32

10 Deadly Sins of Administrators about Windows Security

Embed Size (px)

DESCRIPTION

More info on http://www.techdays.be

Citation preview

Page 1: 10 Deadly Sins of Administrators about Windows Security
Page 2: 10 Deadly Sins of Administrators about Windows Security

10 Deadly Sinsof Administrators about Windows Security

PaulaJanuszkiewiczCQURE: IT Security Auditor, MVP: Enterprise Security, MCThttp://blogs.technet.com/plwit/ [email protected]

Page 3: 10 Deadly Sins of Administrators about Windows Security

http://facebook.com/MVPpress

http://twitter.com/MVPpress

Follow us on:

MVP-Press Training Course

Planning, Deploying and Managing Microsoft Forefront Threat Management Gateway 2010

Available for online purchase: http://www.mvp-press.com

Page 4: 10 Deadly Sins of Administrators about Windows Security

Agenda

1 2 3

Intruduction

Top 10 Sins: From bottom to top

Summary

Page 5: 10 Deadly Sins of Administrators about Windows Security
Page 6: 10 Deadly Sins of Administrators about Windows Security

Agenda

1 2 3

Intruduction

Top 10 Sins: From bottom to top

Summary

Page 7: 10 Deadly Sins of Administrators about Windows Security

10. Weak

Page 8: 10 Deadly Sins of Administrators about Windows Security
Page 9: 10 Deadly Sins of Administrators about Windows Security
Page 10: 10 Deadly Sins of Administrators about Windows Security

DemoWeak Password or… No Password

Page 11: 10 Deadly Sins of Administrators about Windows Security

9. Insecure Internet Browsing

Page 12: 10 Deadly Sins of Administrators about Windows Security

DemoIf you pay peanuts, you get monkeys…?

Page 13: 10 Deadly Sins of Administrators about Windows Security

8. Lack of updates

Page 14: 10 Deadly Sins of Administrators about Windows Security

7. Lack of Encryption

Page 15: 10 Deadly Sins of Administrators about Windows Security

DemoHTTPS Traffic

Page 16: 10 Deadly Sins of Administrators about Windows Security

DemoOffline Access

Page 17: 10 Deadly Sins of Administrators about Windows Security

6. WYSI (NOT) WYG

Page 18: 10 Deadly Sins of Administrators about Windows Security

DemoExplorer.exe

Page 19: 10 Deadly Sins of Administrators about Windows Security

5. Network Monitoring

Page 20: 10 Deadly Sins of Administrators about Windows Security

DemoEvil Website & Sniffing

Page 21: 10 Deadly Sins of Administrators about Windows Security

4. Pirated Software

Page 22: 10 Deadly Sins of Administrators about Windows Security

DemoMalware on Board

Page 23: 10 Deadly Sins of Administrators about Windows Security

3. Lack of Backup Mechanisms

Page 24: 10 Deadly Sins of Administrators about Windows Security

DemoEntryTTL

Page 25: 10 Deadly Sins of Administrators about Windows Security

Entry TTL!

Ouch!

Page 26: 10 Deadly Sins of Administrators about Windows Security

2. Lack of Training

Page 27: 10 Deadly Sins of Administrators about Windows Security

DemoImage Hijacks

Page 28: 10 Deadly Sins of Administrators about Windows Security

1. Lack

of

Documentation

Page 29: 10 Deadly Sins of Administrators about Windows Security

DemoAutoruns

Page 30: 10 Deadly Sins of Administrators about Windows Security

Life without passwords…

10. Weak Passwords

Summary

9. Insecure Internet Browsing

8. Lack of Regular Updates

7. Lack of Encryption

6. WUSI (NOT) WUG

5. Lack of Network Monitoring

4. Using Pirated Software

Top 10 List

3. Lack of Backup Mechanisms

2. Lack of Training

1. Lack of Documentation

Page 31: 10 Deadly Sins of Administrators about Windows Security

Be Proactive!• Infrastructure must be well documented• Split and rotate tasks between admins• Use the legal code

• Perform periodical checks• Autoruns• Kernel Level Files• Network Traffic• Processes

Sourc

e:

Heard

.Typ

ePa

d.c

om

Page 32: 10 Deadly Sins of Administrators about Windows Security

© 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries.The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.