APK Posted November 22, 2007 Report Share Posted November 22, 2007 HOW TO ACHIEVE 85.xxx (or, better) CIS TOOL scores for Windows users via the APK "12 step program" 4 a secure Windows NT-based OS (2000/XP/Server 2003/VISTA)) INTRODUCTION:Windows CAN be secured very well, but, you have to go thru some "GYRATIONS/EFFORT" to do it, but, it IS doable (but not to any 100% levels, because again - new holes/vulnerabilities appear in the OS & its libs + apps, but this gets you closer, if not as close as a body needs to be!).THIS IS GEARED TO "stand-alone" systems online on the internet (However - it can be adapted for LAN/WAN office or home networked environs, BUT, pay attention to step #2's 'warnings' about pulling Client For Microsoft Networks, &/or File & printer sharing - most networks require/need this)BACKGROUND & INFORMATION + TOOLS YOU CAN USE TO HELP YOU SECURE YOUR SYSTEM:Here I am running Windows Server 2003 SP #2, fully current patched by MS update pages, here (I check it every 2nd Tuesday of the month of course, on "Patch Tuesday's"):http://www.microsoft.com/downloads/Browse....rder=descendingIt is a personally 'security-hardened' model I have been working on for many years, using principals I learned & used since the NT 3.5x days onward to this version of the OS: As is now?I score an 85.760 on the CIS Tool 1.x currently as of 10/10/2007!http://forums1.techpowerup.com//attachment...mp;d=1192208359This is up from my past score here of 76.xxx on it (default score I had prior to this security hardening via CIS TOOL & its advisements & past the 84.735 I initially hardened it up to, & later 85.185 as well), & here is how to do it!Currently, I can go NO higher than this score of 85.760 (of 100 total) on CIS Tool 1.x for Windows, pictured here (photo proof/pictures DO say, a 1,000 words (like this post, lol)) & even IF I could get past the few areas I know are wrong (the test errs, as it does on some areas in LINUX as well), I cannot get past 88% or so, period!============================================================================HERE ARE LINUX SCORES FROM CIS TOOL (SuSE Enterprise Linux under VMWare):============================================================================HARDENED LINUX:http://forums1.techpowerup.com//attachment...mp;d=1192894351DEFAULT LINUX:http://forums1.techpowerup.com//attachment...mp;d=1192894012(It appears that LINUX has FAR LESS TESTED, when compared to the SIZE of the Windows tets, & Linux CAN reach 90++ scores (but there is an error in CIS TOOL preventing myself from going to a higher than 85.760 score & I have submitted the data to CIS TOOL's authors on that account WITH PROOFS, and even if I could get the few areas I am scored down on still, it would not add to past 88% or so... bug, bigtime, do the math from my score & see))============================================================================BUT, that is a GOOD score (especially considering the default score of VISTA even, is FAR BELOW THAT! Nice part is? The techniques noted here can LARGELY APPLY TO VISTA AS WELL! Read on...)(For CIS Tool - There are Linux, Solaris, BSD variants, & other OS models ports (some only in .pdf security guide form though, not programmatically automated yet, like MacOS X) of this are available too by the way - not really "ports" strictly speaking, they require JAVA to run)DOWNLOAD URL FOR CIS TOOL (for multiple platforms), from "The Center for Internet Security" here:http://www.cisecurity.org/bench.html(IMPORTANT: This tool IS invaluable in guiding you to a more secure OS, on any OS platform really!)APKP.S.=> Now that the "introductory material" has been put out (scores possible, tools to use, etc. et al)? Have @ it & enjoy. Also - IF You have additional points to make that improve OR add to this?? Please - let 'em rip (we ALL can gain by it)... apk Quote Link to comment Share on other sites More sharing options...
APK Posted November 22, 2007 Author Report Share Posted November 22, 2007 APK 12 STEPS TO FOLLOW TO SECURE YOUR WINDOWS NT-BASED SYSTEM (2000/XP/SERVER 2003/VISTA):1.) Windows Server 2003's SCW was run over it FIRST (this only exists on Windows Server 2003, not on 2000/XP (you have to install this, it does NOT install by default) first to help security it (SCW = security configuration wizard, & it's pretty damn good believe-it-or-not, (@ least, as as starting point))...Directions for its installation are as follows:Start the Add or Remove Programs Control Panel applet.Click Add/Remove Windows Components.On the Windows Components Wizard screen, select the "Security Configuration Wizard" check box, as the figure shows. Click Next.The Windows Components Wizard builds a list of files to be copied and finishes installing SCW. Click Finish.DONE! Now, run it...It is very simple to use, and will help even TRIM services you do not need running (which saves Memory, other resources, & I/O to cpu/ram/disk etc. AS WELL AS PROVIDING SECURITY should any services you disable turn up vulnerabilities (this has happened before)).ALSO, per TPU forums user (username "xvi") @ techpowerup.com forums (software section): Use Microsoft Baseline Security Advisor, a free download from Microsoft as well to check your system for security holes, patch updates, etc. (be wary of the fact it does require various services running though, iirc, Terminal Server Services Client - I do NOT keep that running here anymore, & this program failed on me because of that (would not initialize @ all))---------------------------------------------------------------------------------------------------2.) Disable Microsoft "File & Print Sharing" as well as "Client for Microsoft Networks" in your LOCAL AREA CONNECTION (if you do not need them that is for say, running your home LAN)!E.G.-> Here? I pull ANY Networking clients &/or Protocols in the Local Area Connection, other than Tcp/IP typically (& disable NetBIOS as well, because I don't need it here), on a stand-alone machine that is not dependent on Microsoft's File Sharing etc. on a LAN/WAN. I also disable that too!---------------------------------------------------------------------------------------------------3.) Use IP security policies (modded AnalogX one, very good for starters, you can edit & add/remove from it as needed) - Download url link is here for that:http://www.analogx.com/contents/articles/ipsec.htm(Search "AnalogX Public Server IPSec Configuration v1.00 (29k zip file)" on that page & follow the directions on the page!)NOTE: This can be 'troublesome' though, for folks that run filesharing clients though.An alternative to this is using IP Ports Filtrations, in combination with a GOOD software firewall &/or NAT 'firewalling' (or true stateful inspection type) router. All of these work in combination w/ one another perfectly.(HOWEVER - Should you choose to use it, and do filesharing programs? No problem really, because you can turn them on/off @ will using secpol.msc & the IP stack in Windows 2000/XP/Server 2003/VISTA is of "plug-N-play" design largely, & will allow it & when done? TURN THEM ON, AGAIN! These work WITH software & hardware router firewalls, IP port filtering, and security IP policies, simultaneosly/concurrently, for "layered security", no hassles!).---------------------------------------------------------------------------------------------------4.) USE General security policies (in gpedit.msc/secpol.msc), these are VALUABLE tools (and will be needed & suggestions for it will be told to you by the CIS Tool noted above - great stuff!) and regedit.exe!(Newly added - regedit.exe use is for registry ACL permissions, via its EDIT menu, PERMISSIONS submenu item (to add/remove users that have rights to regisry hives/values, & to establish their rights levels therein))ALSO NEWLY ADDED - Explorer.exe "right-click" on drive letters/folders/files (for file access ACL permissions hardening) using its popup menu selection of "PROPERTIES", & in the next screen, the SECURITY tab (to add/remove users that have rights to said items, & to establish their rights levels therein), also - this is another requirement of CIS Tool 1.x & its suggestions for better security.