Internet Security Tips...

ic

MyBroadband
Super Moderator
Joined
Nov 8, 2004
Messages
14,812
Reaction score
268
Location
A nearby event horizon
I have decided to start this thread, hoping that we can share some internet security tips - general stuff (i.e. nothing specific to any particular type of connection).

So, here's my first tip for Windoze 2000 Professional & XP:

In Network and Dial-up Connections, open the properties for the connection you use to connect to your ISP, now click on the Networking tab, now ensure that File and Print Sharing for Microsoft Networks is unchecked (disabled).
 
Last edited:
If you are on a network of shared pc's of which at least one is semi/permanently connected to the Internet, make sure any network shares are password protected to stop the spread of virusses that propagate through this weakness in Windows networks.
 
1) Firewall for your network, ideally a seperate Linux box, but if not then either enables Windows firewall or install the free version of ZoneAlarm (better imho that Windows firewall)

2) Keep your machine clean. Don't install things just because you can, take time to understand what the install is doing (is it setting things up to run on startup, what does the EULA say). Clicking next-next is not a good idea
 
Keep clear off ad banners for :

  • fancy bouncy bouncy smileys,
  • sotware offering to update your clock or weather;
  • screensavers
  • browser enhancement

Better yet; get Firefox.

Have a password for the Adminstrator account, if you can rename that account to something else
 
antowan said:
If you are on a network of shared pc's of which at least one is semi/permanently connected to the Internet, make sure any network shares are password protected to stop the spread of virusses that propagate through this weakness in Windows networks.

To do that you need Win2k or higher, which is just recommended as well for decent security (obviously latest patches should be installed). Win95/98/Me do support it but there are viruses and hundreds of tools to crack them in millisecond, hell GFI Languard even cracks them and it's aimed at sys-admins not l33t hax0rs :)
 
If you are wanting to use the free version of ZoneAlarm, make sure you only use it on ICS client machines and not a gateway machine. If you want to use ZoneAlarm on your gateway machine (Internet Connection Sharing "server" / IP: 192.168.0.1) you'll need to install the ZoneAlarm Pro version.
 
Let me guess then, your mind to my mind, your thoughts to my thoughts.>.>.>.XP & Fifi1.0.>.>.>?
 
make sure that if you are using a wireless lan that it is secured properly - unsecured wireless is the easiest way to get yourself hacked.
 
you will never be 100% safe - all you can do is mitigate your risk. Make it as hard as possible for a hacker to get into your system. If he/she is after a quick win, they will move on quickly. If they are hell bent and determined to get in, they most probably will.
If you need help mitigating risk, i can post some guidelines...
 
cool - will just password protect my new networks (ones i use for gaming etc) - i don;t keep anything very valuable on my computer (no banking details etc) so it should be fine
 
kilps said:
cool - will just password protect my new networks (ones i use for gaming etc) - i don;t keep anything very valuable on my computer (no banking details etc) so it should be fine

Be carefull of that neighbour that might hack into your wireless home-lan to use find your internet proxy machine and use up your bandwidth. ;)
 
ScrnScrm said:
you will never be 100% safe - all you can do is mitigate your risk. Make it as hard as possible for a hacker to get into your system. If he/she is after a quick win, they will move on quickly. If they are hell bent and determined to get in, they most probably will.
If you need help mitigating risk, i can post some guidelines...

I picked up a lot of tips from the Linux Security How-to (here's one: http://www.tldp.org/HOWTO/Security-HOWTO) even for my W2K machine
 
hmm...maybe updated anti-virus and anti spyware is da answere
 
Anyone reading this thread, please read the following thread as well (there is actually useful info in there ;)):

[post=106381]what anti-virus do you use?[/post]
 
I do some wierd stuff. Gotta SQL Server database with a database called porn, and if it's accessed, the SQL Server shuts down.

My "server" has a fake (Ramdisk) C: drive with a fake windows directory. If the windows directory is accessed, I get an email (Using FileAccessMonitor type thingy.). The email contains the program + process of the attacking program. I'm still trying to get the code that tells me more about the process (What port's its binding to) to be stable. One - day.

I used a similar thing with the registry, though I stopped using that, cos was getting too many false alarms, need to fixitup a bit.

I like the - lure the attacker in this direction - approach.
 
stoke said:
I like the - lure the attacker in this direction - approach.
It's called a honeypot. Used a lot by anti-spam groups as well.
There is also some special software coming out now days to create honeypots
 
Top
Sign up to the MyBroadband newsletter
X