Steps you have taken to secure your computer(s)
Moderator: Thanas
Steps you have taken to secure your computer(s)
List them here:
My computer [Debian Linux "Sid"]:
Don't use Windows
Set up iptables to filter traffic
Tweaked permissions
My Dad's computer [Win2K SP4]
Forced everyone to be restricted user- programs can be run if one manually adjusts permissions- Ground Control appears to run fine.
Hid all IE icons and cranked up security to "High".
Computer's internet access is via my Linux computer via NAT.
Use Firefox
Attempted to disable write to C:\ - unsuccessful since this disables the recycle bin for all users - probably not a real improvement in security, but I'm used to / being non-world writable.
I don't have antivirus or spyware software though or spyware detection, but I'm sure it's pretty safe since no one moves executables around on disk- stuff download on the internet is a different matter, but I have never gotten any viruses when using downloaded stuff... most of the stuff is from trustworthy places anyway, so unless the server gets cracked... Downloading AV software is too slow and bothersome, and I have never been infected with a virus except for CIH when it came on a CD-ROM that had... um... software of questionable origin *wink wink*.
Computer is unpatched- too bothersome over dialup (26.4kbps shared between 4 computers)... will need to do that some time in the future- for now it seems safe behind NAT.
Administrator is almost never used- I use runas on Windows Explorer as the Windows equivalent of 'su'
My sister's computer [Windows NT 4 SP4]:
Still need to upgrade to SP6 or something...
Internet Explorer not used (forgot to adjust security settings, but will do so later)
Everyone forced to be a restricted user
Otherwise no steps taken.
There's probably more I should do, so what should I do, that doesn't involve downloading something...
My computer [Debian Linux "Sid"]:
Don't use Windows
Set up iptables to filter traffic
Tweaked permissions
My Dad's computer [Win2K SP4]
Forced everyone to be restricted user- programs can be run if one manually adjusts permissions- Ground Control appears to run fine.
Hid all IE icons and cranked up security to "High".
Computer's internet access is via my Linux computer via NAT.
Use Firefox
Attempted to disable write to C:\ - unsuccessful since this disables the recycle bin for all users - probably not a real improvement in security, but I'm used to / being non-world writable.
I don't have antivirus or spyware software though or spyware detection, but I'm sure it's pretty safe since no one moves executables around on disk- stuff download on the internet is a different matter, but I have never gotten any viruses when using downloaded stuff... most of the stuff is from trustworthy places anyway, so unless the server gets cracked... Downloading AV software is too slow and bothersome, and I have never been infected with a virus except for CIH when it came on a CD-ROM that had... um... software of questionable origin *wink wink*.
Computer is unpatched- too bothersome over dialup (26.4kbps shared between 4 computers)... will need to do that some time in the future- for now it seems safe behind NAT.
Administrator is almost never used- I use runas on Windows Explorer as the Windows equivalent of 'su'
My sister's computer [Windows NT 4 SP4]:
Still need to upgrade to SP6 or something...
Internet Explorer not used (forgot to adjust security settings, but will do so later)
Everyone forced to be a restricted user
Otherwise no steps taken.
There's probably more I should do, so what should I do, that doesn't involve downloading something...
ah.....the path to happiness is revision of dreams and not fulfillment... -SWPIGWANG
Sufficient Googling is indistinguishable from knowledge -somebody
Anything worth the cost of a missile, which can be located on the battlefield, will be shot at with missiles. If the US military is involved, then things, which are not worth the cost if a missile will also be shot at with missiles. -Sea Skimmer
George Bush makes freedom sound like a giant robot that breaks down a lot. -Darth Raptor
Re: Steps you have taken to secure your computer(s)
Bought a Mac.Pu-239 wrote:List them here:
My computer [Debian Linux "Sid"]:
Don't use Windows
Set up iptables to filter traffic
Tweaked permissions
My Dad's computer [Win2K SP4]
Forced everyone to be restricted user- programs can be run if one manually adjusts permissions- Ground Control appears to run fine.