---------------------------------------------------------------------------------------------------5.) HARDENING & SECURING SERVICES HOW-TO:Many services I do not need are either cut off OR secured in their logon entity to lower privilege entities (from default, near "ALL POWERFUL" SYSTEM, to lesser ones like NETWORK SERVICE or LOCAL SERVICE). I went at ALL of the services in Windows Server 2003 (some will not be in XP for instance, & Windows 2000 has no NETWORK SERVICE or LOCAL SERVICE as far as I know, but not sure, you can always make a limited privelege user too for this on 2000 if needed)...I did testing to see which services could be run/logged in as LOCAL SERVICE, or NETWORK SERVICE, rather than the default of LOCAL SYSTEM (which means Operating System entity level privileges - which CAN be "misused" by various spyware/malware/virus exploits).LOCAL SERVICE startable list (vs. LocalSystem Logon Default):Acronis Scheduler 2 ServiceAlerter (needs Workstation Service Running)COM+ System ApplicationGHOSTIndexing ServiceNVIDIA Display Driver ServiceOffice Source EngineO&O Clever CacheRemote RegistrySandra ServiceSandra Data ServiceSmartCardTcp/IP NetBIOS HelperTelnetUserProfile Hive Cleanup ServiceVolume Shadowing ServiceWindows UserMode DriversWindows Image AcquisitionWinHTTP Proxy AutoDiscovery ServiceNETWORK SERVICE startable list (vs. LocalSystem Logon Default):ASP.NET State ServiceApplication Layer GatewayClipbook (needs Network DDE & Network DDE DSDM)Microsoft Shadow Copy ProviderExecutive Software UndeleteDNS ClientDHCP ClientError ReportingFileZilla ServerMachine Debug ManagerMergerNetMeeting Remote Desktop Sharing ServiceNetwork DDENetwork DDE DSDMPDEngine (Raxco PerfectDisk)Performance Logs & AlertsRPCRemote Desktop Help Session Manager ServiceRemote Packet Capture Protocol v.0 (experimental MS service)Resultant Set of Policies ProviderSAV RoamSymantec LiveUpdateVisual Studio 2005 Remote DebugPLEASE NOTE: Each service uses a BLANK password when reassigning their logon entity (when you change it from the default of LOCAL SYSTEM Account), because they use SID's as far as I know, not standard passwords.WHEN YOU TEST THIS, AFTER RESETTING THE LOGON USER ENTITY EACH SERVICE USES: Just run your system awhile, & if say, Norton Antivirus refuses to update, or run right? You KNOW you set it wrong... say, if one you test that I do NOT list won't run as LOCAL SERVICE? Try NETWORK SERVICE instead... if that fails? YOU ARE STUCK USING LOCAL SYSTEM!If you cannot operate properly while changing the security logon entity context of a service (should NOT happen w/ 3rd party services, & this article shows you which ones can be altered safely)?Boot to "Safe Mode", & reset that service's logon entity back to LOCAL SYSTEM again & accept it cannot do this security technique is all... it DOES happen!If that fails (shouldn't, but IF it does)? There are commands in the "Recovery Console" (installed from your Windows installation CD as a bootup option while in Windows using this commandline -> D:\i386\winnt32.exe /cmdcons, where D is your CD-Rom driveletter (substitute in your dvd/cd driveletter for D of course)) of:ListSvc (shows services & drivers states of stopped or started)Enable (starts up a service &/or driver)Disable (stops a server &/or driver)Which can turn them back on if/when needed(ON Virtual Disk Service being removed, specifically (because it used to be in this list)): This was done solely because, although it will run as LOCAL SERVICE, diskmgmt.msc will not be able to work! Even though the Logical Disk Manager service does not list VirtualDisk as a dependency, this occurs, so VirtualDisk service was pulled from BOTH the LOCAL SERVICE and NETWORK SERVICE lists here... apk)CUTTING OFF SERVICES YOU DO NOT NEED TO RUN IS POSSIBLY THE BEST METHOD OF SECURING THEM, AND GAINING SPEED SINCE YOU ARE NOT WASTING I/O, MEMORY, or OTHER RESOURCES ON THEM, PERIOD, in doing this - do consider it, when possible! Many guides online exist for this, & I authored one of the first "back in the day" for NTCompatible.com as "Article #1" back in 1997-1998 - the latest ones are even BETTER!SECURING SERVICES @ THE ACL LEVEL VIA A SECURITY POLICY HOW-TO:STEP #1: CONFIGURE A CUSTOM Microsoft Management Console for this!Configuring yourself a "CUSTOM MMC.EXE (Microsoft Mgt. Console)" setup for security policy templates, here is how (these are NOT default Computer Mgt. tools, so you have to do this yourself, or run them by themselves, but this makes working w/ them convenient):The next part's per BelArcGuy of BELARC ADVISOR's advice (pun intended):http://forums.techpowerup.com/showthread.php?t=16097"Security Configuration and Analysis" is an MMC snap-in. To access the MMC, type in mmc to the Windows Run.. command to pop up the console. Then use it's File|Add/Remove Snap-in... command and click the Add button on the resulting dialog. Choose both "Security Configuration and Analysis" and "Security Templates", close that dialog, and OK. You'll end up with a management console that has both of those snap-ins enabled. The whole MMC mechanism is a bit weird, but does work"(It's easy, & it works, & is necessary for the actual steps to do this, below)Next, is the actual "meat" of what we need to do, per Microsoft, to set ACLs!STEP #2: HOW TO: Define Security Templates By Using the Security Templates Snap-In in Windows Server 2003http://support.microsoft.com/kb/816297Create and Define a New Security Template(To define a new security template, follow these steps)1. In the console tree, expand Security Templates2. Right-click %SystemRoot%\Security\Templates, and then click New Template3. In the Template name box, type a name for the new template.(If you want, you can type a description in the Description box, and then click OK)The new security template appears in the list of security templates. Note that the security settings for this template are not yet defined. When you expand the new security template in the console tree, expand each component of the template, and then double-click each security setting that is contained in that component, a status of Not Defined appears in the Computer Setting column.1. To define a System Services policy, follow these steps:a. Expand System Servicesb. In the right pane, double-click the service that you want to configurec. Specify the options that you want, and then click OK.(And, of course, the user feedback on its effectiveness (Makes your Win32 NT-based OS very much like how MacOS X treats its daemon processes via privelege levels), which uses the same general principals)It works, & although many service packs for Windows OS' have changed their services (not all but many nowadays) to less than SYSTEM, my list covers those they may not have in recent service packs AND 3rd party services are listed too that you may be running possibly!DONE!---------------------------------------------------------------------------------------------------6.) Another thing I do for securing a Windows NT-based OS: IP Port Filtrations (like ip security policies (per AnalogX above), it is often called the "poor man's firewall" & works perfectly with both IPSecurity policies, hardware AND software firewalls, all in combination/simultaneously running)!DIRECTIONS ON HOW TO IMPLEMENT THEM (very easy):Start Menu -> Connect To Item (on the right hand side) -> Local Area Connection (whatever you called it, this is the default, iirc) open it via double click OR, right-click popup menu PROPERTIES item -> Properties button on left-hand side bottom, press/click it -> NEXT SCREEN (Local Area Connection PROPERTIES) -> "This connection uses the followng items" (go down the list, to Tcp/IP & select it & /click the PROPERTIES button there) -> Press/Click the Advanced Button @ the bottom Right-Hand Side (shows Advanced Tcp/IP Settings screen) -> OPTIONS tab, use it & Tcp IP Filtering is in the list, highlite/select it -> Beneath the Optional Settings, press/click the PROPERTIES button on the lower right-hand side -> Check the "Enable Tcp/IP Filtering (on all adapters)" selection -> In the far right, IP PROTOCOLS section, add ports 6 (tcp) & 17 (udp) -> In the far left "tcp ports" list - check off the radio button above the list titled "PERMIT ONLY", & then add ports you want to have open (all others will be filtered out, & for example, I leave port 80,8080, & 443 here open, only - you may need more if you run mail servers, & what-have-you (this varies by application)) -> I leave the UDP section "PERMIT ALL" because of ephemeral/short-lived ports usage that Windows does (I have never successfully filtered this properly but it doesn't matter as much imo, because udp does not do 'callback' as tcp does, & that is why tcp can be DDOS'd/DOS'd imo - it only sends out info., but never demands verification of delivery (faster, but less reliable)) -> DONE!You may need a reboot & it will signal if it needs it or not (probably will, even in VISTA):I say this, because although IP Security Policies work with the "Plug-N-Play" design of modern Windows NT-based OS' (ipsec.sys) & do NOT require a reboot to activate/deactivate them in Windows 2000/XP/Server 2003/VISTA? This is working @ a diff. level & diff. driver iirc (tcpip.sys) & level of the telecommunications stacks in this OS family & WILL require a reboot to take effect (for a more detailed read of this, see here):http://www.microsoft.com/technet/community...guy/cg0605.mspx(In THAT url above? Trust me - Enjoy the read, it is VERY informative: That article shows you how TcpIP.sys, ipnat.sys, ipsec.sys, & ipfiltdrv.sys interact, PLUS how you can use them to your advantage in security!)