Computing.Net > Forums > Security and Virus > security experts needed! =(

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

security experts needed! =(

Reply to Message Icon

Original Message
Name: nuzzy
Date: July 22, 2006 at 22:41:00 Pacific
Subject: security experts needed! =(
OS: windows 2000
CPU/Ram: n/a
Model/Manufacturer: n/a
Comment:

Hello, All...

I have some questions with regard to security in windows 2000 (in general... any windows 2000 machine). =) I would really appreciate some insight from anyone who knows network security better than myself. I know I am asking a lot of questions, and it may seem lazy, but I promise that if I find the answer myself later, I will answer myself!

So, here we go...

Are any of the following definately a security risk or definite evidence of an intrusion?

1) If the access permission to the "c:\Documents and Settings\Administrator\My Documents" folder is set to only allow access to the administrator of the machine (not to be confused with administratorS plural), is there any circumstance where this can be reset to the default (several users allowed access, including "everyone") by anyone other than the administrator of the machine?

2) A directory exists, c:\documents and settings\[computer name here] and was not explicitly created by any user of the machine. I think this might have something to do with ASP net?

3) In the directory, C:\Documents and Settings\Administrator\Local Settings\, there is a directory called "History" which contains objects (not folders) named "3 weeks ago", "2 weeks ago", "last week", "Monday", "Tuesday", etc... and these objects contain urls visited and file access under a subfolder named "My Documents". All users other than administrator do not have this in their directories. They only contains another subfolder: ...\History\History.IE5.

4) The followings (unconnected at this moment) connections are present:

(PROCESS,PROTOCOL,LOCAL,REMOTE,STATUS)

explorer.exe:1508 UDP usa-fnn4uo0bkye:1808 *:*

LSASS.EXE:248 UDP usa-fnn4uo0bkyf:isakmp *:*

LSASS.EXE:248 UDP usa-fnn4uo0bkyf:4500 *:*

mstask.exe:780 TCP usa-fnn4uo0bkyf:1025 usa-fnn4uo0bkyf:0 LISTENING

svchost.exe:420 TCP usa-fnn4uo0bkyf:epmap usa-fnn4uo0bkyf:0 LISTENING

System:8 TCP usa-fnn4uo0bkye:microsoft-ds usa-fnn4uo0bkyf:0
LISTENING

System:8 TCP usa-fnn4uo0bkyf:netbios-ssn usa-fnn4uo0bkyf:0 LISTENING

System:8 UDP usa-fnn4uo0bkyf:microsoft-ds *:*

System:8 UDP usa-fnn4uo0bkyf:netbios-ns *:*

System:8 UDP usa-fnn4uo0bkyf:netbios-dgm *:*

5) Yahoo Messenger fails to sign on despite internet connectivity in every other respect, and in add/remove programs, there are two entries, "Yahoo Messenger" and "Get Yahoo Messenger." The applications are of similar size but not identical. The uninstall of "Get Yahoo Messenger" is relatively quick compared to "Yahoo Messenger."

General questions:

A) In the properties for any event log (app, security, system), you can set max file size, and also set the expiration length... the default is 512k, and 7 days long. Why would the event logs span more that 7 days? Does the filesize take precedence?

B) If file and printer sharing is disabled in TCP/IP properties, does that mean that it is impossible to remotely access file shares whether or not folders are "shared."?

C) Is there any intrusion technique/transmission that could go undetected by a legit version of TCPview by Sysinternals?

D) Is there such a thing as a root kit that can be implemented from a website? or does it have to be a fake windows 2000 CDROM?

Thanks.


