Documente Academic
Documente Profesional
Documente Cultură
Module 2
Simplifying Security.
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
MalwareContaminationonWindows7High,WhileforXPLow
May21,2011
InitslatesteditionofSecurityIntelligenceReportthatMicrosoftreleasedonMay12,2011,thecompanyrevealsthatthe
infectionrateonWindows7roseover30%inH22010,whilethatonWindowsXPdroppedover20%.
SaysPrincipalGroupProgramManagerJeffWilliamsforMicrosoftMalwareProtectionCenter,therateofcontaminationon
Windows7increased,that'sbecauseofmoremalwareattacksprevailingincyberspace.Computerworld.compublishedthis
onMay12,2011.
Notably,duringJulyDecember2010,therewasameanrateofmorethan432bitWindows7computersgettinginfected
forevery1,000 suchcomputers,ariseof33%comparedtoabout3suchPCsgettinginfectedforevery1,000duringH1
2010.
http://www.spamfighter.com
2
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
Module Objectives
SystemSecurity
HowtoHideFilesandFolders?
ThreatstoSystemSecurity
WindowsSecurityTools
HowDoesMalwarePropagate?
GuidelinesforSecuringMacOSX
GuidelinesforWindowsOperating
SystemSecurity
ResourcesontheInternetfor
ComputerSecurity
TwoWayFirewallProtectionin
Windows
OperatingSystemSecurity
Checklists
WindowsEncryptingFileSystem(EFS)
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
Module Flow
GuidelinesforSecuring
MacOSX
SystemSecurity
WindowsSecurity
Tools
ThreatstoSystem
Security
WindowsEncrypting
FileSystem(EFS)
HowDoes
MalwarePropagate?
GuidelinesforWindowsOSSecurity
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
System Security
Everyoperating
systemand
applicationis
subjectto
securityflaws
Usershaveto
installthe
patchesand
configurethe
software
Softwarevendors
usuallydevelop
patchestoaddress
theseflaws
System
compromisecan
bepreventedby
applyingsecurity
patchesina
timelymanner
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
Module Flow
GuidelinesforSecuring
MacOSX
SystemSecurity
WindowsSecurity
Tools
ThreatstoSystem
Security
WindowsEncrypting
FileSystem(EFS)
HowDoes
MalwarePropagate?
GuidelinesforWindowsOSSecurity
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
Rootkit
Asetofprogramsor
utilitiesthatallows
someonetomaintain
rootlevelaccesstothe
system
Worm
Aselfreplicatingvirus
thatdoesnotalterfiles
butresidesincomputer
memoryandreplicates
itself
Trojan
Aprogramthatseems
tobelegitimatebutacts
maliciously,when
executed
Backdoor
Anunauthorizedmeanof
accessingthesystemand
bypassingthesecurity
mechanisms
Logic Bomb
Aprogramthatreleasesa
virusoraworm
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
Spyware
SpywareincludesTrojansand
othermalicioussoftwarethat
stealspersonalinformation
fromthesystemwithoutthe
usersknowledge.Example:
Keylogger
PasswordCracking
Passwordcrackingistheprocess
ofidentifyingorrecoveringan
unknownorforgottenpassword
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
Password Cracking
Passwordcrackingistheprocessofidentifying orrecovering anunknownorforgottenpassword
Brute
Forcing
Guessing
Dictionary
Attack
Tryingcombinations
ofallthecharacters
untilthecorrect
passwordis
discovered
Tryingdifferent
passwords until
oneworks
Itusesapre
definedlist of
words
Shoulder
Surfing
Social
Engineering
Watching someone
typethepassword
Tricking peopleto
revealtheirpassword
orotherinformation
thatcanbeusedto
guessthepassword
OriginalConnection
Victim
Attackergetsthe
Sniff
Server
passwordofthevictim
Attacker
10
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
Module Flow
GuidelinesforSecuring
MacOSX
SystemSecurity
WindowsSecurity
Tools
ThreatstoSystem
Security
WindowsEncrypting
FileSystem(EFS)
HowDoes
MalwarePropagate?
GuidelinesforWindowsOSSecurity
11
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
Through USB
Memory Sticks
A virus createan
autorun.inf filethatisa
systemhiddenanda
readonlyfile
Whentheuseropensthe
pendrivefiles,the
autorun.infisexecuted
andcopiesthe virus files
intothesystem
12
Through Infected
Websites
Visitingcompromised
sitesmayresultin
installationof
malicioussoftware,
designedtosteal
personalinformation,
onuserscomputer
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
http://www.sonicwall.com
13
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
ThroughSharedFolders
Malwaremaypropagatevianetwork shares
Themalwarecanspreadbycreating copies ofitselfin
sharedfolders
14
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
ThroughDownloads
Downloadingsoftware,music,photos,andvideosfrom
untrustedwebsites mayalsocausedownloadinga
maliciousfileinfectedwithavirus,worm,Trojan,etc.