---------------------------------------------------------------------------------------------------7.) Plus good email client practices like using .txt mail only, no RTF or HTML mail, not opening or allowing attachments unless I know the person & even THEN, scan it with an antivirus (still gets email scanned though by your resident antivirus email scan component (use AntiVirus programs with these, OR, manually scan ANY attachments before opening them (if you get Microsoft Office .doc, .xls, .ppt etc. files uncompressed? HOLD DOWN THE SHIFT KEY AS YOU OPEN THEM - this stops macros from running & macros are the avenue utilized using VBA script to infect you))---------------------------------------------------------------------------------------------------8.) I also use a LinkSys/CISCO BEFSX41 "NAT" true firewalling CISCO technology-based router (with cookie & scripting filtering built-in @ the hardware level), these are excellent investments for security.---------------------------------------------------------------------------------------------------9.) USE Tons of security & speed oriented registry hacks (reconfiging the OS basically - stuff like you might do in etc / conf in UNIX/LINUX I suppose)Download them from here @ SOFTPEDIA (where they are rated 4/5):http://www.softpedia.com/get/Tweak/System-...up-Guides.shtmlOR, just email me here for them -> [removed](The email option's the best, because I also have these PREBUILT, in .reg files, mind you, available by email, BUT, the ones I can mail ARE FULLY INTERNALLY DOCUMENTED!)They are FULLY documented internally, with link url's to the Microsoft pages they came from, inside the .reg files, so YOU can look at what the hack does inside them, verify this @ MS, & know what the valid parameters are as well!(This? It took me FOREVER a year or so ago to do this, but worth it!)The urls, or downloadable .mht files, outline it all (as do my prebuilt .reg files, probably the BEST choice of the lot imo), as to what you can ".reg file hack" for better SPEED, and SECURITY online, in a modern Windows 2000/XP/Server 2003 OS & has references from Microsoft in it for each setting plus their definitions & parameters possible!---------------------------------------------------------------------------------------------------10.) The use of a CUSTOM ADBANNER BLOCKING HOSTS FILE (my personal one houses, as of this date, 90,000 known adbanner servers, OR sites known to bear malicious code & exploits (per GOOGLE mostly, from stopbadware.org))Custom HOSTS files work in combination with Opera adbanner blocks & the usage of .PAC filering files + cascading style sheets for this purpose.(As well as speeding up access to sites I often access - doing this, acting as my own "DNS Server" more or less, is orders of magnitude faster than calling out to my ISP/BSP DNS servers, waiting out a roundtrip return URL-> IP Address resolution. It may take some maintenance for this @ times, especially if sites change HOSTING PROVIDERS, but this is a rarity & most sites TELL YOU when they do this as well, so you can make fast edits, as needed (and, on Windows NT-based OS since 2000/XP/Server 2003 & VISTA? A reboot is NOT required upon edits & commits of changes in the new largely near fully PnP IP stacks!))For a copy of mine, write me, here -> [removed]And, I will send it to you in .zip or .rar format (with sped up sites # UNIX comment symbol disabled, enable the ones you use AFTER you 'ping' them first from my list, & add ones YOU PERSONALLY USE to it as needed after determining their IP address via a PING of them)OR, JUST DOWNLOAD IT HERE:http://forums1.techpowerup.com/attachment....mp;d=1172567412An example of WHY you'd want to use one of these for security's sake? Read here:http://forums.techpowerup.com/showthread.php?t=25937---------------------------------------------------------------------------------------------------11.) KEEP UP ON PATCHES FROM MICROSOFT, for your OS & Microsoft Office Apps, & IE, etc., HERE (ordered by release date) and run AntiVirus/AntiSpyware/AntiRootkit tools (& yes, keep them updated/current)!http://www.microsoft.com/downloads/Browse....rder=descendingAgain, keep up on antivirus/antispyware/antirootkit AND Java runtimes updates!(Done either automatically via their services, or manually)Download them manually & install them yourself (OR just let "Windows Automatic Updates" run)ALSO - do the use of the "std. security stuff", like:AntiVirus Programs (NOD32 latest 2.7x - best one there is, & that is not only MY opinion after testing it vs. my former fav. NAV Corporate 10.2 (it is lighter in RAM & resource uses than NAV Corporate even, finds more virus' than others, & uses less "moving parts" (in the way of services componentry, than most do, & certainly less than NAV))Proof? See here -> http://www.eset.com/products/compare.php+ SpyBot (Ad-Aware is another option) as my resident antispyware tool running in the background!This tool in SPYBOT also installs & runs PERFECTLY in safemode (combined with ComboFix &/or SmitfraudFix, you can "burn out" just about ANY spyware/malware infestation in 30-60 minutes, depending on level of infection, speed of your disks/CPU/RAM, & amount of files on your disks - A good antivirus (See NOD32 above, best there is on speed/efficiency, resource consumption, & accuracy) alongside it plus vendor specialized "removal tools" is all a body needs (mostly) when infected.AntiRootkit tools are another one to be conscious of nowadays, now that such machinations are available for Windows (they originated, afaik, in the UNIX world though). The "best ones" (AntiRootkit scanners) & their download URL links are:AVG AntiRootkitBitDefender AntiRootkitGMERRootkit RevealerPrevX AntiRootkitRootkit Hook AnalyzerSophos AntiRootkitF-Secure BlacklightGromozon Rootkit Removal ToolKListerMcAfee Rootkit DetectivePatchFinderRogueRemoverVICESystem Virginity Verifier for Windows 2000/XP/2003That is a list for you all to choose from, look them up on GOOGLE to download them from their homepages, as they all do a decent enough job though, & are 100% FREE - SO, DO use them!---------------------------------------------------------------------------------------------------12.) It is also possible, for webbrowsers &/or email clients, to create a "VISTA LIKE IE 7 Protected Mode"-like type scenario, isolating them into their own spaces in memory, here are 2 methods, how (not needed on VISTA though, afaik):IE6/7 & FF + OPERA AS WELL (as noted by A/C slashdot poster in reply to my methods, both his & my own work well, & are listed here @ /. (slashdot)) on modern NT-based OS "how-to":http://it.slashdot.org/comments.pl?sid=236...mp;cid=19310513MY METHOD for RUNNING IE in a "runas limited user class" sandbox effect:"It is actually possible to run IE securely: just create a throwaway restricted user account for IE use alone. The restricted account user can't install software and can't access files of other users, so even if IE autoexecutes any nastiness, it can't do any damage.Of course, it's a hassle to log in as a different user just to browse the web. So we'd want to use "runas" to run just IE as a different user.Unfortunately, MS has made running IE as a different user a little harder than necessary. Rightclicking and using "Run as" doesn't seem to work. What did work for me was the following.Say the limited account is called "IEuser". Then create a shortcut to "runas /user:IEuser cmd". on your desktop. Double-clicking this will open a command prompt that runs as IEuser. Now you can manually start IE with "start iexplore". Or create a batchfile c:windowsie.bat that just contains the line "start iexplore" and you can start IE by just typing "ie". Remove all shortcuts to IE from you normal desktop and only run it from the restricted account. This way you can use IE without worry about any IE exploits"OTHER, VERY QUITE POSSIBLY SUPERIOR METHOD: http://theinvisiblethings.blogspot.com/200...