Home > Domino Tips > Spam and Security > Check those ACLs
Domino Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

SPAM AND SECURITY

Check those ACLs


Ezzeddeen Jradi
05.14.2002
Rating: -4.28- (out of 5) Hall of fame tip of the month winner


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Haste makes waste, as they say, and setting the ACL for your important Domino server files is no exception. Knock on the door and you shall hear the answer, but what if that door was open, certainly you wouldn't notice.

Question: When was the last time you checked the ACL of your names.nsf, catalog.nsf or any other file? Probably not recently. We all agree that the Domino server provides several fields or methods to secure our server from intruders. But too often, those fields are left untamed.

I have been on the Internet lately looking for some material on Lotus Notes, and I ran into several sites that host that info. To my curiosity I wanted to check how secure their systems were, Domino server-wise. To tell you the truth, it was not what I expected. I ran into two situations that led me to write this tip.

One of those had a huge network with four servers and approximately 3,000 users. I don't blame anyone with a big network like that. They had the names.nsf without authentication, but of course they were not that ignorant, and they set the ACL to Reader. Guess what, I was still able to detach several of their server's ID. I believe all of you understand the wealth of information that the names.nsf provide. I was lucky, because they also forgot to turn on the logging, which this means they didn't even know I was there.

The other site was a little bit more conservative than the first. It only had one server and approximately 1,500 users. And by checking the names in the administrator group, I found that there were more administrators, which meant that fewer adjustments were needed. Their logging was on, but the names.nsf had no authentication with Reader Access level. I also went to their catalog.nsf and found discovered lots of databases that had either the Default or the Anonymous with Manager level. (I enjoyed this a lot.)

In both cases, a lot of information was exposed to the public. I even know some of their pets' names, not to mention their fax numbers, phone numbers and more. I can assure you that in either case, the info that was available to the public would have been a major threat on both site identities.

Most administrators, including myself, spend most of their time using the administrator client and rarely open any of those important databases through a browser to find more about what they could provide as information to us or the intruders.

Wondering what I did with them? Well, Lotus geeks always stick together, I e-mailed them both and I believe they have learned their lessons.

This tip is meant to be a reminder that simple actions in each case were necessary to keep them on the safe side.

For more information, see Chuck Connell's tips on searchDomino: Scanners warning and checklist. In this tip, Chuck says he doesn't recommend running this on your server. I would suggest that you run the security check on a lab server and write down those files that the test examined. Then go through your system and check the ACL for those files.

Also see Chuck's tip titled Enforce Consistent ACL.

Finally, I do suggest a schedule for security check every now and then. And of course, Lotus Notes' scheduling will make sure that you are notified!

Rate this Tip
To rate tips, you must be a member of SearchDomino.com.
Register now to start rating these tips. Log in if you are already a member.


Submit a Tip




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Spam and Security
Securely connect Lotus Domino servers on different domains
Protect Lotus Notes from malicious code with the Domino ECL
How to correct Lotus Notes public key mismatches in four easy steps
A recipe for secure IM success
Telecommuter security kit
Spear phishing: Don't be a target
FAQ: Lotus Notes Domino password issues
Security awareness training: How to educate employees about spyware
Seven tips to strengthen your Domino e-mail security
Admin2005 preview: Tips, techniques, and a look at Notes/Domino Rel. 7

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Domino & Lotus Notes Security Solutions: Authentication, Antispam, Encryption and Antivirus
HomeTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersDomino IT Downloads
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 1999 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts