Recommended Posts

Hi Neowinians!

I have run into a bit of a situation - i am a semi-admin for a small family business (of about 5 people or so). We have recently gotten someone in to design some software for us, and for "security reasons" he suggests installing an Antivirus on the server (specifically SBS 2008).

Currently the server is used as a file server (network shares) and will be used with exchange (2007). It hosts no externally visible web pages (only the local intranet page) and its only externally visible is a (fully updated) RDP server for admin tasks only (that is, its not running RDP for general use). I perform no tasks on it, and someone would log onto it every few months - tops. Only people who are 'tech savvy' have access to the server - and it has UAC on it. As i said, we're a small company, so we're not going to get any directed 'hate attacks', we have no published IP/DNS record. Windows firewall is configured, a hardware firewall (NAT/SPI) is in place, and all clients connecting (via VPN) have AV.

General consensus on the net seems to be to install an AV for the server - however it all seems to be knee-jerk justifications "install AV for securitieeez", without providing an actual reason. I mean i understand it WILL be more secure as it can't make it worse...but i mean, what is the actual attack vector for a virus to a server? It seems like a big overhead for our server, which will already struggle with Exchange (8GB of DDR2 RAM and a 2.66Ghz Core 2 Quad).

What do people think?

Thanks for any advice =)

Regards,

UL

Link to comment
https://www.neowin.net/forum/topic/1128892-server-antivirus/
Share on other sites

Definitely a knee jerk reaction. If you're happy with how it is keep it that way.

I imagine you're behind a firewall so the only way a virus will make it onto your server is by someone using remote desktop and going to dodgy sites \ using warez.

The main thing is to keep the box up to date with all windows \ exchange updates.

if users cannot save to any network shares on the SBS box (including home drives & inc admin$ shares), that reduces the localised risk.

id recc something filtering your exchange services for malware/spam though.

Av serves two purposes in the "admin" role, not only gives realtime protection, it also mitigates risk.

TBH Id run av on the server regardless you could always only have on access scanning on writing to the server and most SBS packages will have an smtp or exchange plugin/agent.

You could do a file scan every night.

I can understand the concern if you are using it as a file server for your business.

If the desktop experience role is added, it should bring Microsoft Windows Defender with it which better than nothing and is non-intrusive and shouldn't cause any noticable performance issues. The only drawback will be if you are monitoring Windows Updates as you will regularly get definition updates.

The main issue with the server has to be how exposed it is to the user network. If it is in its own subnet/broadcast domain and is well firewalled with only specific and explicit ports being allowed in to it (and better yet IPSec for file share access) then the attack vector is lower.

If however you have a user network where all of your users insist in living in administrator accounts on the same LAN segment with the same AD user account that has full access to the server, then you have identified the weak point and are wholly reliant on the AV solution on workstations to protect the server. The next time Sophos, McAfee or Symantec (etc) put out a bad DAT and wreck the AV scanning enging on the workstation, you may be left with nothing between it and the next Java exploit.

The real answer is to cost benefit of it to YOUR business (not mine or anyone else?s)

Worst Case: What is the cost of AV + more RAM + may be (if possible) second CPU + potentially reduced response time

vs.

Worst Case: That server going down for x hours, requiring a reinstall / restore from backup and potentially data loss

If the answer is "this server cannot be down, period" then I think you've come to your own answer. If you can afford the server to be out for 4 - 24 hours to do a repair with no tangible damage to the viability of the business (apart from your time) then equally so.

If you have an answer to that question that works for your business, then anyone else?s "gut feeling" doesn't matter. As the IT manager YOU have to make the call, not people on a web forum; simply because you are the one whose neck is on the line. You do however have to justify it at the point where it all goes wrong i.e. "why didn't we have anti-virus, the expensive recovery consultant just told me we didn't have any?" vs. "why did we just spend all that money on anti-virus and the server was down to 16 hours due to a security breach?" :p

Good luck!

  • Like 3

Thanks for the quick replies people =)

That's was my thought - a can have, but not a must have. If no one actually DOES anything on the server, there is no need for it (i don't think i have actually opened an external website on the server before lol)

Regards,

UL

Edit:

Sorry, didn't see the replies from Mando, Aergen and C:Amie.

None of the users have admin rights to the server, and i don't believe we actually have AD set up (default SBS install, basically). There aren't any domain computers on the network. Even if someone dumps an infected file onto a server share...that won't actually DO anything to the server, will it? i mean yes, it will be on the server...but it cant spontaneously insert itself into any processes.

With regard to exploits, the server doesn't actually run java as a side note, but all software is up to date...and an AV wont actually protect from exploits, will it? In my experience i rarely see an AV actually DO anything - UAC is what really saves. (On a desktop computer i would say turn on UAC and go no AV, rather than have an AV with UAC off)

If i could throw in more RAM, i would...but the server only has 4 slots, and i can't find any 4GB DDR2 sticks =(

I won't "do what im told", but it would be naive not to seek advice from people (likely) more experienced - I am far from an experienced network admin =P

Thanks again! =)

actually yes it can do something to the server if you are not signed on to it. There are ways for the server to get infected even if you are not logged onto it.

The morto worm is just one that would do so using a exploit in rdp.

http://www.infosecur...com/view/27277/

There was a SQL worm virus in 2003 that exploited holes in SQL (again don't have to be logged on into the server to get the virus).

While most viruses and malware you have to be logged onto the server to be able to get infected, there are quite a few that just having a server on the network could get the server infected. I have only listed examples of malware that have previously infected servers in the past without logging into them, this could happen again and if your system is not protected it could happen to you. It is better to have something on the server than not to protect it, esp if opening it up to the internet...the only way to be 100% and not get it infected is if you unplug the network cable and do not have it attached to any wireless network, but then what is the point of central storage when you can't attach to it some way?

[First of all, a disclaimer: I happen to work for a company that develop anti-malware software, so please keep that bias in mind when reading my reply. AG]

Hello,

It's not clear to me from reading the message thread as to whether the network containing the server has Internet access or not. If this is an isolated (non-Internet connected) network, than installing and updating security software on it is probably going to be more for compliance or insurance reasons, than anything else (e.g., install the virus signature database at the same time OS and application patches are brought in on disc).

If the server is connected to the Internet, or other devices attached to the same network it's on are connected to the Internet, than one needs to start thinking about the way in which those systems could be compromised, and what that might lead to for the business if those hosts?or the server?were compromised. Securing a network is about managing risk, and as C:Amie noted, that is a cost measurement you have to make.

For the most part, how a server is used at a business is not that relevant to the attacker: There may be data of value on it (financial or customer records, business plans and so forth), but targeted attacks like that are rare. Usually they serve as a springboard from which to attack other hosts, either on that network or other Internet-connected hosts. For that matter, an infection could occur from something like the Conficker worm, which is still spreading, even though it seems the operators of that particular piece of malware gave up on it years ago.

Does that mean that your network is bound to be infected? No, it does not. But, perhaps it does mean that some basic level of protection isn't a bad idea. While most anti-malware products for servers are commercial products, there's Clam AV, which is free. It does not have a real-time component, but you could schedule it to run at times when it won't impact the business.

Regards,

Aryeh Goretsky

This topic is now closed to further replies.
  • Posts

    • Samsung Galaxy Z Fold 8, Flip 8, Z Fold Wide: Everything you need to know The ONLY thing I need to know is the price, which I know will be way higher than I (and most people) are willing to pay for a phone... so basically nothing here I need to know. PS: Nice job getting that Apple reference to a non-existent and unrevealed product as "competition" in there. Cheque is in the mail.
    • Well I really think the repasting helped if your higher clocks have returned, maybe the next thing to look at is if there is a problem with your case airflow? I guess this because your 3080 has returned to optimal state, but is still staying too warm, which might suggest it was thermal throttling before you repasted, of which the only logical conclusion could be outside factors.
    • Samsung Galaxy Z Fold 8, Flip 8, Z Fold Wide: Everything you need to know by Hamid Ganji Galaxy Z Fold 7 - Image via Samsung The next generation of Samsung foldables is set to be unveiled next month at the second Unpacked event of the year. Samsung’s 2026 foldables are not expected to offer significant upgrades over their predecessors, with the Korean firm instead focusing on design refinements and conventional upgrades such as faster processors and better cameras. However, Samsung is reportedly planning to unveil an all-new passport-style foldable this year to rival Apple’s first foldable iPhone, which is expected to debut this September. Here’s a roundup of everything we know about Samsung’s upcoming foldable devices ahead of their official debut. When can we expect Samsung’s new foldables? The Galaxy Z Fold 7 and Z Flip 7 series were unveiled in July, and Samsung is expected to maintain this timeframe in 2026. Based on previous reports from Korean sources, Samsung will hold its Unpacked event on July 22 in London, UK, to pull back the curtain on the Galaxy Z Fold 8 series. The devices are also expected to hit the shelves a few weeks after launch. However, Samsung has yet to announce an official date. A new naming scheme? One of the most interesting changes we might see this year is a new naming scheme for Samsung’s latest foldables. SamMobile reported that since Samsung is expected to unveil three foldables this year, it has adopted a new naming strategy to simplify product identification for customers. Accordingly, the standard Galaxy Z Fold 8 will reportedly be called the Galaxy Z Fold 8 Ultra and will serve as the direct successor to last year’s Galaxy Z Fold 7. The “Ultra” suffix suggests the phone could feature higher-end specifications, such as additional rear camera modules. Samsung’s new passport-style foldable is expected to carry the Galaxy Z Fold 8 name without any suffix. This model is reportedly equipped with two rear cameras. No major changes are expected for the Flip model. Galaxy Z Fold 8 Ultra and Z Flip 8 anticipated specs Rumors over the past few months suggest Samsung is preparing several upgrades for its upcoming foldables, although the devices may continue to rely on larger batteries and faster charging speeds rather than dramatic design changes. The primary focus this year is expected to be the Galaxy Z Fold 8 and its wide-screen design. Galaxy Z Fold 8 Ultra official CAD renders - Image via AndroidHeadlines Here are the anticipated specifications for the Galaxy Z Fold 8 Ultra based on previous leaks: 6.5-inch outer display and 8-inch inner display, 120Hz refresh rate, and 2,600 nits peak brightness Snapdragon 8 Elite Gen 5 processor, paired with 12GB or 16GB of RAM and 256GB, 512GB, or 1TB of storage 4.1mm thickness when unfolded and a weight of 210g 200MP main camera, 50MP ultrawide camera, 10MP or 12MP telephoto camera, 10MP cover camera, and 10MP selfie camera 5,000mAh battery with 45W wired charging Android 17 and One UI 9 As for the Galaxy Z Flip 8, the device is not expected to be a major departure from its predecessor, although it could become slightly slimmer. Expected specifications include: Snapdragon 8 Elite Gen 5 or Exynos 2600 processor 12GB of RAM with 256GB and 512GB storage options 6.9-inch Dynamic AMOLED 2X inner dispaly and 4.1-inch Super AMOLED outer dispaly 50MP main camera, 12MP ultrawide camera, and 10MP selfie camera 4,300mAh battery with 25W wired charging Android 17 and One UI 9 Samsung’s foldables are also expected to launch with Gemini Intelligence, Google’s AI suite for automating tasks in Android ecosystem. Moreover, given current memory and component costs, some Galaxy Z Fold 8 Ultra and Z Flip 8 variants could see a price hike. Galaxy Z Fold 8 adopts a wide-screen design The centerpiece of the upcoming Unpacked event could be the Galaxy Z Fold 8, previously rumored as the Galaxy Z Fold Wide. This model adopts a passport-style form factor and is expected to compete directly with Apple’s iPhone Fold. Galaxy Z Fold 8 official CAD renders - Image via AndroidHeadlines Here’s what to expect: 7.6-inch primary OLED display and 5.4-inch cover display, 120Hz refresh rate, 2,600 nits peak brightness, and 4:3 aspect ratio Snapdragon 8 Elite Gen 5 processor, 12GB or 16GB of RAM, and 256GB, 512GB, or 1TB storage options 4,800mAh battery with 45W wired charging 50MP main camera, 50MP ultrawide camera, and 10MP selfie camera Android 17 and One UI 9 The three new foldable phones are unlikely to be the only devices unveiled at Samsung’s Unpacked event. The company is also expected to introduce the Galaxy Watch Ultra 2 and the Galaxy Watch 9 series.
    • Thanks
  • Recent Achievements

    • Week One Done
      rolfus earned a badge
      Week One Done
    • One Month Later
      Leroy Jethro Gibbs earned a badge
      One Month Later
    • Conversation Starter
      flexorcist earned a badge
      Conversation Starter
    • One Month Later
      AndreaB earned a badge
      One Month Later
    • One Month Later
      agatameier earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      504
    2. 2
      +Edouard
      196
    3. 3
      PsYcHoKiLLa
      140
    4. 4
      ATLien_0
      88
    5. 5
      Steven P.
      81
  • Tell a friend

    Love Neowin? Tell a friend!