According to researchers Nikita Tarakanov and Oleg Kupree they are.
From Network World:
"For one, it's easy to make an image of the USB modem's file system,
modify it and write it on the modem again. There's a tool
available from Huawei to do modem backup and restore, but there are
also free tools that support modems from other manufacturers,
Tarakanov said.
Malware running on the computer could detect the model and version of
the active 3G modem and could write an image with malicious
customizations to it using such tools. That modem would then
compromise any computer it's used on.
The modem contains the installer for an application that gets installed on the computer, as well as the necessary drivers
for different OSes. The application allows the user to stop, start and manage the Internet connection established through
the modem.
The configuration files for the installed application, as well as
those of the application installer stored on the modem,
are in plain text and can be easily modified. One setting in the
configuration files defines what DNS servers the modem should
use for the Internet connection.
An attacker could change those entries to servers controlled by the attacker, Tarakanov said. This would give the attacker
the ability to direct users to rogue websites when they're trying to visit legitimate ones using the modem connection.
While the application installer itself cannot be directly modified to load malware because it's a signed executable, there
are some entries in its configuration file that can be used for this purpose.
For example, many configuration files had paths to antivirus installers and an option of whether to install those programs
or not, Tarakanov said. The researcher said that he never found an antivirus installer shipped with the USB modems he tested,
but the feature was there.
An attacker could create a custom image with a modified configuration file that enables this feature and installs a malicious
file stored on the modem instead of an antivirus program. If the image is written on a USB modem, every time the user would
install the modem application, the malware would also be installed, Tarakanov said.
The researchers also found a possible mass attack vector. Once installed on a computer, the modem application -- at least
the one from Huawei -- checks periodically for updates from a single server, Tarakanov said. Software branded for a specific
operator searchers for updates in a server directory specific to that operator.
An attacker who manages to compromise this update server, can launch mass attacks against users from many operators, Tarakanov
said. Huawei 3G modems from several different Russian operators used the same server, but there might be other update servers
for other countries, he said.
Tarakanov said that he didn't look for vulnerabilities in the actual modem drivers installed in the OS, but he expects them
to have vulnerabilities. The vast majority of third-party drivers in general have vulnerabilities, he said.
Tarakanov specializes in exploit writing and finding vulnerabilities in the Windows kernel mode drivers. However, Oleg Kupreev
was the leader for this particular research project concerning 3G/4G modems.
Research in this area is just at the beginning and there's more to investigate, Tarakanov said. Someone has to do it because
many new laptops come with 3G/4G modems directly built in and people should know if they're a security threat"
Let's hope new models will be safe because I use a 3G usb modem on occasion.
Source: Network World
Showing posts with label security. Show all posts
Showing posts with label security. Show all posts
Tuesday, March 19, 2013
Thursday, January 10, 2013
malware removal and prevention like a boss
It's highly likely that malware will never go away, no matter how awesome computers and the internet become malware will most likely still hang around like that old suit or old dress your parents never remove from their wardrobe and wear to parties. Gross. Anyway, since malware is here to stay, how does one go about removing it? Better, how does one prevent it? It can happen.
Check out this new blog post at InfoWorld written by Roger Grimes; let him tell you how the pros remove malware. It's a good piece.
While you're here let me give some advice on prevention. While malware is here to stay, it doesn't have to come stay at your house. This prevention method is near perfect.
1. Get behind a router/hardware firewall
If you have a direct line to the internet then you're screwed. You need to be behind a firewall and not just a firewall, but a hardware firewall. This is a good one. It's affordable and it rocks.
2. Antivirus
You know, I think if you're behind a firewall and you practice safe browsing then you're most likely good to go. However, many people don't practice safe browsing. So, download and install Microsoft Security Essentials. It's the best antivirus out there in my opinion. Note: if you're running windows 8 then you don't have to do this because it's already installed and running on your system.