Alargenumberofmaliciousapplicationsareavailable
overtheInternetwithadescriptionthatmaytrick
usersintodownloadingthem
15
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
http://www.entertane.com
16
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
Module Flow
GuidelinesforSecuring
MacOSX
SystemSecurity
WindowsSecurity
Tools
ThreatstoSystem
Security
WindowsEncrypting
FileSystem(EFS)
HowDoes
MalwarePropagate?
GuidelinesforWindowsOSSecurity
17
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
ApplySoftwareSecurityPatches
KillUnnecessaryProcesses
CreateStrongUserPassword
UseWindowsFirewall
ConfigureAuditPolicy
DisabletheGuestAccount
UseNTFS
HideFilesandFolders
LockOutUnwantedGuests
UseWindowsEncryptingFile
System
DisableSimpleFileSharing
RenametheAdministrator
Account
EnableBitLocker
UseWindowsUserAccount
Control(UAC)
DisableStartupMenu
DisableUnnecessaryServices
ImplementMalware
Prevention
18
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
Lock
19
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
20
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
21
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
22
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
23
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
Rightclickonuser AdminorAdministrator
selectRename typethenewnamefor
accountandclickOK
24
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
25
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
Windows Updates in
Windows 7
WindowsUpdates
ClickStart Control
Panel select System
andSecurity
SelectWindowsUpdate
ChangeSettings
ChoosehowWindowscan
install updates
26
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
AlwayspatchtheOSand
applications tothelatest
patchlevels
Ensurethatyouare
downloadingpatchesonly
fromauthenticsources
preferablythevendorsite
Donotopenexecutable
filesfromsourcesof
questionableintegrity
Usepatch
managementtoolsfor
easierupdatingthere
areseveralfreetools
Donotsendpatches
throughemail
27
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
SoftwareupdatesareusedtokeeptheOSandother
softwareuptodate
Updatesmustbeinstalledfromthevendorswebsite
Updatescanbeinstalledautomaticallyormanually
Automaticupdatescanbeinstalledonascheduled
basis
Theupdateprocesscanbehiddenandrestored
28
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
29
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
30
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
31
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
Thechangeisappliedtothelistofaddedprograms
32
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
33
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
34
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
35
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
36
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
37
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
38
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
Closeanyopenprograms
runningonthepartitionor
logicaldrivetobe
converted
IntheCommandPrompt,
typeconvertdrive_letter:
/fs:ntfs,where
drive_letter istheletterof
thedrivetobeconvertedto
NTFS,andthenpressENTER
Typethenameofthe
volumeyouwanttoconvert,
andthenpressENTER
Note:ConvertingapartitionfromFATtoNTFSdoesnotaffectthedataonit.
YouneedtorestartthecomputerfortheNTFSconversionifthepartition
containssystemfiles.
39
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
Module Flow
GuidelinesforSecuring
MacOSX
SystemSecurity
WindowsSecurity
Tools
ThreatstoSystem
Security
HowDoes
MalwarePropagate?
WindowsEncrypting
FileSystem(EFS)
GuidelinesforWindowsOSSecurity
40
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
41
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
Rightclickthefiletobedecrypted
selectProperties
OntheGeneral tab,clickthe
Advanced button.AnAdvanced
Attributes dialogboxappears
Therearetwooptionsunder
CompressorEncryptAttributes,
Compresscontentstosavediskspace
andEncryptcontentstosecuredata
UncheckEncryptcontentstosecure
data clickOK toclosethe
Compress/EncryptAttributesdialog
box applythesettings clickOK
42
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
43
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
BitLockerDriveEncryptionprovidesbetterdataprotectionbyencryptinganentireWindowsoperatingsystem
volume
2.
Theharddriveandanyremovablemediaonthecomputercanbeencrypted
3.
EncryptedremovablemediacanbedecryptedandreencryptedonanyWindows7computer
4.
