Title: Internet Security
1Internet Security Submitted to Professor Mort
Anvari Author Yungeng Qi ID 104293 Date
11/16/2000
2Internet Security
- Internet has become a part of peoples life,
when you are surfing on the internet enjoying
the huge resources, you are also open your door
to rest of the world ! - Today we will address some internet security
holes regarding windows .xx operating system
3Background information
- Nearly 80 percent home computers use windows
operating system.(PC World) - 80 percent of People using internet have
- E-transaction experience(PC world)
- Hundreds of IP address scanners can be
obtained freely via internet(Asmodeus)
4You may have known Denial of Service shutting
down Yahoo Microsoft has been hacked recently
and stolen of latest source code You may not
aware of your computer is also in danger caused
by its operating system.
5Lets look at an experiment
- Visiting http//grc.com to probe my
- DSL-connected windows 98 system.
- The system contains MS personal web
- server internet explorer pc anywhere
- quicken IRC, ICQTelnetFTP.
6Here is the result
Pavilion is at IP 209.244.212.85 is being probed
7Here is my network configuration
8Here are the security holes
- The default File and Printer Sharing by
- NetBIOS NetBEUI protocol.
- Blank logon password
- Too many application software installed
9Two reasons causing security holes
- NetBIOS NetBEIU Vulnerability
- Inappropriate protocol binding
10NetBIOS NetBEIU Vulnerability
- Releasing machine name, volume name
- whenever connection established and
- being asked
- Backward compatibility.
- Allowing anonymous logon.
11Inappropriate protocol binding
12Solutions
Remove Client for Microsoft Networks and its
related file and printer sharing
13Solutions
The improved protocol binding
14Solutions
Beware your other backdoors, such
asPWS IRCICQ,Telnetbrowsers and email
readers. They are also potential security
holes. Try to use logon password, it can delay
attack. Never run executable file from untrusted
email source
15Solutions
Install Internet Firewall software
16Solutions
Turn off the internet access when you do not need
it!
17Questions
Can you tell me what information I can get from
your email sent with MS Outlook Express?
Thank You