Slashdot Mirror


NIST Issues Windows XP Security Guide

routerwhore writes "NIST Special Publication 800-68 (zip file) has been created to assist IT professionals, in particularly Windows XP system administrators and information security personnel, in effectively securing Windows XP systems. It discusses Windows XP and various application security settings in technical detail."

11 of 253 comments (clear)

  1. Re:50% by Mz6 · · Score: 3, Insightful
    "Fifty percent of those problems are IE problems."

    Does this get filed the same as "90% of all statistics are made up"?

    --
    Hmmm.
  2. Re:Step one by Marxist+Hacker+42 · · Score: 3, Insightful

    And the answer is simple- hook it up to a Linux-based NAT router! If no server ports are exposed to the WAN, no worms can find the new box.

    --
    SJW: a person who perceives an injustice, and while correcting it, commits a greater injustice.
  3. Re:Page 1: For best security... by xOleanderx · · Score: 4, Insightful

    Hopefully SP2 will fix many of these problems.

  4. Re:Step one by crimethinker · · Score: 4, Insightful
    You're only partly correct. If you put the windoze box behind a NAT, you won't get 0WN3D by all of the remote exploits, but that's only half of the solution. You're still vulnerable to virus-laden e-mails (especially if you use MS Outhouse) and malicious web pages (if you use IE).

    Yes, you and I have a clue and use something else for mail and web, but most home users are not savy enough to switch away from the vulnerable products, and worms and viruses will continue to spread through these channels for some time to come.

    -paul

    --
    Pistol caliber is like religion: everyone has their favourite, and theirs is the only right choice.
  5. Reminds me of Bastille linux by mentatchris · · Score: 5, Insightful

    I just briefly read thru that document. It is an excellent read. Lots of the things they mention are fairly well known, but to have it all grouped together in a comprehensive document is a real godsend. Reminds me A LOT of bastille linux .
    There is a huge advantage to have predefined profiles you can apply. I imagine myself using these security profiles to harden family member's PCs. I usually have neither the time nor the inclination to lock down my mother's computer.... so having some defaults and a quick checklist will save me a TON of time in the long run.
    It's also nice to be able to send someone a link and tell them "Do this stuff" rather than walk them thru all the things they need to do to be safe. As I am sure most Slashdot readers have experienced, the unending number of tech calls from friends and family gets old after a little while. I think this document will help restore the free time that Uncle Bill has taken from me.

  6. Re:50% by Pharmboy · · Score: 5, Insightful

    You're in IT? Notify the upper-management about the best tools available then implement those tools. If you can't make a reasonable argument why Windows is a hazard than get another career and move over for someone that can. It is POSSIBLE.

    IT departments are the problem and Windows will be the dominant OS for decades to come until more IT "men" grow some balls.


    HA! Just ask the boss for money and he gives it to you? Thats rich. So, if windows allows an email client to arbitrarily execute code in an email, its the IT depts fault? If Windows IIS allows you to run code by simply sending a malformed URL, its the IT depts fault? So, the solution is buy yet more software, that will not know about these exploits until they are exposed anyway, so is useless for unknown (but will be discovered) vulnerabilities?

    And MS is the good guy and the IT guys are the bad guys, because all they have to do is go spend a bunch of money to secure an operating system they already paid alot of money for? And if the company is dependent on software that will only run on Windows for a year or two, its the IT depts fault if the boss won't change to Linux?

    I gotta admit, I did enjoy the "grow some balls", coming from an AC. You sound more like a pissed off 20 year old who just finished a program at Devry and can't believe someone won't hire him for $80k.

    --
    Tequila: It's not just for breakfast anymore!
  7. Re:isolate by eean · · Score: 3, Insightful

    At my .edu they decided that our firewall would protect us from Blaster. Didn't take them long to figure out how wrong they were.

    Firewalls assume they're aren't malicious things happening on your side of it.