Note:BitLocker isavailableonlyintheEnterpriseandUltimateeditionsofWindowsVistaandWindows7
44
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
WindowsXP
Windows7
45
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
46
1. EventViewercategorizeseventsintofivetypes:
Error,Warning,Information,AuditSuccess,and
AuditFailure
2. Eacheventlogisdifferentiatedbyitslevel and
containsheaderinformationandadescriptionof
theevent
3. Eacheventheadercontainsadetaileddescription
ofthelevel,date,time,source,eventID,andtask
category
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
47
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
Killing a process
Press [Alt]+[Ctrl]+[Del]keyssimultaneously click
TaskManager
InTask Manager gotoProcesses tab selectthe
Process clickEnd Process
Alternatively,rightclickonaselectedtargetprocess
selectEnd Process
48
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
49
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
1. ClickStart typesecpol.msc in
searchbar,andpressEnter
2. ClickLocalPolicies selectAudit
Policy doubleclicktheAudit
accountlogoneventspolicy
checktheSuccess andFailureboxes
clickApply click OK
3. Similarly,changethesecurity
settingforallthepolicieslistedin
therighthandpaneofLocal
SecurityPolicywindow
4. ClosetheLocalSecurityPolicy
window
50
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
51
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
52
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
53
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
Module Flow
GuidelinesforSecuring
MacOSX
SystemSecurity
WindowsSecurity
Tools
ThreatstoSystem
Security
WindowsEncrypting
FileSystem(EFS)
HowDoes
MalwarePropagate?
GuidelinesforWindowsOSSecurity
54
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
MicrosoftSecurityEssentials
providesrealtimeprotection
forahomePCthatguards
againstviruses,spyware,and
othermalicioussoftware
http://www.microsoft.com
55
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
http://portableapps.com
56
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
2.
RegistryMechanicsafelycleans,repairs,andoptimizes theregistryandautomaticallybacksupchanges
forfuturerecovery
3.
http://www.pctools.com
57
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
http://www.microsoft.com
58
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
Module Flow
GuidelinesforSecuring
MacOSX
SystemSecurity
WindowsSecurity
Tools
ThreatstoSystem
Security
WindowsEncrypting
FileSystem(EFS)
HowDoes
MalwarePropagate?
GuidelinesforWindowsOSSecurity
59
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
60
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
61
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
Eachusershouldhavehisor
herownstandard or
managed account
Administratorsshouldonly
usetheiradministrator
accounts foradministration
purposes
62
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
63
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
64
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
65
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
66
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
67
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
68
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
Disable automaticlogin
Requirepasswordtounlock eachSystem
Preference.
69
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
70
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
2.
3.
4.
5.
Choosewhichapplication(s)youwantthefirewall
toallowandwhichtoblock
6.
71
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
InternetFraudComplaint
Center(IC3)
http://www.itsecurity.com
http://www.ic3.gov
CYBERCRIME
VirusBulletin
http://www.cybercrime.gov
http://www.virusbtn.com
CommonVulnerabilities
andExposures
WindowsSecurityGuide
http://www.winguides.com
http://www.cve.mitre.org
StaySafeOnline
MacintoshSecuritySite
http://www.staysafeonline.org
http://www.securemac.com
72
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
Module Summary
Attackersdiscovernewvulnerabilitiesandbugstoexploitincomputersoftware
Softwarevendorsusuallydeveloppatchestoaddresstheproblems
Encryptionistheprocessofconvertingdataintoasecretcode
Regularlyupdatetheoperatingsystemandotherapplications
WindowsSystemRestoreisusedtoreturnonescomputertoanearlierstatein
caseofasystemfailureorothermajorproblemwiththesystem
MicrosoftSecurityEssentialsprovidesrealtimeprotectionforthePCthatguards
againstviruses,spyware,andothermalicioussoftware
WindowsDefenderhelpstoprotectthesystemagainstpopups,slowperformance,
andsecuritythreats
73
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
74
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
75
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
Backupyourfilesandsettingsregularlysothatifyougetavirusorhaveanykindof
hardwarefailure,youcanrecoveryourfiles
SetWindowsUpdatetodownloadandinstallthelatestupdatesforthecomputer
automatically
WindowsFirewallcanhelppreventhackersandmalicioussoftware,suchasviruses,
fromgainingaccesstoyourcomputerthroughtheInternet
UseActionCentertomakesurethefirewallisON,antivirussoftwareisuptodate,and
thecomputerissettoinstallupdatesautomatically
76
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
InstallMacOSXusingMacOSExtendeddiskformatting
Createanadministratoraccountandastandardaccountforeach
administrator
Createkeychains forspecializedpurposes
SecurelyconfigureSecuritypreferences
77
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.