Hid all IE icons and cranked up security to "High".
Computer's internet access is via my Linux computer via NAT.
Use Firefox
Attempted to disable write to C:\ - unsuccessful since this disables the recycle bin for all users - probably not a real improvement in security, but I'm used to / being non-world writable.
I don't have antivirus or spyware software though or spyware detection, but I'm sure it's pretty safe since no one moves executables around on disk- stuff download on the internet is a different matter, but I have never gotten any viruses when using downloaded stuff... most of the stuff is from trustworthy places anyway, so unless the server gets cracked... Downloading AV software is too slow and bothersome, and I have never been infected with a virus except for CIH when it came on a CD-ROM that had... um... software of questionable origin *wink wink*.
Computer is unpatched- too bothersome over dialup (26.4kbps shared between 4 computers)... will need to do that some time in the future- for now it seems safe behind NAT.
Administrator is almost never used- I use runas on Windows Explorer as the Windows equivalent of 'su'
My sister's computer [Windows NT 4 SP4]:
Still need to upgrade to SP6 or something...
Internet Explorer not used (forgot to adjust security settings, but will do so later)
Everyone forced to be a restricted user
Otherwise no steps taken.
There's probably more I should do, so what should I do, that doesn't involve downloading something...
Don't use IE.
As for the Windows PC's, I've installed FireFox on all of them and have my router firewall protecting all but one (mine), which is allowed via DMZ for games.
- Uraniun235
- Emperor's Hand
- Posts: 13772
- Joined: 2002-09-12 12:47am
- Location: OREGON
- Contact:
- 2000AD
- Emperor's Hand
- Posts: 6666
- Joined: 2002-07-03 06:32pm
- Location: Leeds, wishing i was still in Newcastle
Since the only threat is my sodding brother i've set up a crappy limited acount for him and passworded my Admin account with a 20 character.
By my calculation there's 1.887e39 different combination there.
Let's see the bitch crack that motherfucker!
By my calculation there's 1.887e39 different combination there.
Let's see the bitch crack that motherfucker!
Ph34r teh eyebrow!!11!Writers Guild Sluggite Pawn of Chaos WYGIWYGAINGW so now i have to put ACPATHNTDWATGODW in my sig EBC-Honorary Geordie
Hammerman! Hammer!
Hammerman! Hammer!
- Brother-Captain Gaius
- Emperor's Hand
- Posts: 6859
- Joined: 2002-10-22 12:00am
- Location: \m/
I salute you sir. Effort sucks.Uraniun235 wrote:I'm not motivated enough to put real effort into security.
As for myself, pretty much the same. ZoneAlarm, occasional spyware/virus scans, Firefox... not much else.
Agitated asshole | (Ex)40K Nut | Metalhead
The vision never dies; life's a never-ending wheel
1337 posts as of 16:34 GMT-7 June 2nd, 2003
"'He or she' is an agenderphobic microaggression, Sharon. You are a bigot." ― Randy Marsh
The vision never dies; life's a never-ending wheel
1337 posts as of 16:34 GMT-7 June 2nd, 2003
"'He or she' is an agenderphobic microaggression, Sharon. You are a bigot." ― Randy Marsh
- Lord Pounder
- Pretty Hate Machine
- Posts: 9695
- Joined: 2002-11-19 04:40pm
- Location: Belfast, unfortunately
- Contact:
For my sins i bought not 1 but 2 editions of Windows XP Pro. One for my computer and one for the family computer. On each computer i have the Windows Firewall and Norton Internet Security installed. I also deleted IE of each computer and installed Mozilla. Also my sister is under orders that if any virus gets onto the family computer she will suffer in ways that will give me nightmares. My brother is just a dumbass and we don't allow him near the computer much.
