Protect against external threats

Outside threats (eavesdropping, password guessing, misconfigurations, information slips) are real and many; follow these simple steps to reduce your risk

In a previous column, I revealed how the vast majority of computer security threats facing your environment live on the client side and require end-user involvement. Users have to be socially engineered to click an item on their desktop (an e-mail, a file attachment, a URL, or an application) that they should not have. This is not to say that truly remote exploits aren't a threat. They are.

Remote buffer overflow and DoS attacks remain a serious threat against the computers under your control. Although they are less prevalent than client-side attacks, the idea that a remote attacker can launch a series of bytes against your computers, then gain control over them always brings the greatest fear to administrators and captures the biggest headlines. But there are other sorts of remote attacks against listening services and daemons as well.

A gauntlet of remote exploits

The simplest attack type is the availability of another remote access entry point. Many services and daemons (such as FTP, Telnet, HTTP, SSH, RDP, RLogin) provide the perfect place for malicious hackers to guess logon credentials, either manually, one at a time, or using automated tools such as Hydra. Since most administrators never check their logs and use neither strong passwords nor account lockout mechanisms, it's not all that hard to guess at passwords. Find a remote logon portal and guess away. Even if the password is long and complex, chances are the system doesn't monitor logs, lock out accounts, or force password changes, so the hacker can guess at it for months or years without being detected.

Many services and daemons are subject to MitM (man in the middle) attacks and eavesdropping. Far too many services do not require end-point authentication or use encryption. With eavesdropping, unauthorized parties can learn logon credentials or confidential information.

Inappropriate information disclosure is another threat. It takes only a little Google hacking to scare the crap out of you. You'll find logon credentials in plain view, and it won't be much longer before you find real top-secret and confidential documents.

Many services and daemons are often misconfigured, allowing anonymous privileged access from the Internet. Last year while teaching a class on Google hacking, I found an entire (U.S.) state's health and social welfare database accessible on the Internet, no logon credentials required. It included names, Social Security numbers, phone numbers, and addresses -- everything an identity thief would need to be successful.

Many services and daemons remain unpatched, but exposed to the Internet. Just last week, database security expert David Litchfield found hundreds to thousands of unpatched Microsoft SQL Server and Oracle databases on the Internet unprotected by a firewall. Some did not have patches for vulnerabilities that had been fixed more than three years ago. Some new operating systems are knowingly released with outdated libraries and vulnerable binaries. You can download every patch the vendor has to offer and you're still exploitable.

Join the PC World newsletter!

Error: Please check your email address.

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Roger A. Grimes

InfoWorld
Show Comments

Most Popular Reviews

Latest News Articles

Resources

PCW Evaluation Team

Azadeh Williams

HP OfficeJet Pro 8730

A smarter way to print for busy small business owners, combining speedy printing with scanning and copying, making it easier to produce high quality documents and images at a touch of a button.

Andrew Grant

HP OfficeJet Pro 8730

I've had a multifunction printer in the office going on 10 years now. It was a neat bit of kit back in the day -- print, copy, scan, fax -- when printing over WiFi felt a bit like magic. It’s seen better days though and an upgrade’s well overdue. This HP OfficeJet Pro 8730 looks like it ticks all the same boxes: print, copy, scan, and fax. (Really? Does anyone fax anything any more? I guess it's good to know the facility’s there, just in case.) Printing over WiFi is more-or- less standard these days.

Ed Dawson

HP OfficeJet Pro 8730

As a freelance writer who is always on the go, I like my technology to be both efficient and effective so I can do my job well. The HP OfficeJet Pro 8730 Inkjet Printer ticks all the boxes in terms of form factor, performance and user interface.

Michael Hargreaves

Windows 10 for Business / Dell XPS 13

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Aysha Strobbe

Windows 10 / HP Spectre x360

Ultimately, I think the Windows 10 environment is excellent for me as it caters for so many different uses. The inclusion of the Xbox app is also great for when you need some downtime too!

Mark Escubio

Windows 10 / Lenovo Yoga 910

For me, the Xbox Play Anywhere is a great new feature as it allows you to play your current Xbox games with higher resolutions and better graphics without forking out extra cash for another copy. Although available titles are still scarce, but I’m sure it will grow in time.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?