Report Offensive Message For Removal


Response Number 1
Name: Johnw
Date: July 23, 2006 at 17:29:34 Pacific
Reply: (edit)


Important reading
http://grc.com/su-fixit.htm
http://www.grc.com/su-bondage.htm
http://www.grc.com/su-rebindingnt.htm
http://www.digitalguru.com/dgstore/product.asp?isbn=0072133244&ac_id=76
http://www.nwinternet.com/~pchelp/security/issues/sharing.htm
http://cable-dsl.home.att.net/netbios.htm
http://support.sbcglobal.net/general/features/4589.shtml
http://netsecurity.about.com/library/weekly/aa051600b.htm
http://www.chebucto.ns.ca/~rakerman/trojan-port-table.html
http://www.practicallynetworked.com/sharing/netbeui.htm
http://www.speedguide.net/Cable_modems/cable_security.shtml
http://comcast.comcastonline.com/onlinesecurity/filefaq.asp
http://asia.cnet.com/itmanager/netadmin/0,39006400,39033105,00.htm
http://searchsecurity.techtarget.com/tip/1,289483,sid14_gci811495,00.html
http://www.windowsitlibrary.com/Content/169/02/7.html
http://www.uksecurityonline.com/husdg/windowsxp/wxpp2.php
========================================
http://www.uksecurityonline.com/husdg/windowsxp/wxpp2.php
Shut down unnecessary ports
http://www.uksecurityonline.com/husdg/windowsxp/shutdownports.htm
Close port 445 TCP/UDP by disabling NetBT in Device Manager
http://www.uksecurityonline.com/husdg/windowsxp/close445.htm
Disabling Distributed COM (this gets rid of Port 135)
http://www.uksecurityonline.com/husdg/windowsxp/close135.htm
Clean up your networking bindings (removing File & Print sharing)
http://www.uksecurityonline.com/husdg/windowsxp/cleanbindings.htm
Tightening TCP/IP further (using IPSec)
http://www.uksecurityonline.com/husdg/windowsxp/ipsec.htm
Protecting against Denial of Service Attacks
http://www.uksecurityonline.com/husdg/windowsxp/dos.htm
Restrict access to public Local Security Authority (LSA) information
http://www.uksecurityonline.com/husdg/windowsxp/lsa.htm
Secure XP - A Windows XP Security Guide
http://mywebpages.comcast.net/SupportCD/SecureXP.html
http://www.tweakhound.com/xp/security/page_1.htm
===========================================
Windows Worms Doors Cleaner
http://www.firewallleaktester.com/wwdc.htm
Windows 2000 / XP / 2003 server
==========================================
There are four services associated with lsass.exe and most users (especially home users) do not need any of them running.
They are:
IPSEC services
Net Logon
NT LM Security Support Provider
Protected Storage
Type "services.msc" in run, press Enter and disable them.
I suggest you visit the following URL for complete info:
http://majorgeeks.com/page.php?id=12
http://www.blackviper.com/WinXP/servicecfg.htm
=======================================
If you only want to share a single folder on a network, you can just right click on it, go to “Sharing and Security”, and check the “Share this folder on the network box”. If you want to share numerous folders and set them up easily, do as follows:
1.) Go to “Start?Run” and in the command prompt, enter “shrpubw.exe”. Hit enter.
2.) When the new Window pops up, hit “Next”.
3.) Now you will be given many options as to how you want your folder set up. Go through all of the options and choose the settings you want.
=========================================
ShareWatch
http://stevemiller.net/sharewatch/
=======================================
Configure NT-services securely - for Windows 2000 & XP
http://www.ntsvcfg.de/ntsvcfg_eng.html
=====================================
Surf the Internet Safely
http://surfthenetsafely.com/
===================================
RootKit Hook Analyzer
http://www.resplendence.com/hookanalyzer
RootkitRevealer
http://www.sysinternals.com/utilities/rootkitrevealer.html
http://www.sysinternals.com/Files/RootkitRevealer.zip
http://www.sixfiles.com/dbase/files/sysinternals-rootkitrevealer.html
========================================
NetDetox ( uses the host file method )
http://www.netdetox.com/
95/98/NT/ME/2000/XP/2003
Never see another ad again Blocks unwanted pop-ups Prevent infection by spyware Surf Faster Fully Compatible with Windows 95 or later Automatic Free Updates. Prevents spyware infection and stops spyware from phoning home Blocks ads and unwanted pop-ups No configuration required - just install and then let it work its magic Automatically downloads updates silently in the background.


Report Offensive Follow Up For Removal







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home








Do you own an iPhone?

Yes
No, but soon
No


View Results

Poll Finishes In 7 Days.
Discuss in The Lounge
Poll History




Data Recovery Software