Saturday, 31 December 2011

Windows Security

The book I read to research this post was Hacking Exposed Windows 3rd edition by Joel Scambray which is an excellent book which I bought from amazon. No matter what you do to secure windows it will never be 100% secure the best you can hope for is to make it as difficult as possible. Microsoft releases security patches on the 2nd tuesday of the month. You must download these. The most common virus problems are when someone hasn't kept their pc upto date & hence made it vulnerable. When you set up a website you shouldn't register your details publicly many hackers use this information. It costs extra to have your web host provide default details but it's worth it. It's worth mentioning that there are websites that provide information like the IP address on any computer & this is very useful to hackers. They can use john the ripper to crack passwords & it's a free program. They can use fakeGINA to crack your log on password & can also remotely reboot your machine. NAT is another password cracker. Netbtscan will hack your bios. Another trick done by hackers is called SQLinjecting & is basically entering SQL statements into a form in the hope it will do something like drop a table. No website with a backend database is totally immune from it. Another trick is to enter nonsense information into a form & again no website is totally immune from that.

No comments:

Post a Comment