-every-day.htmlSee section: Do-It-Yourself: Implementing Privilege Separation. Using the psexec tool as described results in a "clean" process tree where iexplore.exe will show up directly under the root avoiding beeing a child process.Note - The "invisible thing"? She's "Yuriko DeathStrike" as far as I am concerned... Joanna Rutkowska, my fellow "Polish Person" & she's a regular "wonder" in the security/hacking/cracking world!This is my runopera.bat which runs opera as user internet:psexec.exe -d -u internet -p p4ssw0rd "cmd" "/d /D /c start /b Opera.exe"PLUS, Windows Server 2003 has a hardened IE6/7 by default (which can be duplicated on other Win32 OS versions, because it mainly just does what I have been doing for a long time & noted by myself earlier, in stuff like turning off ActiveX & scripting + JAVA online on the public internet, of all types by default, & I do this in ALL of my browsers (IE, FF, & Opera) & only make exceptions for CERTAIN sites)A USER SUGGESTED ADDON TO AUTOMATE THIS STUFF ON ISOLATION OF IE: (Per "OILY 17" (TPU forums user) suggestion, to aid in automating this (a tool)):http://forums1.techpowerup.com/showthread....0284#post500284"For running IE,Firefox etc as a throw away account has anyone tried this app out yet.Recently came across it, but have not tried it out yet.Anyone any views?http://www.sandboxie.com/As the name suggests runs IE etc in a sand box effect."Thanks oily (apk)============================================================================AN IMPORTANT POINT:STOP JAVASCRIPT USAGE IN YOUR BROWSERS (along with ActiveX & JAVA) On the PUBLIC internet, PERIOD!Why? Well, read on:Fact is, that today? Well... Javascript's dangerous & can be used AGAINST you, as well as help you... it truly is, or can be, a 'double-edged sword'...(For example - if you follow security related news, you will see that JavaScript is the key avenue being used against you in today's attacks (even thru adbanners!)). Some examples:http://www.wired.com/techbiz/media/news/2007/11/doubleclick&http://apcmag.com/5382/microsoft_apologise...re_to_customersIf you MUST use Javascript (for instance, on a particular site like banking or shopping oriented ones)?Try "NoScript" (the .xpi addon for FireFox/Mozilla/NetScape 9 etc.) & let it let YOU decide sites to use it on, & then DISABLE JAVA/JAVASCRIPT globally...(& if you use IE, trying to do the same can be a nightmare (as IE will "nag you to death" if you turn off javascript on sites that use it)).Opera has similar functionality, ALBEIT, built into it by default as a NATIVE tool!I.E.-> The ability to GLOBALLY block scripting tools like Javascript, BUT... to also allow it for sites you MUST use it on as exceptions to the GLOBAL rule set in Tools, Preferences menus it has on its menubar.Opera has the NATIVE BUILT IN ABILITY to allow you to use it on sites you visit IF you must, via rightclicks on the page & "EDIT SITE PREFERENCES" popup menu submenu item that appears.Either way? It works, & I STRONGLY recommend this. I also recommend Opera for these reasons (less security holes period, & the 1 it had yesterday? Patched yesterday too... fast!)=====SECUNIA DATA ON BROWSER SECURITY (dated 11/20/2007):=====Opera 9.24 security advisories @ SECUNIA (0% unpatched):http://secunia.com/product/10615/?task=advisories----Netscape 9.0.0.3 (0% unpatched)http://secunia.com/product/14690/----FireFox 2.0.0.9 security advisories @ SECUNIA (29% unpatched):http://secunia.com/product/12434/----IE 7 (latest cumulative update from MS) security advisories @ SECUNIA (37% unpatched):http://secunia.com/product/12366/----Those %'s are the latest for FireFox 2.0.0.9, Netscape 9.0.0.3, IE7 after last "patch Tuesday" from MS with the "CUMULATIVE IE UPDATES" they have (see the security downloads URL I post in the 12 steps above to secure yourself), & Opera 9.24... all latest/greatest models.So, as you can see?Well, NOT ONLY IS OPERA MORE SECURE/BEARING LESS SECURITY VULNERABILITIES? It's faster too, on just about ANYTHING a browser does, & is probably the MOST standards compliant browser under the sun (not counting HTML dev tools). This is borne out in these tests:http://www.howtocreate.co.uk/browserSpeed.htmlAND, yes others (most recently in Javascript parsing speeds, oddly enough, lol... given the topic of my post here that is), right here:http://nontroppo.org/timer/kestrel_tests/Opera's just more std.'s compliant, faster, & more secure than the others... so, "where do you want to go today?"...ALSO - HOW TO SET THE "KILL BIT" ON ACTIVEX CONTROLS:(I.E.-> This is how to stop an ActiveX control from running in Internet Explorer)http://support.microsoft.com/kb/240797In case you have "problematic" or security vulnerable ActiveX controls, per this RealPlayer example thereof:http://service.real.com/realplayer/securit...1007_player/en/apk Quote Link to comment Share on other sites More sharing options...
APK Posted November 22, 2007 Author Report Share Posted November 22, 2007 For reader's reference (as to my reported CIS TOOL scores):http://forums.techpowerup.com//attachment....mp;d=1192208359OR, if that doesn't work for you? Try this:http://forums1.techpowerup.com//attachment...mp;d=1192208359 Quote Link to comment Share on other sites More sharing options...
ɹəuəllıʍ ʇɐb Posted November 23, 2007 Report Share Posted November 23, 2007 Wow! Quote Link to comment Share on other sites More sharing options...
APK Posted November 23, 2007 Author Report Share Posted November 23, 2007 Wow! LOL! Well, I hope you find it useful, especially in today's online virus/spyware/trojan/malware (& imo, soon to be rootkit) infested online world... especially for Win32 users.APK Quote Link to comment Share on other sites More sharing options...
Irene Posted November 23, 2007 Report Share Posted November 23, 2007 APK, that must be the most sizeable post of the century!! :D Congratulations!! Quote Link to comment Share on other sites More sharing options...
andsome Posted November 23, 2007 Report Share Posted November 23, 2007 The forum is full. :D Quote Link to comment Share on other sites More sharing options...
APK Posted November 24, 2007 Author Report Share Posted November 24, 2007 APK, that must be the most sizeable post of the century!! :D Congratulations!!LOL! Yes, it's big. No avoiding that.(See, I've been popping its content together since 1996, & in early 1997, it became part of "Article #1" over @ NTCompatible.com when it first started, & was there until 2004. This is an outgrowth of it basically, albeit this post's HEAVILY geared to showing folks how to secure themselves, as much as possible, because of today's online threats... mainly virus/spyware/trojans/malwares in general.)I hope you all get to try & use its suggestions: They just work.APKP.S.=> I am placing it on forums that deal in Microsoft Windows NT-based systems, & all over the wire this week. I do so because each day on the job, I have to bail out clients that infect themselves with infestations like those, & it is pretty ludicrous I have to imo. Microsoft DID help, for example, Windows XP via SP #2 a great deal in this capacity, but still, even THAT patch needs somw work ontop of its reconfiguration of the OS. How? Well, via a handful of IT tips/tricks/techniques you can apply, as shown above, with a pinch of "common sense" (as to email, file downloads, & etc. et al) can prevent you from getting bushwhacked like that, so I figured "why not - put it out, so everyone gains by it" & especially today in the online world that's riddled with these kinds of threats... & using the CIS Tool as your "benchmark test" of your security as I note using it above? Makes it 1/2-way FUN even, in a nerdy/geeky/techie kind of way, almost like a game! apk Quote Link to comment Share on other sites More sharing options...
