Showing posts with label Network. Show all posts
Showing posts with label Network. Show all posts

Tuesday, September 15, 2009

Securing shared folders in Windows NT, 2000 & XP

Securing shared folders in Windows NT, 2000 & XP

It is good practice to secure any folders that you share for access over the network. It is a simple process and helps prevent the spread of viruses and minimises the risk of your such shares being abused.

By default when you create a shared folder the group 'Everyone' is given permission to access that folder. This is very insecure as the Everyone group means exactly that - anyone who can access the network has permission to see what is in your shared folder, can edit the material you have stored there and can save anything that they like to it.

Although you may believe that because people do not know it exists they will not find your shared folder this is not true. There are simple tools available for identifying network shared folders, and many viruses now search for shared folders and then attempt to use the folders they find to duplicate themselves. However by following the information below you can secure your shared folders.

Under Windows 95 /98 the sharing process is different - all users have to be specifically added i.e. the Everyone group is not added by default, so the same risk does not occur. However we would recommend that access to shares is limited to only those people or groups who specifically require it.

To secure a shared folder:

Before you start, decide on who will need access to the shared folder that you have created. Access can be to either individual users by login name, or to groups of users - these are the same as those available in Outlook, however you can only use centrally defined groups. So you can choose to have either a number of specified colleagues or a relevant group e.g. your departmental staff group, or a combination of both. We would advise the use of groups where possible, as this leads to easier management, and that access should be kept to the minimum required, to reduce risks.
Open Windows Explorer or My Computer and locate the folder you wish to secure. Shared folders can be identified by the hand underneath them - in this example the Utilities folder.
Right click on the folder and select the 'Sharing' or 'Sharing and Security' option from the list provided
You will now see a dialogue box similar to the one below (they vary with operating system), giving information about the shared folder. Click on the 'Permissions' button

NB. If you have not shared the folder before you will need to click on the 'Share this folder' radio button and then select a share name for the folder - by default this is the same as its local name. By adding a $ sign after the name (e.g. Utilities$) the folder will not be openly visible on the network.
A new window (Share Permissions) lists the users or groups of users who can access the share you have created, by default this is the Everyone group.
Click on the Add button and in the lower window type the names of the users / groups that you wish to limit access to - separated by a semi-colon. If you are not sure of the names you can use the upper window to browse for them, check that the 'Look in' box is set to essex or Entire Network first.

In this case we are going to grant access to Computing Service Staff (serstaff) and Keith Brooke (kbrooke).
Click on OK.
The Share Permissions window now contains the added users. You can now use the lower portion of this window to modify what the people you have granted access to are able to do.

In this case I want to only allow Keith to read the material in the folder, so having selected Keith in the top portion I confirm that only the Read box is checked in the lower portion. I also want to limit Service staff to being able to modify material (they cannot create new material or delete existing material), so again I select them in the top portion and now ensure that the Change and Read boxes are checked.

Please note that the boxes offered in the lower portion of the window maybe different with your operating system but they can be used in the same way.

Finally you need to remove the Everyone group. Select it and then click the remove button.

Access to share is now restricted.

Sunday, September 13, 2009

How to Fix External Drive Connection Problem in Windows Vista

In default mode, Windows Vista only permits NTLMv2 authentication on a network due to security reason. Certain external drives are incompatible with this authentication type. To fix this problem, LM and NTLM authentications need to be enabled. Here is the method:
  1. Click Start button.
  2. Select command/search field, type secpol.msc. The Local Security Policy utility will open.
  3. Examine the left menu and select Local Policies \ Security Options.
  4. Examine the right pane, scroll down to find Network Security: LAN Manager authentication level. Double click on it.
  5. Examine the Local Security Setting tab and there will be a drop down menu with several options. Select “Send LM & NTLM – use NTLMv2 session security if negotiated.”
  6. Some dialogs will appear. Accept it all.
  7. The computer will restart.

Saturday, September 12, 2009

Stay safe on a public wireless network


A few precautions to take when using wireless hotspots, to ensure that your computer’s security doesn’t land in a spot. Like everything technological, wireless hotspots are a boon and a bane. While they ensure quick and easy Internet access, they also pose big risks for your laptop.

First, communication over most public wireless networks is unencrypted, so that anyone on the same network can use some tools to read the data you transfer. Unless you’re communicating with your office via VPN (Virtual Private Network), which ensures a secure, encrypted channel even over the public network.

Second, rogue attacks are very easily executed on the public wireless network. One of these is the ‘evil twin’ attack. In this case, the attacker uses a laptop or other mobile device to place a wireless access point (WAP) close to your computer, one that gives a more powerful signal than the access point you intend to connect to. The name of such a ‘rogue’ network would probably be a known name, such as Linksys, so that you wouldn’t be suspicious about connecting. Once you do connect, all your data will flow through the attacker’s laptop to the Internet.

The third big risk is ‘over the shoulder’. Say you’re checking email or shopping online at a crowded cafĂ© or hotel lounge. There are chances of someone peeking at your usernames, passwords, and credit-card details as you enter them.

Here are a few ways in which you can guard against these risks.

• Take care while browsing
Public hotspots are definitely much less secure than your office networks. So try to avoid using them for transactions that require high levels of security, such as online banking or shopping. Reserve these for when you’re in a more secure environment.

• Use secure means
As far as possible, use VPNs for secure communication. Access email via Secure Socket Layer (SSL) sessions—many email providers support these. You could also avoid going to websites that require you to send sensitive information in clear-text, unencrypted format.

• Avoid evil twin attacks
To guard yourself against an evil twin attack while you’re trying to connect to a public network, carefully observe the icons on the screen that shows available network connections. If any icon shows two computers connected together, it’s a peer-to-peer network, something that’s used in evil twin attacks. Do not connect to such a network—the legitimate network would have the icon of a light beacon, and if it supports encryption, you will also see a padlock icon next to it. Prefer to connect to such an access point.

You can also tweak your Windows settings to avoid evil twin attacks. From the Wireless Networks panel, you can disable automatic connections; you can also configure your machine to “Connect to access point (infrastructure) networks only”. You could also give your home network a distinct name that cannot be confused with the names of other networks, so that there is less possibility of connecting to an ‘evil twin’ from home.

• Turn off all sharing
Your laptop may be configured for file and printer sharing. You should turn that off when you’re using a public hotspot. If you use share programs such as iTunes or have other shared directories on your laptop, you should turn those off too, unless you want to share your music and other preferences with a lot of strangers.

• Remember the basics
As always, the last line of defense is on your machine—a personal firewall and anti-virus and anti-spyware software are crucial. You should also have applied all the latest security patches to update

How to Secure a Wireless Network


Wireless networks are extremely convenient, but that convenience comes at a price: security. With a traditional wired network, data is channeled through cables and cannot be easily intercepted. With a wireless network, data is beamed through the sky and can be more easily intercepted – unless, that is, you have appropriate security measures in place. This article explains how to secure a wireless network against attack.

Before outlining the steps you should take to secure a wireless network, let’s quickly look at a couple of things that you probably don’t want to do: namely, disabling SSID broadcasting and enabling MAC filtering. The SSID is the name of your wireless network and its broadcast to enable people to easily find and connect to your network. Numerous Websites – in fact, just about every Website - recommend disabling SSID broadcasting (if the bad guys can find it they can hack it, right?) and enabling MAC filtering. However, MAC filtering is so easily bypassed as to render it almost completely redundant. With regards to SSID broadcasting, you can read more about this here.

So, if you shouldn’t disable your SSID broadcast, what should you do? Read on!

1. Use encryption. To stop outsiders being able to data this transmitted over your wireless network, the data should be encrypted. There are 3 wireless encryption standards: WEP, WPA and WPA2. WEP is the oldest and most easily cracked standard, so ideally you should use WPA or, better yet, WPA2.

2. Change the default account names and passwords. The majority of access points (APs) use default account names/passwords set by the manufacturer that are known to one and all. Change them to something unique.

3. Segment your network. Even when best practice is adhered to, a wireless network will be less secure than a wired network. Segmentation creates a barrier between the physical network and wireless network – by using a firewall, for example - and enables you to control access/communication between them. Unfortunately, this can be a somewhat complex job and, unless you have a fair amount of in-house expertise, you’ll probably need to retain the services of a consultant.

4. Authenticate users. RADIUS provides you with far more control over access to the WLAN. For more information, visit Microsoft's overview on securing wireless LANs with certificate services and the FreeRADIUS Project.

5. Update your firmware. The manufacturers of AP devices often release firmware updates to fix bugs and security vulnerabilities. So, keep your firmware updated.
Security is only as strong as its weakest link. Long and too often the wireless network is the weakest link. In simple environments, the network can probably be DIY’d; however, security matters do become more challenging in complex environments and in such cases the best advice may well be to leverage the expertise of a consultant.

One final bit of advice: the value of securing your own wireless network will be eroded if your data is bounced in unencrypted form over other networks. Educate your users and make sure that they are aware of the risks associated with connecting to an insecure network.