(Windows
2008 Server:
Lesson 11)
{ Installing Microsoft
Security Baseline Analyzer }
Section 0.
Background Information |
- Overview
- In this lab, we will install Microsoft Security
Baseline Analyzer. We will also turn on and configure Windows Update.
- To easily assess the security state of Windows
machines, Microsoft offers the free Microsoft Baseline Security Analyzer (MBSA)
scan tool.
- MBSA includes a graphical and command line
interface that can perform local or remote scans of Microsoft Windows
systems.
Section 1. Login to
your W2K8 server. |
- Start your Windows 2008 Server
- Instructions:
- Click on W2K8 Server
- Click on Play virtual machine
- CRTL + ALT + DELETE
- Instructions
- Virtual Machine
- Send Ctrl+Alt+Del
- Login as Administrator
- Click on the Administrator icon.
- Login
- Command:
Provide the password for the Administrator account.
Section 2. Turn Off
Microsoft Internet Explorer Enhanced Security |
- Launch Group Policy Editor
- Instructions:
- Start --> Administrative Tools -->
Server Manager
-
- Open Internet Explorer Enhanced Security
- Instructions:
- Click on "Configure IE ESC"
-
- Configure Internet Explorer Enhanced Security
- Instructions:
- Administrators: Radio Button: Off
- Users: Radio Button: On (Recommended)
- Click OK
Section 3. Download
Microsoft Security Baseline Analyzer |
- Open Internet Explorer
- Instructions:
- Start --> Internet Explorer
- Download
- Save
- Instructions:
- Click on the Save Button
- Browse Folders
- Instructions:
- Click on the Browse Folders
- Browse Folders
- Instructions:
- If not already, Navigate to
C:\Users\Administrator\Downloads
- Click Save
- Open Folder
- Instructions:
- Click on the Open Folder
- Open Folder
- Instructions:
- Right Click on MBSASetup-x86-EN
- Click on Install
- Run
- Instructions:
- Click on Run
- Next
- Instructions:
- Click on Next
- Accept Agreement
- Instructions:
- Click the I accept radio button.
- Click the Next Button.
- Next
- Install
- Instructions:
- Click Install
- Completed Successfully Message
Section 4. Running
Microsoft Security Baseline Analyzer |
- Open a Command Prompt
- Instructions:
- Start --> Command Prompt
- Obtain Your IP Address
- Instructions:
- ipconfig
- My IP Address is 192.168.1.109;
Your IP Address will probably be different.
- Completed Successfully Message
- Instructions:
- Right Click on Microsoft Baseline
Security Analyzer
- Run as administrator
- Scan a computer
- Instructions:
- Click on Scan a computer
- Start Scan
- Instructions:
- Enter the IP Address you obtained
earlier.
- Click on the Start Scan Button.
- This report might take between
2 and 15
minutes depending on System and Network resources.
- View General Results
- Instructions:
- Using the Scroll Bar, you will see a
general report for each Issue that was scanned.
- Scroll down to Windows Security
Updates.
- Notice I have 75 security dates
that are missing, because this server was just installed and no
updates have been applied.
- Click on Result details for Windows
Security Updates
- View Detailed Results
- Notes:
- Notice that all 75 issues are listed
below.
- Each line contains a MS ID,
Description, Severity and Download link.
- Some System Administrator install these
updates manually depending on their customer and applications
restrictions.
- However, that is a lot of work.
- Continue to next section.
Section 4.
Configuring Windows Update |
- Open Control Panel
- Instructions:
- Start --> Control Panel
- Open Windows Update
- Instructions:
- Double Click on Windows Update
- Open View advanced options
- Instructions:
- Click on View advanced options, under
the Turn on now button.
- Configuring Windows Update
- Instructions:
- Select the Install updates
automatically radio button.
- Select the time you want the check and
install to occur.
- Select the OK Button.
- Install new Windows Update Software
- Instructions:
- Click on Install now.
- Install updates
- Instructions:
- Click on the Install updates button
- Accept Terms
- Instructions:
- Click on the I accept radio button.
- Click the Finish button.
- Waiting on Download updates
- Informational:
- Now you will just wait and watch.
- This might take between 1 and 2 hours
depending on how many patches are required to make your machine
compliant.
-
Go ahead
and continue to the Proof of Lab Section.
- Restart After Installation Completes
- Informational:
- Click on Restart now.
- Copy to Clipboard
- Instructions:
- Click on Copy to Clipboard.
- Open Notepad
- Instructions:
- In the search box type Notepad
- Click on Notepad once displayed under
programs.
- Paste Report Contents
- Instructions:
- Edit --> Paste
- Save the Contents
- Instructions:
- File --> Save As...
- Browse Folders
- Instructions:
- Click the Browse Folder
- Save File
- Instructions:
- Navigate to
C:\Users\Administrator\Documents
- Filename: YYYYMMDD.txt
- Click Save
- Open a Command Prompt
- Instructions:
- Start --> Command Prompt
- Proof of Lab
- Instructions:
- cd "C:\Users\Administrator\Documents"
- dir
- date
- Press <Enter>
- echo "Your Name"
-
Proof of Lab Instructions:
- Do a PrtScn
- Paste into a word document
- echo "Your Name"
- Replace the string "Your Name" with
your actual name.
- e.g., echo "John Gray"
|
|