m setting up our firms first Domino server outside our firewall… It will be version 6.5 on a Windows2003 server.
Is there a checklist or documentation out there somewhere about how to harden the Domino server against attacks? We have something similar for the OS and I was hoping that there was something I could use to model our Domino server.
Thanks
Scott
Subject: It’s called i.scan.domino
http://80.219.231.235/ref/iscandomino.nsf
VERY handy tool.
Subject: RE: It’s called i.scan.domino
also a very Handy tool for DRCC to know your URLs and sell you business. I would not recommend it for that reason alone.
Subject: No negative experiences with drcc
I get mail from them but that’s stuff I explicitly opted in for. Haven’t seen any other spam.
Subject: I didn’t opt in - and don’t… so seems OK to me.
Subject: RE: It’s called i.scan.domino
Hi DRCC here!! We would NEVER publish, sell or in any way shape or form divulge any information sent to us by you using any of our tools. I understand that this does occur but please be assured that DRCC does not participate in any such information sharing.
just so the record is clear =)
Subject: …never been approached yet…
I often read your posts with interest (and sometimes tongue in cheek) and have learned a lot from you… in this case I have to disagree - I consider them a reputable resource who would not send unsolicited information; I have used the tool several times and never had any contact from them.
C>
Subject: Rod Whiteley posted this before…
RE: Locking Down SecurityPosted by Rod Whiteley on 15.Oct.03 at 07:51 AM using Lotus Notes
Category: Domino ServerRelease: 6.0.2 CF2Platform: All Platforms
There is an interesting paper by NGSSoftware: Hackproofing Lotus Domino Web Server, but I do not think it applies specifically to Domino 6.
Helped me out…
Addition: There was also a web site that will query a given domino server for the usual exploits and give recommendations. I think it was run by the ini reference people… I’ll see if I can find it and post the address.