APK Posted January 9, 2008 Author Report Share Posted January 9, 2008 Something VERY cool, as regards online security, that I stumbled onto during my meanderings online today!(A fairly big day in security news imo @ least on a number of grounds, not just with it being "MS Patch Tuesday" *big patch today too imo, from MS*, on Tcpip.sys & lsass.exe, but in terms of security breaches etc. & all this week on application exploits (FireFox REALMS spoofing bug & more), but this one in particular is one that ought to be part of this post, so... here goes):Read on, past this part, this is just crediting the slashdotter who turned me onto the REAL TREAT in this thread, later, that will definitely help you with layered security online by ALL means, & not just HOSTS files, but better DNS servers (like OpenDNS, great stuff, BUT... A NEW ONE (for me @ least) with an ADDED security 'twist'):----MASS HACK INFESTS THOUSANDS OF SITES:http://it.slashdot.org/comments.pl?sid=409...mp;cid=21953040It's one done by a combination of Javascript (like usual the past few years now), & SQL Injection (concatenated statements inserted into DB columns because the coders on the front end didn't "scrub/sanitize" the outputs from it, usual cause)...----Well, if you read the above in the "12 steps to securing your Windows NT-based OS" above?Then, you know my thoughts on HOSTS files being used to protect you!(AND, using a modified/custom HOSTS file to speed you up online via making access to fav. sites of yours faster by not having to query DNS servers even IF YOU WISH... PLUS blocking out potentially malicious adbanners which we ALL have heard tons about lately, caused by Javascript, bum ActiveX controls, &/or Java even being misused)Anyhow, the URL? That is largely what that link above is about from TODAY (date of this post)Also then you know my thoughts & reasons on points also, like limiting Javascript in browsers!Opera's the best (& fastest + safest browser there is) @ doing THIS also, imo, by natively allowing you to first GLOBALLY block Javascript's use on MOST ALL sites to protect yourself against threats like the above, or others more geared to "home users" etc. et al even...(ONLY allowing it on sites that demand it... thus, limiting your "attack surface area" only to those websites you use, that demand you use Javascript, because you need it on them FOR REAL, not just "glitzy features" but for database access/queries return recordsets & updates/inserts etc. et al, on sites like banking &/or shopping ones for example).ANYHOW/ANYWAYS:Well, from that thread, I got another "layer of security" (and, for parents WITH KIDS? An excellent "AntiPr0n" shield that works too with EASE, because of the DNS servers being used)...ScrubItDNS:http://www.scrubit.com:)* GREAT IDEA, & it WORKS, painlessly... AND F A S T, too!APKP.S.=> Take a read of what it does, how EASY it is to implement (lol, they even give a GUI to do the job for you, because digging into your network connection MIGHT be a "bit much" for some folks, to make it easy for anyone really... 2 clicks!) & YOU DECIDE... I have tried it, & it DOES work, by filtering off sites thru it that are 'dangerous' OR 'offensive' (like ones you might find that are involved with the above exploit, or others like GOOGLE + SPYBOT Search & Destroy help you with) - PLUS, Pr0n sites (some of you, lol, may NOT like that "feature" though). Still, bottom-line - For layered security? This is a GOOD idea, this "scrubit" DNS server... imo, so far @ least... apk Quote Link to comment Share on other sites More sharing options...
APK Posted January 13, 2008 Author Report Share Posted January 13, 2008 http://img297.imageshack.us/img297/2240/52041100vo6.pngThat's an example of where your score (for users on Windows XP SP #2 no less fully hotfix patched as of this date) can be @ scoring-wise, on the CIS Tool benchmark test gauge of Windows Security, after following its suggestions for security-hardening your systems.A 90.112 score... & that was AlexStarFire's score from the 3dguru.com forums, once he applied it to his home system ("stand-alone", non-HOME or WORK-LAN system, online on the public internet), which is way, Way, WAY up from its initial default score of 46.xxx/100...:)* Here is an example of a user named Thronka, who employed it to security-harden the endpoints on his LAN/WAN setup @ work, who is also enjoying it successfully as well, albeit this time, in a BUSINESS environs (as I have it as well, for both HOME standalone machine online today, & also on the job):http://www.xtremepccentral.com/forums/showthread.php?t=28430APKP.S.=> I hope you guys also employ it thus as well - it starts with reaching just 1 person, & then, by example? Others start to apply it also, & then things start to change "for the better", because by securing yourself, & maybe even setting up your pals & families machines' this way? You lessen the possibility of "spreading the diseases" out there online today... apk Quote Link to comment Share on other sites More sharing options...
APK Posted January 15, 2008 Author Report Share Posted January 15, 2008 ONE THING THAT I HAVE TO NOTE, THAT IS RATHER IMPORTANT:Using an external DNS server (like OpenDNS &/or ScrubIT DNS, which I mention last page - but, omitted this little critical factoid) in a business settings that utilizes Active Directory, is NOT a good idea:SURE, ones like OpenDNS & ScrubIT DNS are excellent, fast, & more secured than std. ones your typical ISP/BSP gives you, no doubt... HOWEVER:There IS a catch-22, because they won't FULLY "mesh" with your internal LAN AD (active directory) setup, mainly since because AD is SO DNS dependent, it's not funny.Makes sense though - & I omitted this in my earlier posts about ScrubIT DNS in fact:I mean, how on EARTH could an external DNS server be able to serve up IP addresses that are privatized behind a router & a subnet (unless LMHOSTS could work around it, that is)... Systems under your LAN/WAN subnet with privatized non-internet broadcastable IP Addresses especially, like 169.254 (not that you'd usually see THAT, lol), 10.x.x.x, 172.x.x.x, & 192.168.1.xxx DHCP assgined ones... so, be wary of using them with LANS/WANS.SO, anyone with a LAN/WAN (be it HOME, or BUSINESS)? Beware of using OpenDNS or ScrubIT DNS servers, even though I "extolled their virtues" on the pages preceeding this one.OpenDNS &/or ScrubIT DNS are GREAT for home users that have "stand-alone" (meaning not networked to other computers' drives + printers, etc. et al) setups, that are hooked up to the internet... they WILL "mess some stuff up" in ActiveDirectory/AD networks though.Found that out myself in the past: For example - Things like Outlook (FULL) when setup to hitch up with EXCHANCE SERVER (instead of a POP or IMAP or even HTML mail account) will "flake out" for instance, IF you use external 3rd party DNS servers that are external to your network (LAN/WAN & home OR business).:)* Sorry about that, I will have to edit that post for this too...APK Quote Link to comment Share on other sites More sharing options...
AlanHo Posted January 15, 2008 Report Share Posted January 15, 2008 My head hurts..... Quote Link to comment Share on other sites More sharing options...
andsome Posted January 15, 2008 Report Share Posted January 15, 2008 I've used up all my paracetamol. :lol: Quote Link to comment Share on other sites More sharing options...
APK Posted January 16, 2008 Author Report Share Posted January 16, 2008 My head hurts..... LOL, sorry about that man... I admit - the material IS fairly "complex"!I tried to "ease some of that", by using a LOT of detail!(HOWEVER, with that, comes some "bloat" in the post thread material I put out too)I did the detail I used, ALL so folks do NOT have a "tough time" due to some critical missing piece of info. during the steps here... & DO TAKE THOSE, 1 STEP @ a time, in those steps above, & do NOT let the length of it, intimidate you (yes, I too, know that feeling)... See - I used to feel THE SAME AS YOU DO, when I first began professionally writing code (huge multi-million line projects stuff) & tracing the code others had written beforehand to maintenance & update/upgrade it - it's DAUNTING, IF you look @ it, "ALL @ ONCE"... go 1 line @ a time!"Every long journey, begins with a SINGLE step" & all that...Above all? HAVE fun!(CIS Tool also helps here - it is * almost * like playing a game, OR, using a performance testing benchmark (think 3dMark etc.)... except, this one is about SECURITY, based on BEST PRACTICES from this field + it got GOOD solid reviews of its purpose & efficacy from COMPUTERWORLD no less & other sites + publications online & in the "real world" too)* CIS Tool practically WALKS you thru it, & gives you suggestions on WHAT you need to fix up for better security!(My post's material extolls other things it does NOT cover, & also tools/techniques to do what CIS requests too...)ALL, to help you, HELP YOURSELF, mainly.CIS Tool gives you points you are weak on, & 9/10 times, methods to change them to the more secure settings & why too as well.APK Quote Link to comment Share on other sites More sharing options...
Seshomaru Samma Posted March 4, 2008 Report Share Posted March 4, 2008 This Guide is excellent!thank you very muchCan it be moved to the "essential guides" section? Quote Link to comment Share on other sites More sharing options...
