T
TehShiz
Guest
[Author]
TehShiz
[Purpose]
The purpose of this guide is to assist in protecting the valuable information stored on one’s computer, improve security and to improve performance of one’s computer in general and especially while gaming. This guide is intended as a quick note on general protection methods and should be followed with the user’s own accord.
[Definitions]
Malware – Software intended to damage one’s computer by some means; malicious software.
Spyware – Software intended to spy on the activities of computer user; often used for advertisement or password stealing purposes.
Adware – Software, usually embedded in other software, that presents advertisements to the user or attempts to force the user to visit paid advertisement locations.
Virus(es), Virii – Software specifically designed to cause damage to one’s computer; usually the most damaging type of software.
Trojan – The name derived from the Trojan Horse; the object that lead Grecian forces to victory over Troy. This type of software is usually designed to relay information back to the attacker and is often a ‘wolf in sheep’s clothing’.
[Preface]
An entry level approach should be acquiring a decent first line of defense. Below are listed the objectives of building this first line of defense.
Use common sense when visiting websites and downloading information.
Know your browser and how to protect it.
Use Email wisely.
Use a firewall, but not just any firewall.
Use protective software, effectively.
Secure services and startup programs.
Update your operating system regularly.
If this first line of defense is acquired and kept, you should be able to drastically cut risks and improve performance. I will be elaborating on these objectives below.
[Content]
= Use Common Sense =
- Know the website before browsing it.
* Where did I find out about this website’s existence?
* Is my source reliable?
* What do I already know about this website?
* What is the real purpose of this website?
- Know what you’re downloading.
* What is the real purpose of this download?
* What is the name/filename of this download?
* Is this download known to be trouble or suspicious?
* Who am I really downloading this from?
Often times you can perform a simple search on a website’s name or address and obtain simple information about it. I recommend Google.com for searching because of its size and ability to perform some of the most accurate searches available. You can learn a lot about how to use this search engine by reading through the four tutorials listed at http://www.google.com/intl/en/help/basics.html. This search engine provides you with a way of quickly searching through huge archives of news, forums and websites for any mention of a questionable website or download. You can use this to search for filenames before downloading. Once a search is performed, it provides you with a listing of websites relating to your search, but also provides you with an excerpt from the actual website which can give you a feel of the content. Google.com also provides you with the ability to look at the website as it is cached on the Google.com servers, which often removes some of the potentially harmful affects of a website. One of the best features of Google.com is the advanced searching ability (http://www.google.com/advanced_search?hl=en), this provides you with the ability to search specific website addresses for any pages of content that has been cached by Google.com. Now, by simply typing ‘theregister.com’ into the domain blank on the advanced search page, I am presented with this (http://www.google.com/search?q=+site:theregister.com&num=100&hl=en&lr=&as_qdr=all&filter=0), the entire latest cache for tdop.org including excerpts for most of it. Another way of previewing a website is to use the WayBackMachine (http://www.archive.org/web/web.php). Here is an archived version of tdop.org (http://web.archive.org/web/*/http://www.theregister.com). This also generally removes potentially harmful affects from the website so that you can preview most of its content before being fully exposed. Lastly in this section, with merging into the next section, I’d like to say that most browsers support SHIFT+Left Click or CTRL+Left Click to open a link into another window. This is useful when downloading from a website that doesn’t display the link in the information bar at the bottom of your browser; you can use this to open a download link into another window and see where the download is really coming from.