3. Safe-Browsing Add-on
This handy tool from Web of Trust rates websites for you and will give you a warning screen upon clicking a poorly rated link. This helps out a lot because it trains the user in safe browsing. Get it here. You will need to install it on every browser you use.
4. OpenDNS
This is, arguably, optional. Using OpenDNS will not only improve your DNS performance (which makes your internet browsing faster), but it also has excellent security tools like malware prevention and safe browsing. The web filter is not only good for preventing porn, but it also filters sites that are infested with malware and other junk. Good stuff. Use it.
So those are four ways to prevent your pc and network from malware infections. However, these tools can't keep you (totally keep you) from user installed malware. So, learn about safe browsing.
Check out this new blog post at InfoWorld written by Roger Grimes; let him tell you how the pros remove malware. It's a good piece.
While you're here let me give some advice on prevention. While malware is here to stay, it doesn't have to come stay at your house. This prevention method is near perfect.
1. Get behind a router/hardware firewall
If you have a direct line to the internet then you're screwed. You need to be behind a firewall and not just a firewall, but a hardware firewall. This is a good one. It's affordable and it rocks.
2. Antivirus
You know, I think if you're behind a firewall and you practice safe browsing then you're most likely good to go. However, many people don't practice safe browsing. So, download and install Microsoft Security Essentials. It's the best antivirus out there in my opinion. Note: if you're running windows 8 then you don't have to do this because it's already installed and running on your system.
3. Safe-Browsing Add-on
This handy tool from Web of Trust rates websites for you and will give you a warning screen upon clicking a poorly rated link. This helps out a lot because it trains the user in safe browsing. Get it here. You will need to install it on every browser you use.
4. OpenDNS
This is, arguably, optional. Using OpenDNS will not only improve your DNS performance (which makes your internet browsing faster), but it also has excellent security tools like malware prevention and safe browsing. The web filter is not only good for preventing porn, but it also filters sites that are infested with malware and other junk. Good stuff. Use it.
So those are four ways to prevent your pc and network from malware infections. However, these tools can't keep you (totally keep you) from user installed malware. So, learn about safe browsing.
Friday, November 9, 2012
HP All-in-One Black Screen Blinking Cursor at Startup
I got a call from my brother earlier this week. He told me his HP All-in-One computer (brand new by the way) will only display a black screen with a blinking cursor after the blue HP splash screen. At the splash screen he has the option to click the escape key for diagnostics. He said the diagnostics don't solve the problem and asked if I could take a look at it for him. I said sure.
When I arrived at the scene, it's exactly as he told me: black screen, blinking cursor. He was worried about the hardware, but I assured him it most likely isn't his hardware and that if it just happens to be the hardware he still has the safety net of the warranty. I restarted the computer. I hit escape when given the option and waited for the HP diagnostic menu. I checked things out, made sure the boot order was correct, etc. I mostly wanted to check out the hardware diagnostic utility. I ran that and all the hardware passed the tests as I thought they would. I couldn't get into the advanced boot options though due to HP's diagnostic stuff overriding such an option. I wanted to boot into safe mode and check things out. If anyone reading this knows how to override HP's boot utility let me know because it's annoying.
Anyway, I put in the windows 7 disc and got to the recovery console. My hunch was that some malware screwed up the system since Windows wouldn't boot. Keep in mind, I wasn't getting an error message like 'bootmgr failed, couldn't be found, etc." or "ntldr missing." All I had to go off of was the black screen, blinking cursor, which isn't much to go by. My hunch was that the boot files were missing and had to be replaced from the Windows disc.
I booted from the Windows 7 disc. Instead of selecting install, I chose 'repair your computer.' After choosing that option, Windows ran a short scan for startup problems. It detected some problems then asked if I wanted to restart to correct the problems. I went ahead with this option even though my usual skepticism kept me from thinking this would solve the problem. I was right. It didn't solve the problem. I booted back into the recovery console, this time startup repair didn't detect any problems (???), then I went for the command prompt. This is where you want to go for this kind of problem. If you encounter this problem, go to the command prompt and enter the following commands, hitting enter after each command. Make sure and include spacing as spacing is shown.