APK Posted March 4, 2008 Author Report Share Posted March 4, 2008 This Guide is excellent!Thank you, "we try/aim to please" & all that stuff... Professionally/on the job each day, & for years now, I have to clean out folks' systems each day of virus/spyware/trojans/malware!(Even rootkits on occasion, but, only the bootsector originated type really (only type of rootkit I KNOW how to destroy, the rest? REPAVE (redo system usually))) The problem of infection/infestation by such machinations has truly gotten SO outrageous out there nowadays, with folks being infected/infested, I tried to do something about it!(On the New Year this year in fact, as my "new year's resolution" to try to help others when I can, & I did so across 25 forums or so, same guide as this exists)...Hopefully, more folks like yourself can be reached via its guidance AND THE EXCELLENT CIS Tool's guidance as well.It does work, & DOES make a heck of a difference... the person whom I tested it on is a security guard by trade, NOT a "computer guru" etc. et al, & he used to turn up 200-300 viruses & spyware EACH WEEK... now, his having applied this guide's points & rules (such as no javascript/activeX/java online etc.)?He has ONLY turned up 1 in the last 6-7 months now, & THAT was due to his turning on IFRAMES & JAVASCRIPT to do YouTube...thank you very muchThank you, & likewise, for your commentary here!Can it be moved to the "essential guides" section?That is up to the moderation staff here, not myself, but a decent idea (if I do say so myself, lol, but... I am a WEE bit biased of course)...APK Quote Link to comment Share on other sites More sharing options...
APK Posted May 1, 2008 Author Report Share Posted May 1, 2008 More security tools/info. (04/28/2008), for APPLICATION LEVEL SECURITY:(I.E.-> For checking for apps you have that may be security vulnerable OR have been patched vs. said vulnerabilities, etc.):----SECUNIA PSI (checks for outdated OR apps that are known to be insecure):https://psi.secunia.com/NEW VERSION (released very recently too).A good program, by a trusted & WELL-KNOWN security-oriented website online (I tried version 1 earlier on last year, it needed work. This one is solid though, so far @ least, imo!)(It works, & sometimes catches things FILEHIPPO UPDATE CHECKER below, won't - good "2nd Doctor's opinion" etc.)----FileHippo's Update Checker (checks for outdated OR apps that are known to be insecure, supplement's PSI above):http://filehippo.com/updatechecker/Decent program as well, & good to use as a supplement to the SECUNIA PSI Tool as well (from a well-known file downloads site also in filehippo).(It works, & sometimes catches things SECUNIA PSI above, won't - good "2nd Doctor's opinion" etc.)----Windows Vulnerability Scanner:http://www.pspl.com/download/winvulscan.htmNice program for checking Microsoft Operating Systems &/or Ms-Office versions vs. missing security patches, & it works, very well!----APK Registry Cleaning Engine 2002++ SR-7:http://www1.techpowerup.com//downloads/389...ooglehappy.html:)* Yes, "shameless plug" on MY part on the last one, but, it does have "security benefits"...(& more than potentially useful forensics ones, because it shows you what files a user calls upon via its lists (it does check recently used filelists, but, will also list those files the user attempted to delete (this assumes he may have been attempting to hide them)))... it is 100% proven SAFE on all 32-bit versions of Windows (see its description & feedback by users on the download page) 9x-VISTA as well)).APK Quote Link to comment Share on other sites More sharing options...
APK Posted May 1, 2008 Author Report Share Posted May 1, 2008 MORE APPLICATIONS LEVEL SECURITY TIPS...For users of Adobe Reader:Since it has been attacked so much recently (via its ability to place javascripting into its .pdf document format, & javascript that bears "ill will" no less)? Well, update to the latest/greatest version... HOWEVER, if you don't trust that, as I do not, FULLY? (Simply because browser makers have been trying that left & right since "time immemorial" online, & more of those types of attacks pop up of differing nature that evades new patches vs. it, keep popping up regardless of the patches!) Plus, like I had stated earlier in this guide? I suggested turning off using javascript for EVERY SITE online, in your webbrowser (& only keep it for ones that demand it (or, become useless w/out it, like many shopping &/or banking sites - this lessens the possibility of being poisoned by bad adbanner OR site code & also lessens the attack surface area + limits the possibles to the sites you left javascript on for, ONLY))?? Try this: TURN OFF JAVASCRIPT USAGE IN ADOBE ACROBAT READER to be safe vs. attacks in it that are javascript-based in nature! EDIT menu PREFERENCES submenu Javascript section (in left-hand side column of options), & uncheck "Enable Acrobat Javascript" in the right-hand side option for that. APK P.S.=> That assures you are "proofed" vs. Adobe Acrobat malware/bad javascript containing contaminated .pdf documents via bogus javascript in them... The only "hassle" w/ this is that Adobe Acrobat Reader (like IE does) will "nag" each time it hits a script tag, telling you to 'turn on javascript" (I wish they'd amend it NOT to do that), but, this is the price paid for security (minor, but, still there & imo, due to POOR application design as regards useability)... apk Quote Link to comment Share on other sites More sharing options...
Dencandy Posted May 1, 2008 Report Share Posted May 1, 2008 It seems it's about time Adobe and Java and others gave us the choice of allowing scripts on this occasion only (as even IE7 does) rather than the simple global choice of Yes or No for all occasions. Especially as most people, especially those who know least, are going to continue with IE for the foreseeable future. Thanks for all the hard work, APK. Quote Link to comment Share on other sites More sharing options...
APK Posted May 1, 2008 Author Report Share Posted May 1, 2008 Thanks for all the hard work, APK. You're welcome, & I hope you tried CIS Tool & its suggestions, PLUS the ones I layer ontop of those.It's some work on YOUR part (or, anyone else that tries this posts' points)... but, it's necessary, imo @ least: E.G.-> I have seen literally 1,000's of systems this year alone on the job/professionally, that have been compromised from home/end user systems up to entire corporate networks compromised thus by virus/spyware/trojans/malware, etc. & it's largely due to the default security setups that BOTH Windows & Linux (yes, even MacOS X) give you. The CIS Tool merely quantifies & validates my statement of that, as fact. I had to clean them up, sometimes w/ systems numbering LITERALLY into the 1,000's of viruses/spywares on a single machine no less... pretty scary imo!(PLUS - It's actually sad to see imo... but, there IS something a body can do about it, for around 1-3 hrs. of your time downloading, installing, & running CIS Tool + applying its points & suggestions to secure yourself... &, it's worth it!)I.E./E.G.-> I have been running this system here setup on Windows Server 2003 since mid 2005, "110% bulletproof & bugfree", via CIS Tool & the other suggestions/tips/tricks/techniques noted above, & obviously, they work (yes, I know, I am NOT the "end all/be all statistical sampleset" but, I try to back this result of mine via common-sense & documented facts + tools noted in this thread).It just works (w/ a small dose of "common-sense" & saavy which you acquire over time online of course, sometimes, via a "punch in the head" type of lesson, such as virus OR spyware infestations, & I'd like to help folks avoid THAT!).I would like to thank folks from SECURITYFOCUS.COM, SECUNIA.COM, PACKETSTORM.COM, Spybot, & a Mr. Dancho Danchev for their fine websites &/or blogs + softwares... they've been a HUGE help to myself (mainly in the construction of a protecting HOSTS file which I mentioned here).It seems it's about time Adobe and Java and others gave us the choice of allowing scripts on this occasion only (as even IE7 does) rather than the simple global choice of Yes or No for all occasions. Especially as most people, especially those who know least, are going to continue with IE for the foreseeable future. No doubt... but, again, I do NOT like how it can "nag you" everytime it hits a script tag in the .pdf files... this still needs work imo, but, better than nothing!APKP.S.=> Thanks for your reply, enjoy this post, & DO try CIS Tool... apk Quote Link to comment Share on other sites More sharing options...
Scarecrow Man Posted May 1, 2008 Report Share Posted May 1, 2008 Moved to guides section.I suggest reading this topic over a few days as it may be a bit much information to take in all at once. :lol: Quote Link to comment Share on other sites More sharing options...
APK Posted May 2, 2008 Author Report Share Posted May 2, 2008 This Guide is excellent!thank you very muchCan it be moved to the "essential guides" section?Well, it appears you "got your wish"... as 'Scarecrow Man' did as you had requested!:)* Pretty Cool, imo @ least, as the post thread starter & all that...APKP.S.=> I consider it an honor, & this is about the 5th or 6th forums (of the 20 or so forums this very same thread content appears on, verbatim) this has happened, so it must be "doing the job/working" alright for folks, which IS, what it IS all about (my "New Year's Resolution" was "DO A GOOD DEED" & it appears thusfar, I have & folks dig this post's content, which is GOOD)... I am happy about this, & thanks mods/admins, AND USERS who requested this like Seshomaru Samma above... again, thanks, & get those 90++ scores on CIS Tool folks! apk Quote Link to comment Share on other sites More sharing options...
