Go Back   Wireless and Wifi Forums > News > Newsgroups > alt.computer.security
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
Reply
 
LinkBack Thread Tools Display Modes
  #61 (permalink)  
Old 10-14-2009, 08:00 PM
Todd H.
Guest
 
Posts: n/a
Default Re: Security

Albert <albert.xtheunknown0@gmail.com> writes:

> Todd H. wrote:
>> How is the machine physically secured?

>
> What do you mean by "physically secured"?


Your original post didn't mention if we were talking about a server in
a rack, or under a desk, in an office, in a private residence, etc.
Physical security = who can put their hands on the box. Because if
someone can touch the box, they can own it.

>> Who can, say, get at its USB ports? Console?

>
> Only me.


Then that cuts out a lot of worries about attacks from people with
physical access to the box.

>> What OS is it?

>
> To be Windows 7.
>
>> What else is on the LAN with that computer? What else can initiate
>> any sort of network connection to the computer?

>
> Nothing else.


If it's the only machine on the lan, and that lan is firewalled off
from the Internet, and only getting SAS and AV updates, then indeed
your attack surface is very very small. You can then basically cross
network based attacks off the worry list. And as you dont' have a
user running internet based apps like web browsers chat clients or
peer to peer stuff on it, that cuts out all client-side attacks from
the worry list as well. About all you'd have to worry about is the
security of DNS to the SAS and AV update servers to avoid any arcane
man in the middle rougue update attack that might possibly be
envisioned, but I'd say those odds are quite small.

>> What services are running on the computer? Have they been kept up
>> to date? Do they have unpatched vulnerabilities?

>
> An AV, SAS and probably Sun VirtualBox.
>
>> How is it known that the computer only does those 2 things?

>
> Because I said so.


Sounds like if this is to be Windows 7 and you don't have the OS and
machine together yet, that you don't know exactly what services are
really running on the computer, just what things you plan to put on
the box. So, please, don't be an snide asshole when people are trying
to help you for free.

Technically, "Because I said so" doesn't tell you the same things a
port scan, list of running services pasted into a posting, or network
vulnerability tool would in terms of what you think you know about
what services are being offered by this machine (such as SMBv2 and its
(unpatched by vendor?) vulnerability. Then again we just had a patch
Tuesday so maybe they fixed that big ah-shit with smbv2. At any rate,
the services that are listing turns out to be a moot point since
you're in the very unusual situation of this one box being all alone
on the LAN, therefore the threats to its listening services from other
devices aren't really anything to worry about.

In summary: Your proposed setup seems poised to be a pretty tough
target, if the assumptions you've put forward all turn out accurate.

But I suspect that if this is a single machine in your home(?) all
alone on the LAN, you might be doing some web surfing from it? If so,
then that'd probably be the primary vector for getting infected.

Best Regards,
--
Todd H.
http://www.toddh.net/

Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Latest ISO 27001 Security Newsletter (Issue 19) Published Today Sue Thomas alt.computer.security 0 10-28-2008 03:56 PM
ISO 27000 Security Newsletter - Issue 19 Published Today Sue Thomas comp.security.misc 0 10-28-2008 03:51 PM
Issue 18 of The ISO 27000 Newsletter Released Sue Thomas alt.computer.security 0 05-15-2008 07:59 PM
The ISO 27001 Newsletter: Issue 18 Published Sue Thomas comp.security.misc 0 05-15-2008 07:53 PM
Corrupt NTFS filesystem Citizen Bob alt.comp.hardware 144 11-11-2006 08:38 PM


All times are GMT. The time now is 09:48 AM.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45