Bootrec.exe
bcdedit /export C:\BCD_Backup
c:
cd boot
attrib bcd -s -h -r
ren c:\boot\bcd bcd.old
bootrec /RebuildBcd
bootrec /fixmbr
bootrec /fixboot
exit
After these commands, remove the rescue CD then reboot. Your computer should now boot into Windows 7.
We're not out of the woods yet though! I booted into their desktop and what did I see? I saw the File Restore monster. It was "scanning" showing me all of these "problems," a thousand windows were opening a second; it was crazy. Since I had dealt with this monster in the past, I was prepared to slay it this time around. My brother was worried that it was his computer; that it wasn't secure enough. I assured him that this malware only gets in if it's let in. This stuff doesn't get in by brute force. Someone using the computer let it in, by accident of course, but still having an Apple or Ubuntu wouldn't have stopped this.
Anyway, how did I slay the File Restore monster? I'll give you my routine that works. If you have another one, please let me know in the comment box.
File Restore hides your start menu links and a bunch of other stuff to scare you that your computer is truly broken. We won't restore this stuff in the beginning of the routine though. I wanted to go ahead and tell you so you know why those links are gone in case you have to deal with this beast.
I disabled Microsoft Security Essentials real-time scanner in preparation for Combofix.
I then ran combofix. I ran combofix before Malwarebytes because I know this malware is really nasty and wanted to go in with the big guns first. Don't be scared to run comboxfix. Start the app file, proceed with defaults. It will go through around 50 scans (the speed of the scans depends on your computer's specs - I've seen it go fast, I've seen it take a while - 10 to 60 minutes) then, it will create a log report, then open the log report giving you details on what it did.
Rebooted into safe mode.
Ran Malwarebytes quick scan. It only detected some PUPs. I told Malwarebytes to delete them anyway because it was adware and I wanted to make the system squeaky clean.
Rebooted into normal mode.
Ran Windows Repair. This tool is amazing. File Restore can really mess with the default settings for Windows, thus making it look broken. Windows Repair fixes the stuff malware screws up like that. It's a very nice tool. It automatically reboots after the scan finishes. This scan can take a while too. Again, the speed of the scan depends on the specs of your computer.
Windows was fixed after this routine. I wasn't done yet though. I enabled the real-time scanner for Microsoft Security Essentials. I made sure the quick scan was on a daily schedule. It was. I also wanted to make sure this computer was safe not just from the non-user stuff, but even from user-related 'attacks' like answering the door for malware when it goes knocking. I hooked them up with OpenDNS. I enabled the web filter. I went with the Custom configuration on the web filter enabling protection from Adware, P2P/File share sites, Dating sites, Nudity, Pornography, Proxy/Anonymizer, and Web Spam. OpenDNS also has basic malare/botnet protection too which helps.
Then, I installed the Web of Trust addon for Internet Explorer and Firefox. Web of Trust is a terrific broswer add-on rating websites to give you an idea of what you're getting into before you visit a site. A small dot next to each link gives you a rating for the site: green is good, yellow is questionable and red is bad.
If you click on a red rated site WOT will popup asking you if you really want to visit this site and lists why the site is rated red. This will scare most users, preventing them from downloading and installing malware on accident. It's nice. It works.
My brother and his wife were very exited with the work I done for them. They feel better and safer which is good.
This is how I handled the problem. Do you have a different way? Tell me about it in the comment box below.
When I arrived at the scene, it's exactly as he told me: black screen, blinking cursor. He was worried about the hardware, but I assured him it most likely isn't his hardware and that if it just happens to be the hardware he still has the safety net of the warranty. I restarted the computer. I hit escape when given the option and waited for the HP diagnostic menu. I checked things out, made sure the boot order was correct, etc. I mostly wanted to check out the hardware diagnostic utility. I ran that and all the hardware passed the tests as I thought they would. I couldn't get into the advanced boot options though due to HP's diagnostic stuff overriding such an option. I wanted to boot into safe mode and check things out. If anyone reading this knows how to override HP's boot utility let me know because it's annoying.