RIP Yosemite Bear
Gone, Never Forgotten
Gone, Never Forgotten
Just don't let him get physical access whilst your user's logged in, or he could create a Password Reset Disk.2000AD wrote:Since the only threat is my sodding brother i've set up a crappy limited acount for him and passworded my Admin account with a 20 character.
By my calculation there's 1.887e39 different combination there.
Let's see the bitch crack that motherfucker!
- General Zod
- Never Shuts Up
- Posts: 29211
- Joined: 2003-11-18 03:08pm
- Location: The Clearance Rack
- Contact:
- 2000AD
- Emperor's Hand
- Posts: 6666
- Joined: 2002-07-03 06:32pm
- Location: Leeds, wishing i was still in Newcastle
I seriously doubt he knows how to do that, but even so i don't let him on on my account anyway.Vendetta wrote:Just don't let him get physical access whilst your user's logged in, or he could create a Password Reset Disk.2000AD wrote:Since the only threat is my sodding brother i've set up a crappy limited acount for him and passworded my Admin account with a 20 character.
By my calculation there's 1.887e39 different combination there.
Let's see the bitch crack that motherfucker!
Ph34r teh eyebrow!!11!Writers Guild Sluggite Pawn of Chaos WYGIWYGAINGW so now i have to put ACPATHNTDWATGODW in my sig EBC-Honorary Geordie
Hammerman! Hammer!
Hammerman! Hammer!
-
- Fucking Awesome
- Posts: 13834
- Joined: 2002-07-04 03:21pm
Well...my laptop has a password...
Which, considering that it isn't hooked up to the 'Net yet, is more than enough.
Which, considering that it isn't hooked up to the 'Net yet, is more than enough.
The End of Suburbia
"If more cars are inevitable, must there not be roads for them to run on?"
-Robert Moses
"The Wire" is the best show in the history of television. Watch it today.
"If more cars are inevitable, must there not be roads for them to run on?"
-Robert Moses
"The Wire" is the best show in the history of television. Watch it today.
My linux computer is the only one secured with proper passwords- the other PCs use blank passwords- I keep "sensitive" stuff on my computer though. However, my web accounts all have the same passwords, except yahoo and this board, which is hazardous in case some corrupt employee looks through one and uses that on all other sites. I've been too lazy to change passwords, since I can't think of something both easy to remember and short enough to type in on a regular basis. My GPG passphrase and shell account passphrase are similar, except for words in the passphrase shifted slightly, which needs to be rectified. The shell account password really is insecure though, since the server only pays attention to the first 8 characters, resulting in a password easily subject to a dictionary attack (I filed a bug, but it's probably not going to be fixed).
ah.....the path to happiness is revision of dreams and not fulfillment... -SWPIGWANG
Sufficient Googling is indistinguishable from knowledge -somebody
Anything worth the cost of a missile, which can be located on the battlefield, will be shot at with missiles. If the US military is involved, then things, which are not worth the cost if a missile will also be shot at with missiles. -Sea Skimmer
George Bush makes freedom sound like a giant robot that breaks down a lot. -Darth Raptor
I got rid of IE and now use Mozilla, I always make certain my firewall and antivirus is up to date, and I also use SpyBot and AdAware to remove any unwanted spyware and adbots.
The M2HB: The Greatest Machinegun Ever Made.
HAB: Crew-Served Weapons Specialist
"Making fun of born-again Christians is like hunting dairy cows with a high powered rifle and scope." --P.J. O'Rourke
"A man who has nothing for which he is willing to fight, nothing which is more important than his own personal safety, is a miserable creature and has no chance of being free unless made and kept so by the exertions of better men than himself." --J.S. Mill
HAB: Crew-Served Weapons Specialist
"Making fun of born-again Christians is like hunting dairy cows with a high powered rifle and scope." --P.J. O'Rourke
"A man who has nothing for which he is willing to fight, nothing which is more important than his own personal safety, is a miserable creature and has no chance of being free unless made and kept so by the exertions of better men than himself." --J.S. Mill
-
- What Kind of Username is That?
