HOEI

Windows Security Status

October 19th, 2007

When ranking the security status of a PC on a scale from 1 to 5, with 5 being the most vulnerable, this PC ranks an 87.

Windows Update Screen Capture

This is a screen capture from the Windows Update site for one of my laptops shortly after installing Windows XP Professional and adding Service Pack 2.  Choosing to ignore these updates leaves a PC very open to attacks especially if the machine has not anti-virus software and a firewall is not running.

Visiting the Windows Update site is a good first step to securing a PC.  There are a few other things that I would highly recommend when building or buying a new PC.

  1. Purchase and install an enterprise grade anti virus application and subscribe to automatic signature and software upgrades.
  2. Install a client based firewall application, especially if you will be connecting to public networks.
  3. Use VPN software and SSL (https) web sites as much as possible when on public WiFi. (more HOWTO details to come on this subject)
  4. Update your other third party applications on Windows regularly and enable automatic updates where possible. (i.e., iTunes, QuickTime Viewer, Java run-time, etc.)
  5. Verify that your PC is not trying to automatically reconnect to Windows Network shares at logon.

I can not impress upon you bloggers how important number three is for those of you who frequently log onto your blog software via http (tcp port 80) over a public wireless access point from a hotel, coffee shop, or your favorite lunch location.  The software to enable a hacker with the capability to capture your user ID and passwords over a public access point is widely available and very easy to use.   The same from utilities can be used to capture unencrypted passwords used when accessing email, ftp servers, and web site control panels.

1 Comment »

  1. vicrider6 says

    SSL is great, but what about all the applications that are not SSL enabled. Look at these guys, surfbouncer.com. They are not free, but if you use wifi networks you need some type of security. They encrypt all your traffic so even without an SSL connection your traffic is safer.

    October 20th, 2007 | #

Leave a comment

:mrgreen: :neutral: :twisted: :shock: :smile: :???: :cool: :evil: :grin: :oops: :razz: :roll: :wink: :cry: :eek: :lol: :mad: :sad:


Subscribe without commenting

RSS feed for these comments. | TrackBack URI

Feed Icon
Subscribe to our feed.

What's a feed?

Enter your email address:

Delivered by FeedBurner




Blogging Blogs - BlogCatalog Blog Directory