Anyway, I put in the windows 7 disc and got to the recovery console. My hunch was that some malware screwed up the system since Windows wouldn't boot. Keep in mind, I wasn't getting an error message like 'bootmgr failed, couldn't be found, etc." or "ntldr missing." All I had to go off of was the black screen, blinking cursor, which isn't much to go by. My hunch was that the boot files were missing and had to be replaced from the Windows disc.
I booted from the Windows 7 disc. Instead of selecting install, I chose 'repair your computer.' After choosing that option, Windows ran a short scan for startup problems. It detected some problems then asked if I wanted to restart to correct the problems. I went ahead with this option even though my usual skepticism kept me from thinking this would solve the problem. I was right. It didn't solve the problem. I booted back into the recovery console, this time startup repair didn't detect any problems (???), then I went for the command prompt. This is where you want to go for this kind of problem. If you encounter this problem, go to the command prompt and enter the following commands, hitting enter after each command. Make sure and include spacing as spacing is shown.
Bootrec.exe
bcdedit /export C:\BCD_Backup
c:
cd boot
attrib bcd -s -h -r
ren c:\boot\bcd bcd.old
bootrec /RebuildBcd
bootrec /fixmbr
bootrec /fixboot
exit
After these commands, remove the rescue CD then reboot. Your computer should now boot into Windows 7.
We're not out of the woods yet though! I booted into their desktop and what did I see? I saw the File Restore monster. It was "scanning" showing me all of these "problems," a thousand windows were opening a second; it was crazy. Since I had dealt with this monster in the past, I was prepared to slay it this time around. My brother was worried that it was his computer; that it wasn't secure enough. I assured him that this malware only gets in if it's let in. This stuff doesn't get in by brute force. Someone using the computer let it in, by accident of course, but still having an Apple or Ubuntu wouldn't have stopped this.
Anyway, how did I slay the File Restore monster? I'll give you my routine that works. If you have another one, please let me know in the comment box.
File Restore hides your start menu links and a bunch of other stuff to scare you that your computer is truly broken. We won't restore this stuff in the beginning of the routine though. I wanted to go ahead and tell you so you know why those links are gone in case you have to deal with this beast.
I disabled Microsoft Security Essentials real-time scanner in preparation for Combofix.
I then ran combofix. I ran combofix before Malwarebytes because I know this malware is really nasty and wanted to go in with the big guns first. Don't be scared to run comboxfix. Start the app file, proceed with defaults. It will go through around 50 scans (the speed of the scans depends on your computer's specs - I've seen it go fast, I've seen it take a while - 10 to 60 minutes) then, it will create a log report, then open the log report giving you details on what it did.
Rebooted into safe mode.
Ran Malwarebytes quick scan. It only detected some PUPs. I told Malwarebytes to delete them anyway because it was adware and I wanted to make the system squeaky clean.
Rebooted into normal mode.
Ran Windows Repair. This tool is amazing. File Restore can really mess with the default settings for Windows, thus making it look broken. Windows Repair fixes the stuff malware screws up like that. It's a very nice tool. It automatically reboots after the scan finishes. This scan can take a while too. Again, the speed of the scan depends on the specs of your computer.
Windows was fixed after this routine. I wasn't done yet though. I enabled the real-time scanner for Microsoft Security Essentials. I made sure the quick scan was on a daily schedule. It was. I also wanted to make sure this computer was safe not just from the non-user stuff, but even from user-related 'attacks' like answering the door for malware when it goes knocking. I hooked them up with OpenDNS. I enabled the web filter. I went with the Custom configuration on the web filter enabling protection from Adware, P2P/File share sites, Dating sites, Nudity, Pornography, Proxy/Anonymizer, and Web Spam. OpenDNS also has basic malare/botnet protection too which helps.
Then, I installed the Web of Trust addon for Internet Explorer and Firefox. Web of Trust is a terrific broswer add-on rating websites to give you an idea of what you're getting into before you visit a site. A small dot next to each link gives you a rating for the site: green is good, yellow is questionable and red is bad.
If you click on a red rated site WOT will popup asking you if you really want to visit this site and lists why the site is rated red. This will scare most users, preventing them from downloading and installing malware on accident. It's nice. It works.
My brother and his wife were very exited with the work I done for them. They feel better and safer which is good.
This is how I handled the problem. Do you have a different way? Tell me about it in the comment box below.
Tuesday, October 9, 2012
Hardware Firewall Is a Must
From TechRepublic's recent "10 Things" blog:
6: Deploy a hardware-based firewall Let’s face it: The built-in Windows firewall is simply not sufficient. If you want real security, you need a dedicated firewall on your network. This firewall will be a single point of entry that will stop many more attempted breaches than the standard software-based firewall will. Besides, the hardware-based fire will be far more flexible and customizable. Look at a Cisco, Sonicwall, or Fortinet hardware firewall as your primary protection.
This is an excellent, excellent, (did I say excellent?) recommendation. If you or your business is connected straight to your modem without any border protection from the external world then you're in jeopardy and by jeopardy I don't mean the game show, I mean trouble. Why? Because your PC or group of PCs have an external IP. Your device doesn't have a bouncer to keep the bad guys and crap out of your house. You don't have that extra layer of protection that a connected device needs to operate more securely. Now, don't think a hardware firewall will make you invincible. I don't want to paint the wrong picture. I do mean to say that a hardware based firewall along with other security measures can make you more secure.
What are the benefits of a hardware based firewall?
1. NAT
*cue hissing* Some techs don't think NAT is a security feature, but I do. There is some mystery regarding NAT. Was it meant for security? Was it not meant for security? I think it's up in the air. Even so, I think it's fair to say that NAT gives *some* security in that it gives your device a local IP instead of your public, external IP. Intruders, the green ones conservatively speaking, won't know your device's IP which does help. No, it's not a super excellent security feature, but it's just another layer of protection that is nice to have while we're still mostly in a IPv4 world.
2. Rules
With a hardware based firewall, you can make firewall rules which are rules that you create to allow the traffic you want coming in and leaving your network. You can make as many or as little rules as you like. Don't want RDP sessions coming in to your network? Block it. Don't like WMI packets coming in? Block those too. It's customizable. Some techs start by blocking everything then slowly unblocking ports as the days progress. For example, a tech had most ports blocked. He downloaded WoW was able to run some of it, then realized he needed to open certain ports for the game, so he did. That's what I mean by some techs block everything, then slowly open ports when the situation occurs. You don't need everything open right out of the gate. Only open ports that you need open.
3. Logs
Yeah, Windows and other OSs have log views, they're limited to your system though. With a hardware firewall you'll have logs informing you who and what was trying to access your network. You'll see your rules working. You'll see intrusions prevented, this app allowed, another app blocked and so on. It's helpful. It's encouraging. You can see your firewall at work or not at work. You'll see what's getting in, out, and blocked. Those are three reasons I can think of right away for getting a hardware firewall. You don't have to spend hundreds of dollars on a hardware firewall either. Routers come equipped with firewalls. For my home I use a Netgear wireless router that is excellent for my home setup. The firewall provides good protection, customization, and it's easy to use. Buy one.
Netgear WNR3500L this link gives you the specs and has links to the stores it's sold at.
* I didn't make the image used in this blog post. I found it in a google search from this website.