- Posts: 9254
- Joined: 2002-07-10 08:53pm
- Location: Back in PA
- The Yosemite Bear
- Mostly Harmless Nutcase (Requiescat in Pace)
- Posts: 35211
- Joined: 2002-07-21 02:38am
- Location: Dave's Not Here Man
laughs manically
dude your talking to someone who once disconnected his virus friendly boss from the internet, no I mean physically disconnected/burned his modem, and allowwed him to keep his network card because then the secretaries could monitor his activities, and runfirewalls to prevent him from bringing in any more bugs!
dude your talking to someone who once disconnected his virus friendly boss from the internet, no I mean physically disconnected/burned his modem, and allowwed him to keep his network card because then the secretaries could monitor his activities, and runfirewalls to prevent him from bringing in any more bugs!
The scariest folk song lyrics are "My Boy Grew up to be just like me" from cats in the cradle by Harry Chapin
- Crayz9000
- Sith Apprentice
- Posts: 7329
- Joined: 2002-07-03 06:39pm
- Location: Improbably superpositioned
- Contact:
5 computers running in the house. All on Linux.
1 Freesco firewall/NAT box
1 Mandrake 9.2 webserver (will be upgraded soon)
2 Mandrake 10.0 Official boxen, one for my mom and one for my dad. Both run GNOME 2.4 and Mozilla, and have been tweaked for various things. Both user accounts have somewhat locked down permissions and regular passwords.
1 Mandrake 10.1 (Cooker) box, that one's mine. Never updated less than once a week, sudo is used for most administrative duties, long passwords, etc. iptables and shorewall are enabled.
1 Freesco firewall/NAT box
1 Mandrake 9.2 webserver (will be upgraded soon)
2 Mandrake 10.0 Official boxen, one for my mom and one for my dad. Both run GNOME 2.4 and Mozilla, and have been tweaked for various things. Both user accounts have somewhat locked down permissions and regular passwords.
1 Mandrake 10.1 (Cooker) box, that one's mine. Never updated less than once a week, sudo is used for most administrative duties, long passwords, etc. iptables and shorewall are enabled.
A Tribute to Stupidity: The Robert Scott Anderson Archive (currently offline)
John Hansen - Slightly Insane Bounty Hunter - ASVS Vets' Assoc. Class of 2000
HAB Cryptanalyst | WG - Intergalactic Alliance and Spoof Author | BotM | Cybertron | SCEF
John Hansen - Slightly Insane Bounty Hunter - ASVS Vets' Assoc. Class of 2000
HAB Cryptanalyst | WG - Intergalactic Alliance and Spoof Author | BotM | Cybertron | SCEF
- Gandalf
- SD.net White Wizard
- Posts: 16363
- Joined: 2002-09-16 11:13pm
- Location: A video store in Australia
We have one shared computer in the house, running Windows.
I password my login with 12 numbers and a LoTE word. Good luck cracking it.
I password my login with 12 numbers and a LoTE word. Good luck cracking it.
"Oh no, oh yeah, tell me how can it be so fair
That we dying younger hiding from the police man over there
Just for breathing in the air they wanna leave me in the chair
Electric shocking body rocking beat streeting me to death"
- A.B. Original, Report to the Mist
"I think it’s the duty of the comedian to find out where the line is drawn and cross it deliberately."
- George Carlin
That we dying younger hiding from the police man over there
Just for breathing in the air they wanna leave me in the chair
Electric shocking body rocking beat streeting me to death"
- A.B. Original, Report to the Mist
"I think it’s the duty of the comedian to find out where the line is drawn and cross it deliberately."
- George Carlin
- EmperorMing
- Sith Devotee
- Posts: 3432
- Joined: 2002-09-09 05:08am
- Location: The Lizard Lounge
Hardware router/firewall
All 3 boxes running:
Win2000 with the latest patches;
Protowall with the latest blocklist;
Software firewall (Sygate);
AVG antivirus;
Spyguard popup stopper (or whatever);
Spybot 1.3 and Ad Aware for manual scans;
I also run HouseCall antivirus every now and again;
Mozilla Firefox for a browser.
All 3 boxes running:
Win2000 with the latest patches;
Protowall with the latest blocklist;
Software firewall (Sygate);
AVG antivirus;
Spyguard popup stopper (or whatever);
Spybot 1.3 and Ad Aware for manual scans;
I also run HouseCall antivirus every now and again;
Mozilla Firefox for a browser.
DILLIGAF: Does It Look Like I Give A Fuck
Kill your God!
I never used a virus scanner until recently. No viruses found. The only thing I've done on a regular basis is running Adaware, and it hasn't caught anything in months. The admin account is what I use in XP. No need for user accounts.
Most security issues come from people being fucking dumbasses with their computers. That's why my brother's, mom's and other peoples' computers are filled to the brim with viruses and retardware, while mine isn't and never has been.
The only constant security I have is my firewall/router.
Most security issues come from people being fucking dumbasses with their computers. That's why my brother's, mom's and other peoples' computers are filled to the brim with viruses and retardware, while mine isn't and never has been.
The only constant security I have is my firewall/router.
"Right now we can tell you a report was filed by the family of a 12 year old boy yesterday afternoon alleging Mr. Michael Jackson of criminal activity. A search warrant has been filed and that search is currently taking place. Mr. Jackson has not been charged with any crime. We cannot specifically address the content of the police report as it is confidential information at the present time, however, we can confirm that Mr. Jackson forced the boy to listen to the Howard Stern show and watch the movie Private Parts over and over again."
- Vohu Manah
- Jedi Knight
- Posts: 775
- Joined: 2004-03-28 07:38am
- Location: Harford County, Maryland
- Contact:
Firewalls enabled on all computers. NAT router setup that handles Comcast connection. No virus scanners (sadly), and no Windows machines (two Macs and a PS2). Only services running on the Macs are FTP (passive FTP never seems to work) and file sharing (for file exchanges). Print server additionally on my computer (only printer in house).
I considered encrypting the home folders, but I don't see why (both machines being desktops).
I considered encrypting the home folders, but I don't see why (both machines being desktops).
“There are two kinds of people in the world: the kind who think it’s perfectly reasonable to strip-search a 13-year-old girl suspected of bringing ibuprofen to school, and the kind who think those people should be kept as far away from children as possible … Sometimes it’s hard to tell the difference between drug warriors and child molesters.” - Jacob Sullum[/size][/align]
I recommend using libtrash for Linux users, to prevent accidental deletion from the command line. Occasionally some commands such as 'at' have problems with it though, so you have to make shell aliases to disable it.
ah.....the path to happiness is revision of dreams and not fulfillment... -SWPIGWANG
Sufficient Googling is indistinguishable from knowledge -somebody
Anything worth the cost of a missile, which can be located on the battlefield, will be shot at with missiles. If the US military is involved, then things, which are not worth the cost if a missile will also be shot at with missiles. -Sea Skimmer
George Bush makes freedom sound like a giant robot that breaks down a lot. -Darth Raptor
- Daltonator
- Reclusive Wanker
- Posts: 383
- Joined: 2003-03-23 03:10pm
- Location: Zelda fanboy heaven
- Contact:
I don't have anything on my computer right cause I don't have internet connection at the moment (this is being posted from campus).
I plan to install some free virus scanner, and use Firefox and Thunderbird like usual. And use the router's NAT and firewall to block whatever ports I need blocked.
I plan to install some free virus scanner, and use Firefox and Thunderbird like usual. And use the router's NAT and firewall to block whatever ports I need blocked.
What's her bust size!?
It's over NINE THOUSAAAAAAAAAAND!!!!!!!!!
It's over NINE THOUSAAAAAAAAAAND!!!!!!!!!