= Know Your Browser =
There are numerous guides out there that deal with the attempts to secure Internet Explorer, such as this one (http://antivirus.about.com/od/securitytips/a/secureie2.htm). Many people just see internet explorer as a virus of sorts that is better off quarantined away somewhere and only used for updating of the Windows operating system. The truth is that there is no way to really secure Internet Explorer against browser attacks from websites. Many people agree that Microsoft’s programmers aren’t the brightest on the block and they’re really time constrained with fixes because Internet Explorer is the most targeted browser for finding security holes to exploit. I myself only use Internet Explorer for Windows operating system updates; I have my homepage set to http://windowsupdate.microsoft.com/ and the only work Internet Explorer gets is a weekly running to that website to get updates and is then promptly closed. There are many alternatives to Internet Explorer, some free some bought. My favorite is FireFox (http://www.getfirefox.com). This browser has a good backing to be secure, provide the user with a much larger degree of features for security, provide the user with many many extentions and usability factors, has good programmers, is FREE and isn’t the main target. FireFox is famed by USA Today (http://www.usatoday.com/tech/news/computersecurity/2004-09-08-zombieinfect_x.htm) for spyware prevention and by FORBES (http://www.forbes.com/2004/09/29/cx_ah_0929tentech.html?partner=tentech_newsletter) for being ‘Better than Internet Explorer by leaps and bounds’.
If you decide to use FireFox, go the extra step of the way to be a ‘security freak’. Go to the Tools menu, Options and explore this to adjust settings to your needs. While here, go to the Privacy tab and click on Cookies, check the box for allowing cookies for originating websites only. This will help keep the advertisement agencies from tracking your browsing habits. Go to the Download Manager History, and drop the box down to choose to remove files from the manager upon successful downloading. This helps in keeping your download manager clean. Go to the Web Features tab, click to load images for originating websites only. This stops many advertisements and tracking banners. Click the Advanced button beside JavaScript, uncheck all the boxes except ‘change images’. This prevents any screwy work by webmasters to resize or move your windows, flash junk or attempt in hijacking your browser. Finally on the Download Manager tab, choose to close the download manager when downloads are complete. These things allow you to transition from Internet Explorer with ease and provide you with much better security. As a final tip on using FireFox, When you see a red or blue arrow icon appear near the top right corner of the browser, that means that there’s an update ready. I suggest clicking that icon when you see it to make sure you have the latest updates for FireFox.
= Use Email Wisely =
I highly recommend using a web-based email account for everything. This prevents any automated infections to your computer and allows you to see what is happening in the email without being in much danger. The combination of a properly configured browser and a web-based email account provides you with very good first line defense. Yahoo! Email is a good one (http://mail.yahoo.com). If you can score an invite into GMail (Google Mail), that would be good. There are plenty of good online email providers out there. This would be a good time for you to use the skills you learned about the Google search engine. If you do insist on keeping a POP3 (ISP, internet service provider, account), then I highly suggest that you do not use it to sign up for any websites or subscriptions and secure the client you use. Here is a guide to securing some common email clients (http://antivirus.about.com/od/securitytips/a/emailsafety.htm) or you could use Thunderbird (http://www.getthunderbird.com), from the same creators of FireFox.
= Use a Firewall =
Firewalls prevent and many times halt direct attacks on a computer from the Internet. Just any firewall doesn’t cut it in today’s world. The ‘Script Kiddies’, or new comers to attacking computers, are getting more advanced in their knowledge and tactics. It is important to have a quality firewall running at all times while connected to the Internet. An attack only takes 5-15 seconds to execute once someone knows that you’re there. I recommend Kerio Personal Firewall (http://www.kerio.com/us/kpf_home.html), Sygate Personal Firewall (http://smb.sygate.com/products/spf_standard.htm) or any other firewall that can with-stand flood attacks and runs at a system level as a service process. It is important that when you do choose a firewall that you learn how to apply rules and packet filters to the firewall. You should disable NETBIOS on your connection settings and apply rules/filters to prevent incoming NETBIOS and ICMP packets. This keeps outsiders from knowing for sure that you’re even there. Pings, Traceroutes, Broadcast, IGMP, ICMP, Port Scans and VPN communications should have rules/filters to block them. With the Kerio Personal Firewall, this is simply accomplished by double clicking the icon in the system tray, going to the