6: Deploy a hardware-based firewall Let’s face it: The built-in Windows firewall is simply not sufficient. If you want real security, you need a dedicated firewall on your network. This firewall will be a single point of entry that will stop many more attempted breaches than the standard software-based firewall will. Besides, the hardware-based fire will be far more flexible and customizable. Look at a Cisco, Sonicwall, or Fortinet hardware firewall as your primary protection.
This is an excellent, excellent, (did I say excellent?) recommendation. If you or your business is connected straight to your modem without any border protection from the external world then you're in jeopardy and by jeopardy I don't mean the game show, I mean trouble. Why? Because your PC or group of PCs have an external IP. Your device doesn't have a bouncer to keep the bad guys and crap out of your house. You don't have that extra layer of protection that a connected device needs to operate more securely. Now, don't think a hardware firewall will make you invincible. I don't want to paint the wrong picture. I do mean to say that a hardware based firewall along with other security measures can make you more secure.
What are the benefits of a hardware based firewall?
1. NAT
*cue hissing* Some techs don't think NAT is a security feature, but I do. There is some mystery regarding NAT. Was it meant for security? Was it not meant for security? I think it's up in the air. Even so, I think it's fair to say that NAT gives *some* security in that it gives your device a local IP instead of your public, external IP. Intruders, the green ones conservatively speaking, won't know your device's IP which does help. No, it's not a super excellent security feature, but it's just another layer of protection that is nice to have while we're still mostly in a IPv4 world.
2. Rules
With a hardware based firewall, you can make firewall rules which are rules that you create to allow the traffic you want coming in and leaving your network. You can make as many or as little rules as you like. Don't want RDP sessions coming in to your network? Block it. Don't like WMI packets coming in? Block those too. It's customizable. Some techs start by blocking everything then slowly unblocking ports as the days progress. For example, a tech had most ports blocked. He downloaded WoW was able to run some of it, then realized he needed to open certain ports for the game, so he did. That's what I mean by some techs block everything, then slowly open ports when the situation occurs. You don't need everything open right out of the gate. Only open ports that you need open.
3. Logs
Yeah, Windows and other OSs have log views, they're limited to your system though. With a hardware firewall you'll have logs informing you who and what was trying to access your network. You'll see your rules working. You'll see intrusions prevented, this app allowed, another app blocked and so on. It's helpful. It's encouraging. You can see your firewall at work or not at work. You'll see what's getting in, out, and blocked. Those are three reasons I can think of right away for getting a hardware firewall. You don't have to spend hundreds of dollars on a hardware firewall either. Routers come equipped with firewalls. For my home I use a Netgear wireless router that is excellent for my home setup. The firewall provides good protection, customization, and it's easy to use. Buy one.
Netgear WNR3500L this link gives you the specs and has links to the stores it's sold at.
* I didn't make the image used in this blog post. I found it in a google search from this website.
Tuesday, August 14, 2012
Daily Security Checklist
I don't fancy myself as one of the greats in the IT world. I know I'm a lowly rookie IT professional just starting out, but I do think my daily security checklist is worth sharing. If you don't have a security checklist you go through each day you might want to create one (heck, steal mine I don't care) just so you will be able to catch things in time and for peace of mind. If I'm able, I go through this checklist first thing before I do anything else unless there's urgent work waiting for me as soon as I step through the double doors (we have a set of double doors at our building - nothing fancy, but it's kind of cool to walk through them all bad and stuff). This checklist is tailored for our network, so I'll be using the names of hardware and software we have. If you don't have the same hardware and software, replace the name for your configuration, e.g. replace Sonicwall with Cisco, Juniper, etc.
Checking the border - Firewall and DNS
Our border firewall is a Sonicwall TZ 210. This bad boy is perfect for our environment: small in physical size, priced just right, excellent security, small learning curve, and boasts a lot of tools for the admin. I check the Sonicwall logs first thing because that is the point between us and the "external." I check the following logs: attacks, anti-spam service, and networking. I then move over to the current connections under the firewall tab. After that, I check out the current data from the security dashboard. I'm not familiar with other hardware/border firewalls, Sonicwall is my area, but I would think Cisco and Juniper have similar types of logs and such. I think it's important to check the logs first thing and the current connections in and out of your network. After a while, you'll notice the "everyday" stuff. Even though it's tempting to not check these things after a week or so of clean data don't do it. Resist!
