![]() ![]() |
Nov 18 2009, 22:10
Post
#61
|
|
|
Newbie
![]() Group: WF Member
Posts: 89
Joined: 22-November 07
From: A discrete point in the space-time continuum...
Member No.: 10,130
|
Another great point by another user from another forums today, for Windows 7 folks (VISTA too, & of course, Windows Server 2008), from a fellow named "AlphaAlien" here -> http://www.hardwaregeeks.com/board/showthr...0440#post410440
(LOL! Oddly, it's one I overlooked from my OWN GUIDE here, that I applied to Windows 2000/XP/Server 2003, but had "overlooked" in my tips about Windows 7 just above, specifically... &, it IS a good idea, + one I ended up "expanding on" so, I have to thank AlphaAlien for "getting the ball rolling" in my brain here, lol, once more so I could suggest his point (one I suggested here again, no less, for the OLDER MS' OS of Windows NT-based ancestry) & expand on it even more... probably wouldn't have done it w/out he, so, credit goes, where credit is due imo). This is a good point too, so... here goes: Open up gpedit.msc (you can do this from the "Windows Start button" (is it STILL called that now, in Windows 7/VISTA etc. I wonder?) & the RUN or search command). In it, follow its left-hand side pane's tree items down THIS path: Computer Configuration Administrative Templates Network Network Connections Windows Firewall Domain Profile (only use this one IF you are not part of a LAN/WAN or connect to them, & you don't need to do some of what is suggested to turn off there - & you can though, if you don't need to do the stuff we're going to 'crank off' here, especially if you are a single system home user) Local Profile (this one users with a single system @ home that's not part of a home LAN should do) NOW, once there? Use the RIGHT-HAND SIDE PANE items of (now quoting our exchange from the URL above, saves me time, & I have programming assignments in JAVA to do so, excuse the use of this DIRECT quote from the URL above): Prevents administrative remote management services. Looks good to me, especially for most folks (which, face it, most folks don't have home "LAN/WAN" setups (mainly people who are way, Way, WAY "into computing" do imo & experience)). Since they're mainly single system users, & @ home (which I found professionally on a job in 2006 that they're the most "abused" typically as well by malware etc. et al) - they're the folks I put this out for mostly, if they want to take the initiative & time to do it is all. They need it the most, from what I've seen, so... here 'tis. As long as you don't perform remote administration tasks? You should probably turn the ability for "remote administration" off as AlphaAlien points out. I'd have to add this point of AlphaAlien's now though: This same idea/technique/tip/trick can also be done for the DOMAIN and LOCAL profiles there too, and, it also points out a couple others to remove, possibly too (such as UPnP, Remote File & Printer Access, Remote Desktop, setting them as DISABLED there, & possibly to even ICMP also (ping basically)) The PING & UDP ones may affect other wares though, so, test @ your leisure on those 2. (Sounds like a good move, as imo @ least, it really supplements cutting off: A.) Server (allows shares) + Workstation (provides SMB services, in services.msc (& an outbound BLOCK rule in the firewall vs. TCP/UDP for PORTS 139 & 445 (this one mainly, will stall this newly surfaced "bug" noted above in Windows 7 & Server 2008)) B.) Terminal Services/Remote Desktops C.) Cutting out Client for MS Networks + File & Print Sharing in your local area network connection (clients & protocols sections) & also NetBIOS over TCP/IP in the WINS section of the local area connection too. D.) Disabling TCP/IP over NetBIOS in services.msc as well E.) "Stalling out share$", via a batch or .cmd file (possibly even a powershell script as well) & I mean, any shares: Even default ones like in the batch above F.) Setting secured ACL's on the filesystem + registry as well via explorer.exe OR cacls possibly, & regedit.exe (Then, your firewall can do the rest, as far as "inbound intrusion attempts" - I don't think there's much other than that to "get ahold of", & even a nullsession attempt ought to be stalled between this, & the secpol.msc work (plus HOSTS & AnalogX's IP Security Policy as well))) Thanks for the solid point AlphaAlien: It got my "wheels rolling" on a couple of others in gpedit.msc (which I did suggest for Windows 2000/XP/Server 2003 already earlier in this guide), but, I overlooked here, so I added on the rest. APK P.S.=> Oh, AlphaAlien: I am going to credit you with this & put your points out, in your name of course, in regards to this setting in Group Policy Editor on the other 20 or so forums I can still edit this post on as well, hope you don't mind (it's a good solid point, & I do credit others where/when/how/why credit is due they, for solid points) - I am not sure if linking to your photo will work or not (depending on where YOU store it that is), so I may have to "expand" the tree items in gpedit.msc manually in text, so... in any event, there you are... apk -------------------- "I'm REESE: Sgt. TechComVN38416, assigned to protect you - YOU'VE BEEN TARGETTED, FOR TERMINATION!"
|
|
|
|
![]() ![]() |
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:
|
Lo-Fi Version | Time is now: 21st November 2009 - 00:25 |















Nov 18 2009, 22:10