Intrusions tab, denying all three priorities of intrusions. Then to complete the setup of the Kerio Personal Firewall, go to the Network Security tab, click on the Predefined tab and make sure everything is denied except DHCP and DNS. It is also important that you know that the firewall is logging attacks against it and that you monitor these attacks from time to time and if they are persistent that you report them to your ISP and/or the ISP of the attacker, along with your exported firewall log so that they can be dealt with. You can use this website (http://www.arin.net/whois/) along with an IP address (216.239.37.99 for example, which is Google.com website address) to gather information about the source of the attacker and be provided with an email address or website in which to report abuse and attacks. These email address to report to be usually in the format of [email protected]ever, but if this information is not provided there should always be some form of administrator address listed. Finally in this section I would like to address the use of multiple firewalls. The use of multiple software firewalls is bad, period. If you’re on a broadband connection, I recommend you use a hardware router/firewall as a first line of defense and one software firewall on the computer itself. Using a hardware firewall is the only exception for using multiple firewalls. When you place two software firewalls to work, it is nearly unpredictable as to which will accept the packet(s) incoming to your computer. One packet might be accepted by Firewall #1 while the next packet is accepted by Firewall #2. This leaves you with an uncommon and unpredictable central means of protection. There is also the ability for the packet(s) to not go through any firewall and make a direct landing, unfiltered. It is very important that you only use one software firewall. Unfortunately, Windows XP includes a firewall with it. I highly recommend disabling this firewall completely and using one of the firewalls mentioned previously. I will cover the disabling of this firewall in the upcoming ‘Secure Services and Startup Programs’ section of this guide.
= Use Protective Software =
There are many programs out there to scan for and prevent malware, spyware, adware, virii and trojans. I highly recommend Spybot Search & Destroy (http://security.kolla.de/), Ad-Aware (http://www.lavasoftusa.com/software/adaware/) and AVG Anti-virus (http://www.grisoft.com/) as a first line of defense. These are all free programs that are some of the top available and I recommend you download, install, update and scan with these programs. I recommend running, updating and scanning with these programs at least once per week. These programs are designed to get rid of what you might have let through your browser, email client or firewall. Also, when you’ve downloaded a zip file, executable or whatever; right click it and scan it with whatever anti-virus program you have installed.
= Secure Services and Startup Programs =
I highly recommend running the registry editor (regedit.exe, from Start->Run) and browsing to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run. There will be a listing of startup programs on the right side of this window and I suggest deleting every one of them that isn’t absolutely, solidly required for something. When I’m cleaning up a friend’s computer, the first thing I do is go right to this and delete every single one of them. There’s nothing to my knowledge besides maybe cd-rom/dvd-rom/storage virtual drive emulators that have anything that is a must requirement to startup.
The next steps to perform would be running the services control center. This can be done by running services.msc from the Start->Run prompt. This presents you with a window listing of every service that windows, anti-virus, firewalls or drivers use in the background that you were never really aware. This website (http://www.theeldergeek.com/services_guide.htm) provides a lot of information about services and has a list of all the services and details about what they really are. For security and performance, I suggest disabling the following services:
ClipBook
Fast User Switching
Indexing Service
Machine Debug Manager (unless you’re a programmer)
NetMeeting Remote Desktop Sharing
Portable Media Serial Number Service (unless you have a laptop or something)
Remote Registry
Security Center
Smart Card (unless you use them)
TCP/IP NetBIOS Helper
Telnet
Terminal Services
Windows Firewall/Internet Connection Sharing (ICS)
Windows Time
To disable a service, double click it, change the startup type to disabled, apply, ok. These changes should not only improve your security but also your performance as they won’t be using processor cycles or memory any longer.
= Update Your Operating System =
I recommend running windows update once a week (http://windowsupdate.microsoft.com/). Download any updates listed in any of the categories, there are exceptions to this. Don’t download the Microsoft Malicious Software protection update, it’s been known to conflict and be useless. Don’t download any hardware updates, get these directly from their respected websites of manufacturers. Don’t download Windows Media Player 10 or any updates to it, unless you use it as it is a large target.
TehShiz
[Purpose]
The purpose of this guide is to assist in protecting the valuable information stored on one’s computer, improve security and to improve performance of one’s computer in general and especially while gaming. This guide is intended as a quick note on general protection methods and should be followed with the user’s own accord.
[Definitions]
Malware – Software intended to damage one’s computer by some means; malicious software.
Spyware – Software intended to spy on the activities of computer user; often used for advertisement or password stealing purposes.
Adware – Software, usually embedded in other software, that presents advertisements to the user or attempts to force the user to visit paid advertisement locations.
Virus(es), Virii – Software specifically designed to cause damage to one’s computer; usually the most damaging type of software.
Trojan – The name derived from the Trojan Horse; the object that lead Grecian forces to victory over Troy. This type of software is usually designed to relay information back to the attacker and is often a ‘wolf in sheep’s clothing’.
[Preface]
An entry level approach should be acquiring a decent first line of defense. Below are listed the objectives of building this first line of defense.
Use common sense when visiting websites and downloading information.
Know your browser and how to protect it.
Use Email wisely.
Use a firewall, but not just any firewall.
Use protective software, effectively.
Secure services and startup programs.
Update your operating system regularly.
If this first line of defense is acquired and kept, you should be able to drastically cut risks and improve performance. I will be elaborating on these objectives below.
[Content]
= Use Common Sense =
- Know the website before browsing it.
* Where did I find out about this website’s existence?
* Is my source reliable?
* What do I already know about this website?
* What is the real purpose of this website?
- Know what you’re downloading.
* What is the real purpose of this download?
* What is the name/filename of this download?
* Is this download known to be trouble or suspicious?
* Who am I really downloading this from?
Often times you can perform a simple search on a website’s name or address and obtain simple information about it. I recommend Google.com for searching because of its size and ability to perform some of the most accurate searches available. You can learn a lot about how to use this search engine by reading through the four tutorials listed at http://www.google.com/intl/en/help/basics.html. This search engine provides you with a way of quickly searching through huge archives of news, forums and websites for any mention of a questionable website or download. You can use this to search for filenames before downloading. Once a search is performed, it provides you with a listing of websites relating to your search, but also provides you with an excerpt from the actual website which can give you a feel of the content. Google.com also provides you with the ability to look at the website as it is cached on the Google.com servers, which often removes some of the potentially harmful affects of a website. One of the best features of Google.com is the advanced searching ability (http://www.google.com/advanced_search?hl=en), this provides you with the ability to search specific website addresses for any pages of content that has been cached by Google.com. Now, by simply typing ‘theregister.com’ into the domain blank on the advanced search page, I am presented with this (http://www.google.com/search?q=+site:theregister.com&num=100&hl=en&lr=&as_qdr=all&filter=0), the entire latest cache for tdop.org including excerpts for most of it. Another way of previewing a website is to use the WayBackMachine (http://www.archive.org/web/web.php). Here is an archived version of tdop.org (http://web.archive.org/web/*/http://www.theregister.com). This also generally removes potentially harmful affects from the website so that you can preview most of its content before being fully exposed. Lastly in this section, with merging into the next section, I’d like to say that most browsers support SHIFT+Left Click or CTRL+Left Click to open a link into another window. This is useful when downloading from a website that doesn’t display the link in the information bar at the bottom of your browser; you can use this to open a download link into another window and see where the download is really coming from.
= Know Your Browser =
There are numerous guides out there that deal with the attempts to secure Internet Explorer, such as this one (http://antivirus.about.com/od/securitytips/a/secureie2.htm). Many people just see internet explorer as a virus of sorts that is better off quarantined away somewhere and only used for updating of the Windows operating system. The truth is that there is no way to really secure Internet Explorer against browser attacks from websites. Many people agree that Microsoft’s programmers aren’t the brightest on the block and they’re really time constrained with fixes because Internet Explorer is the most targeted browser for finding security holes to exploit. I myself only use Internet Explorer for Windows operating system updates; I have my homepage set to http://windowsupdate.microsoft.com/ and the only work Internet Explorer gets is a weekly running to that website to get updates and is then promptly closed. There are many alternatives to Internet Explorer, some free some bought. My favorite is FireFox (http://www.getfirefox.com). This browser has a good backing to be secure, provide the user with a much larger degree of features for security, provide the user with many many extentions and usability factors, has good programmers, is FREE and isn’t the main target. FireFox is famed by USA Today (http://www.usatoday.com/tech/news/computersecurity/2004-09-08-zombieinfect_x.htm) for spyware prevention and by FORBES (http://www.forbes.com/2004/09/29/cx_ah_0929tentech.html?partner=tentech_newsletter) for being ‘Better than Internet Explorer by leaps and bounds’.
If you decide to use FireFox, go the extra step of the way to be a ‘security freak’. Go to the Tools menu, Options and explore this to adjust settings to your needs. While here, go to the Privacy tab and click on Cookies, check the box for allowing cookies for originating websites only. This will help keep the advertisement agencies from tracking your browsing habits. Go to the Download Manager History, and drop the box down to choose to remove files from the manager upon successful downloading. This helps in keeping your download manager clean. Go to the Web Features tab, click to load images for originating websites only. This stops many advertisements and tracking banners. Click the Advanced button beside JavaScript, uncheck all the boxes except ‘change images’. This prevents any screwy work by webmasters to resize or move your windows, flash junk or attempt in hijacking your browser. Finally on the Download Manager tab, choose to close the download manager when downloads are complete. These things allow you to transition from Internet Explorer with ease and provide you with much better security. As a final tip on using FireFox, When you see a red or blue arrow icon appear near the top right corner of the browser, that means that there’s an update ready. I suggest clicking that icon when you see it to make sure you have the latest updates for FireFox.
= Use Email Wisely =
I highly recommend using a web-based email account for everything. This prevents any automated infections to your computer and allows you to see what is happening in the email without being in much danger. The combination of a properly configured browser and a web-based email account provides you with very good first line defense. Yahoo! Email is a good one (http://mail.yahoo.com). If you can score an invite into GMail (Google Mail), that would be good. There are plenty of good online email providers out there. This would be a good time for you to use the skills you learned about the Google search engine. If you do insist on keeping a POP3 (ISP, internet service provider, account), then I highly suggest that you do not use it to sign up for any websites or subscriptions and secure the client you use. Here is a guide to securing some common email clients (http://antivirus.about.com/od/securitytips/a/emailsafety.htm) or you could use Thunderbird (http://www.getthunderbird.com), from the same creators of FireFox.
= Use a Firewall =
Firewalls prevent and many times halt direct attacks on a computer from the Internet. Just any firewall doesn’t cut it in today’s world. The ‘Script Kiddies’, or new comers to attacking computers, are getting more advanced in their knowledge and tactics. It is important to have a quality firewall running at all times while connected to the Internet. An attack only takes 5-15 seconds to execute once someone knows that you’re there. I recommend Kerio Personal Firewall (http://www.kerio.com/us/kpf_home.html), Sygate Personal Firewall (http://smb.sygate.com/products/spf_standard.htm) or any other firewall that can with-stand flood attacks and runs at a system level as a service process. It is important that when you do choose a firewall that you learn how to apply rules and packet filters to the firewall. You should disable NETBIOS on your connection settings and apply rules/filters to prevent incoming NETBIOS and ICMP packets. This keeps outsiders from knowing for sure that you’re even there. Pings, Traceroutes, Broadcast, IGMP, ICMP, Port Scans and VPN communications should have rules/filters to block them. With the Kerio Personal Firewall, this is simply accomplished by double clicking the icon in the system tray, going to the Intrusions tab, denying all three priorities of intrusions. Then to complete the setup of the Kerio Personal Firewall, go to the Network Security tab, click on the Predefined tab and make sure everything is denied except DHCP and DNS. It is also important that you know that the firewall is logging attacks against it and that you monitor these attacks from time to time and if they are persistent that you report them to your ISP and/or the ISP of the attacker, along with your exported firewall log so that they can be dealt with. You can use this website (http://www.arin.net/whois/) along with an IP address (216.239.37.99 for example, which is Google.com website address) to gather information about the source of the attacker and be provided with an email address or website in which to report abuse and attacks. These email address to report to be usually in the format of [email protected]ever, but if this information is not provided there should always be some form of administrator address listed. Finally in this section I would like to address the use of multiple firewalls. The use of multiple software firewalls is bad, period. If you’re on a broadband connection, I recommend you use a hardware router/firewall as a first line of defense and one software firewall on the computer itself. Using a hardware firewall is the only exception for using multiple firewalls. When you place two software firewalls to work, it is nearly unpredictable as to which will accept the packet(s) incoming to your computer. One packet might be accepted by Firewall #1 while the next packet is accepted by Firewall #2. This leaves you with an uncommon and unpredictable central means of protection. There is also the ability for the packet(s) to not go through any firewall and make a direct landing, unfiltered. It is very important that you only use one software firewall. Unfortunately, Windows XP includes a firewall with it. I highly recommend disabling this firewall completely and using one of the firewalls mentioned previously. I will cover the disabling of this firewall in the upcoming ‘Secure Services and Startup Programs’ section of this guide.
= Use Protective Software =
There are many programs out there to scan for and prevent malware, spyware, adware, virii and trojans. I highly recommend Spybot Search & Destroy (http://security.kolla.de/), Ad-Aware (http://www.lavasoftusa.com/software/adaware/) and AVG Anti-virus (http://www.grisoft.com/) as a first line of defense. These are all free programs that are some of the top available and I recommend you download, install, update and scan with these programs. I recommend running, updating and scanning with these programs at least once per week. These programs are designed to get rid of what you might have let through your browser, email client or firewall. Also, when you’ve downloaded a zip file, executable or whatever; right click it and scan it with whatever anti-virus program you have installed.
= Secure Services and Startup Programs =
I highly recommend running the registry editor (regedit.exe, from Start->Run) and browsing to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run. There will be a listing of startup programs on the right side of this window and I suggest deleting every one of them that isn’t absolutely, solidly required for something. When I’m cleaning up a friend’s computer, the first thing I do is go right to this and delete every single one of them. There’s nothing to my knowledge besides maybe cd-rom/dvd-rom/storage virtual drive emulators that have anything that is a must requirement to startup.
The next steps to perform would be running the services control center. This can be done by running services.msc from the Start->Run prompt. This presents you with a window listing of every service that windows, anti-virus, firewalls or drivers use in the background that you were never really aware. This website (http://www.theeldergeek.com/services_guide.htm) provides a lot of information about services and has a list of all the services and details about what they really are. For security and performance, I suggest disabling the following services:
ClipBook
Fast User Switching
Indexing Service
Machine Debug Manager (unless you’re a programmer)
NetMeeting Remote Desktop Sharing
Portable Media Serial Number Service (unless you have a laptop or something)
Remote Registry
Security Center
Smart Card (unless you use them)
TCP/IP NetBIOS Helper
Telnet
Terminal Services
Windows Firewall/Internet Connection Sharing (ICS)
Windows Time
To disable a service, double click it, change the startup type to disabled, apply, ok. These changes should not only improve your security but also your performance as they won’t be using processor cycles or memory any longer.
= Update Your Operating System =
I recommend running windows update once a week (http://windowsupdate.microsoft.com/). Download any updates listed in any of the categories, there are exceptions to this. Don’t download the Microsoft Malicious Software protection update, it’s been known to conflict and be useless. Don’t download any hardware updates, get these directly from their respected websites of manufacturers. Don’t download Windows Media Player 10 or any updates to it, unless you use it as it is a large target.