DNS security
This step might not be a necessary step depending on your configuration. I check our OpenDNS records after the border firewall check because next in line is our DNS security, so that's the logic I follow (maybe it sucks, but it works for me - haha). Anyway, I login to our OpenDNS dashboard and check the logs. It's important to see what network users are accessing and trying to access. I notice a lot of adware and malware blocked by OpenDNS. The cool thing about OpenDNS is their alert system. If OpenDNS has detected malware, you see the alert in big red letters on your dashboard. The only problem is that OpenDNS can't give you the internal IP address, but it's because it's border protection. So, not only is OpenDNS good for web service, but it's security system is nice as well.
Checking the Inside: Network Monitor, Server, and Antivirus
I then move on to internal checks. Network monitoring tools come in handy here, e.g. LANsweeper and Spiceworks, checking vulnerabilities on PCs and non-PCs. LANsweeper has an excellent dashboard view giving you information like the following: pcs not up-to-date, infections, low disk space, recent changes and other cool stuff for non-PC devices. Most network monitoring software does this. I check the necessary reports then move on.
Next, I check the Windows Server 2008 R2 logs in the server manager. If you don't use Server Manager I recommend it for the simplicity. Everything you need for quick checks is there: roles, functions, and event viewer. I check the high priority events then move on to antivirus. We use Kaspersky Small Office Security. I check the scans of all the PCs in the network to make sure there weren't any infections detected and I also check to make sure all of the PCs were updated.
That is my security checklist. I follow the outside to inside approach because it makes sense to me. Usually the biggest threats will come from the outside (threats users don't notice) and the smaller threats are on the inside. If you have any suggestions feel free to comment on this post. I'm usually on the lookout to improve my checklist.
Checking the border - Firewall and DNS
Our border firewall is a Sonicwall TZ 210. This bad boy is perfect for our environment: small in physical size, priced just right, excellent security, small learning curve, and boasts a lot of tools for the admin. I check the Sonicwall logs first thing because that is the point between us and the "external." I check the following logs: attacks, anti-spam service, and networking. I then move over to the current connections under the firewall tab. After that, I check out the current data from the security dashboard. I'm not familiar with other hardware/border firewalls, Sonicwall is my area, but I would think Cisco and Juniper have similar types of logs and such. I think it's important to check the logs first thing and the current connections in and out of your network. After a while, you'll notice the "everyday" stuff. Even though it's tempting to not check these things after a week or so of clean data don't do it. Resist!
DNS security
This step might not be a necessary step depending on your configuration. I check our OpenDNS records after the border firewall check because next in line is our DNS security, so that's the logic I follow (maybe it sucks, but it works for me - haha). Anyway, I login to our OpenDNS dashboard and check the logs. It's important to see what network users are accessing and trying to access. I notice a lot of adware and malware blocked by OpenDNS. The cool thing about OpenDNS is their alert system. If OpenDNS has detected malware, you see the alert in big red letters on your dashboard. The only problem is that OpenDNS can't give you the internal IP address, but it's because it's border protection. So, not only is OpenDNS good for web service, but it's security system is nice as well.
Checking the Inside: Network Monitor, Server, and Antivirus
I then move on to internal checks. Network monitoring tools come in handy here, e.g. LANsweeper and Spiceworks, checking vulnerabilities on PCs and non-PCs. LANsweeper has an excellent dashboard view giving you information like the following: pcs not up-to-date, infections, low disk space, recent changes and other cool stuff for non-PC devices. Most network monitoring software does this. I check the necessary reports then move on.
