Slashdot Mirror


Security Issues with Windows 2000 Datacenter?

alen asks: "The recent IIS security incidents got me thinking. Code Red and Nimda hit servers that weren't patched by their sys admins. If you get infected, you patch your server and end of story. But what if you're running Windows 2000 Datacenter Server? It's a customized solution that you can't change. All your service packs are customized by your vendor. What happens if you have a web or database server that needs to be patched immediately? Are you left out in the cold running unsecure software that you can't patch while you wait in line for your vendor to issue you a service pack or hotfix?" In a situation like this, the whole ball-o-wax resides with the vendor. If you have a good vendor who actually cares about customer satisfaction, these hotfixes will be available quickly. Would anyone out there actually recommend Datacenter for corporate environments?

"My company is currently looking to cluster our SQL 7 servers. We're considering Win2000 advanced server or datacenter. Around a month ago I sat in a meeting with our VP of IT, and the rest of the network admins I work with. Compaq tried to pitch their Windows 2000 Datacenter or Advanced Server solution. Here is the way the compaq people explained it:

You get datacenter only from an OEM. They look at the apps you're running and customize a solution for you in their lab. Every datacenter implementation is different, and every datacenter CD is different. Since we would be using an EMC SAN as our clustered storage system they said our implementation would take special customization. They would have to contact EMC engineers and work together. Once you deploy it, the OEM monitors it. And you can't install any service packs or anything without getting an OK from your OEM. Any service packs are customized for your enviroment. The SLA guarantees a 99.999% uptime or your money back. Part of your money at least. Datacenter isn't an OS, but a program in their words.

Now here is the problem. With Code Red and Nimda, how do you patch IIS running on datacenter in a timely manner? The reason IIS servers became infected was because the admins didn't patch them in the first place. So say a new worm comes out in a few months and it takes a few days for MS to create a hotfix. Datacenter admins can't install it until they get their customized copy from their OEM. And almost every 2000 server runs IIS for terminal server. It can take a few days and in the meantime your servers could be down. And I don't see the SLA covering a situation like this. Meanwhile you're explaining to your CEO how this $500K supposedly guaranteed solution is sitting dead in the water and you can't do a thing about.

Is there something I'm missing, or did Microsoft look over something like this? Especially when they are trying to push Datacenter as 'Big Iron'."

10 of 357 comments (clear)

  1. Mad Propz by Anonymous Coward · · Score: -1, Offtopic

    Mad propz to all my dead evil_sporkz

  2. the keystone of coding by Anonymous Coward · · Score: -1, Offtopic

    A, a-head, aimies, amp, amped, bam, beans, bennies, Benny and the Jets, benz, black beauties, black bombers, blacks, black mollies, black & white, black birds, blue boy, bombido, bombita, brain ticklers, brownies, browns, bumblebees, candy, cartwheels, chalk, chicken powder, chocolate, Christina, Christmas tree, co-pilot, coasts to coasts, crank, crisscross, cross tops, crossroads, crystal, dexies, diet pills, dominoes, double cross, eye opener, fives, footballs, forwards, French blue, glass, head drugs, hearts, horse heads, ice, inbetweens, jam, jam cecil, jelly baby, jelly bean, jolly bean, jugs, LA, LA turnarounds, leapers, lid proppers, lightning, little bomb, marathons, minibennie, nugget, oranges, peaches, pep pills, pink hearts, pixies, powder, purple hearts, rhythm, ripper, road dope, rosa, roses, snap, snow, snow pallets, sparkle plenty, sparklers, speed, speedball, splash, splivens, sweets, thrusters, TR-6s, truck drivers, turkey, turnabout, turnarounds, uppers, uppies, wake ups, West Coast turnarounds, white, white cross, whites, X

  3. In my opinion: #@ +1 ; Important @# by Anonymous Coward · · Score: -1, Offtopic

    Who gives a f$ck about anything from this
    repressive, totalitarian craporation?

  4. 'unsecure' isn't a word by Anonymous Coward · · Score: -1, Offtopic

    no text

  5. duh by Anonymous Coward · · Score: -1, Offtopic

    Ever hear of a firewall you FUD spreading cocksniffer...

  6. Moron. by Anonymous Coward · · Score: -1, Offtopic

    Now here is the problem. With Code Red and Nimda, how do you patch IIS running on datacenter in a timely manner? The reason IIS servers became infected was because the admins didn't patch them in the first place. So say a new worm comes out in a few months and it takes a few days for MS to create a hotfix. Datacenter admins can't install it until they get their customized copy from their OEM. And almost every 2000 server runs IIS for terminal server. It can take a few days and in the meantime your servers could be down. And I don't see the SLA covering a situation like this. Meanwhile you're explaining to your CEO how this $500K supposedly guaranteed solution is sitting dead in the water and you can't do a thing about.

    This entire discussion is pointless. No one uses Datacenter for web hosting. And wtf is "runs IIS for terminal server" supposed to mean? That doesn't even make any sense.

  7. Ass sideways test utitlized again by Anonymous Coward · · Score: -1, Offtopic

    Heres the deal. If I can shove Windows 2000 Datacenter into my ass sideways, there is a security issue. If not, there is not. I have been able to determine that there IS A SECURITY PROBLEM WITH 12PACKS OF PEANUT BUTTER TOAST-A-CHEES. USE AT YOUR RISK. Thanks in advance.

  8. SUPER DUPER IMPORTANT! READ IMMEDIATELY! by Anonymous Coward · · Score: -1, Offtopic

    Heather Locklear loved lesbian kiss

    By Stephanie N. Marcucci, Hollywood.com Staff

    HOLLYWOOD, October 19, 2001 -- Heather Locklear, whose upcoming episode of Spin City includes a lesbian scene with actress Denise Richards, says she enjoyed the experience.

    "I saw [Denise] in Wild Things with Neve Campbell, and so I knew how sexy [she] was.

    "So I practiced kissing with my make-up artist Lisa. Every Thursday night we run through the lines and rehearse them at dinner, and she said, 'Show me how you're going to kiss Denise.'

    "But when it really happened, I have never felt such beautiful soft lips in my life. I fell in love."

  9. SPLAT!! SPLAT!! by Anonymous Coward · · Score: -1, Offtopic

    (wipes spooge from keyboard)

  10. Re:Whats it needed for? by Anonymous Coward · · Score: -1, Offtopic

    mmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmMMMMM MMMMMMMMMMMMMMMMMMMMMMMMMMMmmmmmmmmm

    THIS Idsf ewrwetr etwertkwe rwe ew
    rew rwqt t tet e
    t

    te