APK Posted May 2, 2008 Author Report Share Posted May 2, 2008 Gentlemen, On the last page of this post, I had mentioned Mr. Dancho Danchev (& other sites here earlier which I noted I wanted to post a "thank-you" to, & why (custom HOSTS file construction for added speed & security)).(BOTH better speed AND better security are VERY possibly obtained (you WILL notice it, guaranteed) by using HOSTS files THAT way)I am going to "rehash" a bit of last page's point #10 first, as a review.First, speed (how to gain it via HOSTS files usage):You get that, simply by acting as your OWN DNS SERVER since you no longer have to call out to your DNS from your ISP/BSP, & even IF their DNS server goes down (or, gets "DNS poisoned" which does happen) you will STILL be able to get to your sites you list in it (bonus)!Now - some folks like webmasters (& certainly advertisers who serve up adbanners won't) may not like this, in the blocking of adbanners, but, it is a PROVEN way to get more speed online, GUARANTEED, since you won't load adbanners data & be calling out to their servers too, saving TONS of online time used for that PLUS CPU cycles (especially in the case of Javascript driven ones)... The past year or two alone has shown TONS of adbanners being "hiijacked" or bearing malicious code too... hence, the reason to "BLOCK OUT" adbanners servers... for speed, definitely & universally that much results, BUT, for security too (but, note - not ALL adbanners are "bad")(HOSTS files are excellent for both speed & security... the one I post here (very old one of mine I put up as an example or starter version folks can try) works, & that shows you how to do the speedup part, inside of itself since I documented the heck out of it with examples for that) YOU FOLKS MAY WISH TO DOWNLOAD THE OLDER EXAMPLE HOSTS FILE I POSTED @ TECHPOWERUP.COM, as a guide you can look @, & read its interior documentation for, as it will help on both counts... but, since it is older? I am going to show you folks WHERE to get more current protection basically. Hence, why I mention NRI & Mr. Danchev's blog (I use it myself)(I even wrote the guy today to thank him no less via email)----HOWEVER, finally getting back on track now?FOR SECURITY:Mr. Danchev also nearly DAILY posts sites (obtained from reputable sources like NRI for example) that are involved with online gangs such as the "RBN"/Russian Business Network & ones like they too).So - That all said & aside? I am now going to add some information in my next posts after this one, that SHOULD assist those of you interested in the usage of CUSTOM HOSTS FILES for not only speeding up your internet access, but more for PROTECTING YOURSELVES ONLINE, especially today, since adbanners have been rampantly abused this way & even MICROSOFT GOT SUCKERED BY SUCH AN ATTACK & ISSUED AN APOLOGY FOR IT (it was NOT their fault really)... so, if you downloaded the example file from point #10 on last page? It can be added to easily, with the lists I am going to paste in successive posts after this one, so you can add them to YOUR custom HOSTS file, for both added online speed AND security.APKP.S.=> Between such a HOSTS file, & limiting the usage of javascript &/or IFrames in your webbrowsers (Opera IS best @ this, FireFox is next via the NoScript addon) from attacks by sites involved with, OR, "poisoned by", online criminal gangs such as the "RBN" (look them up online in GOOGLE if you are curious, they are WIDELY known, especially the past year or two, for rather "nefarious activities" online))? You will definitely be faster (almost an "HBO Internet" with NO COMMERCIALS) AND SAFER online!REVIEW of point #10 "basics" from the last page, on this page now for your referenceA HOSTS file is easy to mend/edit via notepad.exe, & is typically located here:%windir%\system32\drivers\etcIF IT IS NOT THERE (& you should check this anyway, because a virus called QHosts redirects it to a bogus one & I am certain other virus/trojans/spywares do as well)? Check it using regedit.exe, by going here:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters& being SURE it is where you have yours. I redirect mine intentionally, but that is another issue as to why (I use a Solid State Ramdisk, & load mine from there for added system startup speed, since their access/seek is 1000's of times faster than std. HDD's, even 10-15k rpm ones)Anyhow - HOSTS file has 1 single "mandatory" (only if you are on or use a LAN/WAN network @ home OR on the job, otherwise you can technically do without it) entry, & that is this:127.0.0.1 localhost& that is about ALL Ms gives you (they took it from the BSD UNIX world by the by, this is NOT original by MS... nor, is their Tcp/IP stack, again, taken from BSD (widely accepted as the "best in the business" @ things IP, but, that's purely relative)... we're going to show you all how to use one, & where to get GOOD solid info. daily for securing yourself (more than speeding yourself up using them, which my example one in point #10 on the 1st page has already in it, fully documented for your use in THAT capacity), by blocking out malicious sites... For those of you that use SPYBOT "search & detroy" for example (excellent antispyware program)? You already KNOW it fortifies you this way... but, it does NOT catch all the bad sites & only updates every so often... Mr. Danchev's site & his sources can help YOU stay ontop of it, even more currently... here goes! apk Quote Link to comment Share on other sites More sharing options...