Next, I check the Windows Server 2008 R2 logs in the server manager. If you don't use Server Manager I recommend it for the simplicity. Everything you need for quick checks is there: roles, functions, and event viewer. I check the high priority events then move on to antivirus. We use Kaspersky Small Office Security. I check the scans of all the PCs in the network to make sure there weren't any infections detected and I also check to make sure all of the PCs were updated.
That is my security checklist. I follow the outside to inside approach because it makes sense to me. Usually the biggest threats will come from the outside (threats users don't notice) and the smaller threats are on the inside. If you have any suggestions feel free to comment on this post. I'm usually on the lookout to improve my checklist.
Microsoft Security Essentials and me
New kid on the antivirus block, Microsoft Security Essentials, is silently flexing his muscles and attracting some people over to his yard. Folks are going to it and for good reason because 1) It does a very good job 2) It really is anti-annoying and 3) It's lightweight. Plus, the layout is user-friendly and very attractive because of its simplicity.
1. It does a very good job
Recently, before running a malwarebytes scan on an allegedly malware infested system, I'll run a scan on the pc with the system's currently installed antivirus agent. One particular example I can think of was an AVG 2012 protected system. The system had all of the indicators of a malware infestation. I ran a scan with AVG and it returned a "no infections found" report. I uninstalled AVG 2012, installed MSE and on the initial quick scan, MSE found a few trojans and some adware. I ran a full scan in safe mode just to be safe and the scan was clean. I then ran a Malwarebytes full scan, still in safe mode, and the report was clean. I couldn't believe it. I then started using MSE myself and I install it on client systems. MSE obviously doesn't find infections every time on the first initial quick scan after install. Sometimes, the infestation is deep in the system and something more powerful like Malwarebytes would need to be used, but for general protection I'm learning that MSE is better than others like AVG, Avast, and Panda. It's at least better than their free versions.
2. It's Anti-annoying and anti-expensive
"It's true. It's true," said Kurt Angle when asked if MSE was anti-annoying and anti-expensive. I'm just kidding. To my knowledge Angle hasn't been interviewed on MSE (it was funny though, right?). No, but MSE is very silent, lean, and doesn't annoy you unless it has protected you from a threat. It doesn't even tell you when it's been updated like other antivirus programs.
I received a call from a client last week about a problem. He told me his computer was acting funny, i.e., Internet Explorer was crashing every few seconds. When I arrive at this site, he gives me free reign. Before I do anything, I check to see what is running (down close to his clock) and I see that Avast! and MSE are both running. I remembered installing MSE on his pc a while back, but didn't remember Avast! being on his pc. I asked him if he installed Avast! and he said he did just a week ago because he didn't think he had antivirus running on the system since he wasn't getting alerted every day about something. I laughed and showed him MSE was on his system and that was his protection from threats. He mentioned that he remembered me giving him an overview of that, but thought I didn't install it because he couldn't tell it was even on there. That's one thing that makes MSE better than the rest. It's anti-annoying.
3. Lightweight
MSE isn't resource intensive. You don't even notice it updating, scanning; you forget it's even there. Compared with Avast! and AVG, it's very skinny.
The only complaint I have is with scan scheduling. You can either schedule a quick scan or a full scan, but not both. Personally, I would like to have the scan schedule be a quick scan Sunday through Friday, then a full scan on Saturday, but MSE (as far as I know) won't let you do schedule like that. It's a very minor flaw. I have my schedule for quick scan 6 days a week, then do a manual full scan once a week. It's no problem.
Download MSE here.
The only complaint I have is with scan scheduling. You can either schedule a quick scan or a full scan, but not both. Personally, I would like to have the scan schedule be a quick scan Sunday through Friday, then a full scan on Saturday, but MSE (as far as I know) won't let you do schedule like that. It's a very minor flaw. I have my schedule for quick scan 6 days a week, then do a manual full scan once a week. It's no problem.
Download MSE here.
Subscribe to:
Posts (Atom)
