Home > Windows Security Tips > > Windows networking mistakes: The five most common
Windows Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 


Windows networking mistakes: The five most common


Jonathan Hassell
10.13.2005
Rating: -3.91- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Rather than take the common approach of dispensing advice and recommendations, let's change the story a bit. Let's talk about what not to do. What are some of the most common mistakes I see administrators making in their Windows networks?

Mistake one: Not enabling automatic updates on critical Internet-facing machines. This is really an unacceptable oversight, as the machines most vulnerable to exploitation are the ones easily accessible from outside your security perimeter. By enabling automatic updates, which patch these problems regularly, just on these machines, you'll cut your security response load immensely. (Note that it's OK to leave this off internally. You can keep your change management policies intact on the inside part of your network, where the risk of direct exploit is less, as long as you make plans to patch as soon as possible after you conclude testing on the updates.)

Windows security tips
  • Book excerpt: Securing wireless access
  • Checklist: Windows services you should disable today
  • Mistake two: Favoring interoperability over security. So you have a network with the makeup of a mutt: a lot of Windows machines, and Windows on some servers, but also a few Macintosh clients and perhaps a room full of Unix or Linux infrastructure servers. And they all needed to work together painlessly, so you probably hacked a solution together involving stored passwords and plain-text communications and publicly readable directories. I've seen it before. And these are places that nefarious individuals go to glean all sorts of useful credentials and location information for use in their deviant efforts. The bottom line: Make sure when heterogeneous platforms are talking to each other that they still uphold the same level of integrity that's possible when homogeneous machines are communicating.

    Mistake three: Leaving unneeded services on. It's great that all 150 machines on your factory floor have the Messenger service enabled, but it's probably not something that your workers are making legitimate use of. And it can be a very confusing way to convince other computer users to do bad things on behalf of crackers (these Messenger boxes can look a lot like error messages). Use the services guide I wrote for SearchWindowsSecurity.com to lock down these unneeded services.

    Mistake four: Not hardening remote access points. There are weak points in every network, and they're invariably located at the windows into your network -- where machines and users from outside your security boundaries can come inside and use resources and make changes within. After all, in your house, it's a lot more likely someone will break into a door or window than cut through siding or brick and drywall. Make sure your VPN concentrators, remote access servers, dial-in modem banks and public authentication servers are all hardened and protected against external threats.

    Mistake five: Deploying wireless Internet access without security. Wired networks have at least one advantage over wireless -- their contents aren't leaked to anyone who can listen. Your data and messages and the secure content they contain are at least constrained within the bounds of a wire, whereas transmitting the same packets over the air allows anyone to come in and sample the waves. And if you're in a city or another highly trafficked area, it's probably already happened. Deploy some sort of encryption and security measures, like not broadcasting your SSID and enabling WPA, to thwart the more casual data and access thieves.

    These five issues are the most conspicuous issues I see on average. If you're able to make progress on fixing these five, you'll be several orders of magnitude more secure than you were before you began.

    About the author: Jonathan Hassell is author of Hardening Windows (Apress LP), and is a SearchWindowsSecurity.com site expert. Hassell is a systems administrator and IT consultant residing in Raleigh, N.C., who has extensive experience in networking technologies and Internet connectivity. He runs his own Web-hosting business, Enable Hosting. His book RADIUS (O'Reilly & Associates), is a guide to the RADIUS authentication protocol and offers suggestions for implementing RADIUS and overall network security. Ask Hassell a hardening Windows question today.


    Rate this Tip
    To rate tips, you must be a member of SearchWindowsSecurity.com.
    Register now to start rating these tips. Log in if you are already a member.


    Submit a Tip




    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Wireless
    Windows Mobile security tips for the on-the-go pro
    Security tools that can boost Windows mobile security
    Windows mobile security: Get it locked down
    Remote access security measures for Windows users
    IT admins get help minding remote users
    Step 3: Dig in deep to demonstrate the threat
    Step 2: Search for weaknesses
    Step 1: Build your arsenal of tools
    A five-point strategy for secure remote access
    Penetration testing for Windows systems

    Configuration and Deployment
    DHCP Client Service error affects network security
    How to use a GPO to improve Windows folder security
    Remote management for Windows system upgrades
    How to secure BitLocker configurations
    What's new and improved in IPsec in Windows Server 2008
    Have my Windows patches actually been installed?
    What's hot in Windows security: Ins and outs of Windows Server 2008
    Rights management in Windows: Security expert roundup
    Set write permissions in Windows network folders
    Windows network rights, password policy and network security testing
    Configuration and Deployment Research

    Patch Maintenance
    DHCP Client Service error affects network security
    Microsoft will release three critical patches in May
    Critical patches for IE and Office released
    Microsoft releases April trove of patches
    PatchLink Update 6.4
    What's hot in Microsoft Windows security
    Importance of managing unpatched third-party software
    Microsoft patch management policy
    Microsoft patch maintenance and post-patch security
    Patch management and Windows Update aid in network setup

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary

    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

    HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersIT DownloadsBlogs
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2004 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts