Hi! I pursue an MSc in System and Network Security and I am currently doing my internship in a media group (ieTV, Radio, WebSites etc).My "mission" is to write down a security policy for their network.
Basically I know where to start,meaning things such as Anti-Virus etc. The problem is that their network is not totally new. They have PIX, Packet Shapers, Anti Virus installed etc. That means that my "job" is getting even more difficult cause I have to dig and find the details, which is not so easy for a newbie in security :-( Another problem is that their systems are based on Windows :-( Any advices? Where could I start? Having several thoughts, test the password cracking of the users could be a good step(I assume). Is there any such tool?or does anyone know where Win2k stores the password and how it is hashed? Finally, I am trying to find a tool (freeware) to help me do the auditing (eg run penetration tests etc) If anyone knows such tool, it woud be great? Thnx in advance John --------------------------------------------------------------------------- ----------------------------------------------------------------------------