APK Posted May 2, 2008 Author Report Share Posted May 2, 2008 USING NOTEPAD.EXEADD THIS LIST TO YOUR CUSTOM HOSTS FILE (usually located in %windir%\system32\drivers\etc subfolder-subdirectory):# === START OF KNOWN RUSSIAN BUSINESS NETWORK/RBN MAPPINGS + AFFILIATED KNOWN SERVERS ===0.0.0.0 rxpharmacy-support.com0.0.0.0 ns3.cnmsn.com0.0.0.0 thecanadianmeds.com0.0.0.0 officialmedicines.com0.0.0.0 psxshop.com0.0.0.0 10000xing.cn0.0.0.0 222360.com0.0.0.0 adslooks.info0.0.0.0 bnably.com0.0.0.0 eqcorn.com0.0.0.0 familypostcards2008.com0.0.0.0 freshcards2008.com0.0.0.0 happy2008toyou.com0.0.0.0 happysantacards.com0.0.0.0 hellosanta2008.com0.0.0.0 hohoho2008.com0.0.0.0 kqfloat.com0.0.0.0 ltbrew.com0.0.0.0 mymetavids.com0.0.0.0 obebos.cn0.0.0.0 parentscards.com0.0.0.0 postcards-2008.com0.0.0.0 ptowl.com0.0.0.0 qavoter.com0.0.0.0 santapcards.com0.0.0.0 santawishes2008.com0.0.0.0 siski.cn0.0.0.0 snbane.com0.0.0.0 snlilac.com0.0.0.0 tibeam.com0.0.0.0 tushove.com0.0.0.0 wxtaste.com0.0.0.0 yxbegan.com0.0.0.0 iframedollars.biz0.0.0.0 NS1.RBNNETWORK.COM0.0.0.0 NS1.4USER.NET0.0.0.0 NS1.EEXHOST.COM0.0.0.0 NS1.AKIMON.COM0.0.0.0 NAME1.AKIMON.COM0.0.0.0 NS2.RBNNETWORK.COM0.0.0.0 NS2.4USER.NET0.0.0.0 NS2.AKIMON.COM0.0.0.0 NS2.EEXHOST.COM0.0.0.0 NAME2.AKIMON.COM0.0.0.0 RUSOUVENIRS.COM0.0.0.0 RBNNETWORK.COM0.0.0.0 NS1.INFOBOX.ORG0.0.0.0 NS2.INFOBOX.ORG0.0.0.0 NS1.RUSOUVENIRS.COM0.0.0.0 NS2.RUSOUVENIRS.COM0.0.0.0 NS1.RUSOUVENIRS.NET0.0.0.0 NS2.RUSOUVENIRS.NET0.0.0.0 SBTTEL.COM0.0.0.0 AKIMON.COM0.0.0.0 AKIMON.NET0.0.0.0 EEXHOST.COM0.0.0.0 NS1.EEXHOST.COM0.0.0.0 NS2.EEXHOST.COM0.0.0.0 NS1.4USER.NET0.0.0.0 NS1.AKIMON.COM0.0.0.0 NS1.EEXHOST.COM0.0.0.0 NAME1.AKIMON.COM0.0.0.0 NS1.RBNNETWORK.COM0.0.0.0 NS2.4USER.NET0.0.0.0 NS2.AKIMON.COM0.0.0.0 NAME2.AKIMON.COM0.0.0.0 NS2.RBNNETWORK.COM0.0.0.0 NS2.EEXHOST.COM0.0.0.0 VALUEDOT.NET0.0.0.0 ns0.valuedot.net0.0.0.0 ns1.valuedot.net0.0.0.0 1000WATT.BIZ0.0.0.0 2SOVKA.NET0.0.0.0 AIDEN-GROUP.COM0.0.0.0 AKIMON.COM0.0.0.0 ALEKC.NET0.0.0.0 ANDREY-STUDIO.INFO0.0.0.0 AUTOKUBAN.INFO0.0.0.0 AVIATRAVELAGENCY.COM0.0.0.0 AVTOMOBILEY.NET0.0.0.0 BAGATITSA.COM0.0.0.0 BAIKERGROUP.COM0.0.0.0 BALTICDOORS.COM0.0.0.0 BALTMONOLIT.COM0.0.0.0 BRIGADA-EL.COM0.0.0.0 CARPRIVOZ.COM0.0.0.0 CHILLERU.COM0.0.0.0 CVETOVODSTVO.COM0.0.0.0 E-GOLD-CHANGER.COM0.0.0.0 ELECTRONOV.NET0.0.0.0 FASHIONER.BIZ0.0.0.0 FFFFFF.ORG0.0.0.0 FIFACUP06.INFO0.0.0.0 FISHTORG.COM0.0.0.0 FKGARANT.COM0.0.0.0 FOTORETUSH.COM0.0.0.0 FREGATSOFT.COM0.0.0.0 FROLROMANOFF.COM0.0.0.0 FULLVER.INFO0.0.0.0 GAKKEL.COM0.0.0.0 GARANTSERVICE.ORG0.0.0.0 GDEDENGI.INFO0.0.0.0 GLAZKI.NET0.0.0.0 GOLD-DRAGON.INFO0.0.0.0 GORODM.COM0.0.0.0 GRAYZI.NET0.0.0.0 GRIFFINFLY.COM0.0.0.0 HEAT-ENERGO.COM0.0.0.0 HITEMA.NET0.0.0.0 HYIPREVIEW.INFO0.0.0.0 HYIPSMAP.COM0.0.0.0 ILOXX.ORG0.0.0.0 IMYA.INFO0.0.0.0 INFODOSKA.COM0.0.0.0 INTERNETWORLDBOOK.COM0.0.0.0 KLIMATA.NET0.0.0.0 KOMOV.NET0.0.0.0 KOSMETICHKA.NET0.0.0.0 LIDTRADE.COM0.0.0.0 LIFE-RU.ORG0.0.0.0 LPSPB.COM0.0.0.0 M-OST.NET0.0.0.0 M-UNLOCK.COM0.0.0.0 MAMRU.COM0.0.0.0 MAPSERV.COM0.0.0.0 MASTERDOKS.COM0.0.0.0 MIRMED.COM0.0.0.0 MOOSEMUSE.COM0.0.0.0 MOREPRODUCT.NET0.0.0.0 MUSEMOOSE.COM0.0.0.0 NESTRONICS.COM0.0.0.0 NESTRONICS.NET0.0.0.0 NOFUN.INFO0.0.0.0 OIL-GAS-MINERALS.COM0.0.0.0 OKOSHKA.NET0.0.0.0 OPTIMUS.BIZ0.0.0.0 OTKRITKI.NET0.0.0.0 OTKRITOK.NET0.0.0.0 PARALLELSIXTY.COM0.0.0.0 PASSOMONTANO.COM0.0.0.0 PETROBALT.NET0.0.0.0 PHARMACY-MD.COM0.0.0.0 PISKUNOV.NET0.0.0.0 POIGRAI.INFO0.0.0.0 PROETCONTRA.ORG0.0.0.0 PSOLAO.ORG0.0.0.0 ROSEL.INFO0.0.0.0 SBTTEL.COM0.0.0.0 SECONDAPPROACH.COM0.0.0.0 SMARTSOFTLINE.COM0.0.0.0 SMESHNOY.COM0.0.0.0 SQUAREDREAM.COM0.0.0.0 STROIINFORM.COM0.0.0.0 STROYBRIGADA.COM0.0.0.0 TANK-HOBBY.COM0.0.0.0 TECHNONORDIC.COM0.0.0.0 TELEUNITED.NET0.0.0.0 TEPLOCOM.COM0.0.0.0 THERMOCAUTERY.COM0.0.0.0 TIARU.COM0.0.0.0 TRADEFINANS.COM0.0.0.0 TRADEFINANS.NET0.0.0.0 TRAININGS-TRIUMPH.ORG0.0.0.0 TSAR-SUVENIR.COM0.0.0.0 UEFACUP08.INFO0.0.0.0 UMNIKSOFT.COM0.0.0.0 UNDERCOOLED.NET0.0.0.0 VALIDBIT.COM0.0.0.0 VERESC.ORG0.0.0.0 VOROLAIN.COM0.0.0.0 WHITENIGHTSHOSTELS.COM0.0.0.0 WORLDFONDS.NET0.0.0.0 XRUST.NET0.0.0.0 YAHOCHU.COM0.0.0.0 Z-GROUP.INFO0.0.0.0 ZDRAV.INFO0.0.0.0 ZHESTOV.NET0.0.0.0 ZOOSPB.COM0.0.0.0 goldenpiginvest.com0.0.0.0 goldenpiginvest.net0.0.0.0 pharmacy-viagra.net# === END OF KNOWN RUSSIAN BUSINESS NETWORK/RBN MAPPINGS + AFFILIATED KNOWN SERVERS ===Also - You can (AND SHOULD) verify your HOSTS file location, because it CAN be moved (& some virus/spywares do so, like QHosts) by using regedit.exe& going here:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters& checking to see it has NOT been misdirected from C:\WINDOWS\SYSTEM32\DRIVERS\etc(Unless you KNOW that YOU move it, as I do!)I move mine INTENTIONALLY to another disk here that is less used & faster on seeks!That is just so it init.'s faster since the HDD is not contending with other programs loading etc.or data loading etc. - mine's on an SSD (solid-state ramdisk, for access-seek gains for example).----FOR FIREWALL BLOCKING RULES (or IE "restricted zones" lists (in IE options), OR possibly IP Security Policies usage):I.P. address block for Russian Business Network:81.95.144.0/20 #SBL43489(81.95.144.0 - 81.95.159.255)And the address blocks for its equally corrupt cousins at Intercage, Inhoster, and Nevacon:85.255.112.0/20 #SBL36702(85.255.112.0 - 85.255.127.255)69.50.160.0/19(69.50.160.0 - 69.50.191.255)194.146.204.0/22 #SBL51152(194.146.204.0 - 194.146.207.255)Lastly/Optionally - You should block all IPs starting with these if you do not care about Russia and China:193.194.195.213.217.62.64.62.76.(AND, A few major Internet providers that provide services to RBN including)Tiscali.ukSBT TelecomAki Mon TelecomNevacon LTDFrame Cash76serviceNoc4HostsAPK Quote Link to comment Share on other sites More sharing options...
APK Posted May 2, 2008 Author Report Share Posted May 2, 2008 So you all know WHY I put up info. on the "RBN" (Russian Business Network) in my last post above? Well, I strongly suspect "they're @ it again" & here is why:Cyber-attack launched from 10,000 web pages:http://itnews.com.au/News/71994,cyberattac...-web-pages.aspx"A single entity is likely to be behind this attack, since the malicious code on all these pages came from the same server in China."(AND, the "RBN" is KNOWN to 'hop between' China & Russia regularly, as needed, & I suspect they are the ones behind this, but the article offers NO discrete IP Address ranges or IP's so, we have to wait on the specifics, but it is a GOOD guess based on their prior track record w/ Zlob, which I see nearly every day @ times on the job)...APKP.S.=> I posted this on other sites that are "severely security-oriented", & I did a little "guesswork" & turned up correct... it WAS the "RBN", @ it again... hence, just reposting it here as verification from a reputable source! apk Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.