  8. How to install Windows XP in 5 hours or less by spoonyfork · · Score: 5, Insightful
    From Mark Pilgrim's How to install Windows XP in 5 hours or less:

    1. Back up entire d: drive to iMac upstairs. rsync rocks.
    2. Find Windows XP install disc.
    3. Reboot with Windows XP install disc.
    4. Asked for product activation. Curse Microsoft.
    5. Search my house in vain for my original, 100% legitimate, retail Windows XP box.
    6. Reboot.
    7. Search control panels in vain for a window, dialog, tab, or pane that displays my current product key.
    8. Search Google for "windows xp get current product key".
    9. Find a utility on a cracker web page in Russia that displays the current product key. This is one of the more lame utilities, since most of the good ones allow you to change it. I don't wish to change it; I actually have a perfectly good product key, I just don't know what it is.
    10. Reboot with Windows XP install disc.
    11. Reboot repeatedly as required.
    12. Boot screen. Choose between "Windows XP Professional" and "Windows XP Professional". Brilliant. Pick one. The wrong one. Boot into fucked Windows XP install. Hard reboot. Pick the right one. Make mental note to hack boot.ini later.
    13. "Welcome to Windows XP. You have no useful programs and no internet access. You have 30 days left for activation. Would you like to activate now?" Yes, I would, but I have no internet access.
    14. Unnecessarily loud and cheerful startup noises. Make mental note to turn off all sounds later.
    15. Search the "Network and Internet Connections" wizards in vain for some way to set up my Linksys wireless card. Having never done a clean install of XP (I previously upgraded from Windows 2000), and having been moderately impressed by the new wireless networking features in XP, I naively assumed this would "just work". Silly rabbit.
    16. Search my house for my Linksys wireless card driver install disc. Find the install disc that came with the old card, that broke and was replaced by the new-and-improved version 3.0 card. Wonder if that will suffice.
    17. Fight with the "Add New Hardware Wizard" trying to install the obviously inferior drivers off this disc.
    18. Wonder where the "Device Manager" is hiding.
    19. Find the "Device Manager". Right-click on the unknown device, "Linksys_Instant_Wireless_Card". Update driver. "Windows was unable to locate a driver for this device. Would you like to search on the internet?" Yes, I'd love to, but I can't, you moron. Install driver from specific location. Specify WIN2000 folder on old-and-inferior install disc.
    20. "This driver is not digitally signed." OK.
    21. "This driver may cause your computer to become unstable." OK.
    22. "This driver may anally rape your mother while pouring sugar down your gas tank." OK.
    23. Nothing. No connection, no internet access, no acknowledgment of any device whatsoever.
    24. Reboot.
    25. Doesn't work.
    26. "Take a tour of Windows XP!" I am.
    27. Reboot.
    28. Doesn't work.
    29. Dig out old wired PCMCIA card. Take computer upstairs. Plug directly into switch. cmd. ipconfig. We have an IP address. ping www.google.com. We have name resolution and internet access.
    30. Fire up Internet Explorer. runonce.msn.com. No. www.linksys.com. Support. Downloads. WPC11. Windows XP. Linksys.com rocks.
    31. Insert Linksys wireless card.
    32. Back to Device Manager.
    33. Uninstall old-and-inferior driver.
    34. Update driver.
    35. "This driver is not digitally signed." OK.
    36. "This driver may cause your computer to become unstable." OK.
    37. "This driver may…" OK.
    38. cmd. ipconfig. We have internet access.
    39. "Add your .NET Passport to Windows XP!" No.
    40. Fire up Internet Explorer. www.msn.com. No. www.mozilla.org. Download Mozilla.
    41. Realize I should create an "f8dy" user because it will make my life easier later.
    42. Create "f8dy" as an administrator. Log out. Log in.
    43. Install Mozilla. Yes, I would like to make you my default

    --
    Speak truth to power.
  9. Missing step 148. by Tenebrious1 · · Score: 3, Insightful

    147. Search Google for "apache 2.0 win32?. Download. Install. Copy and paste custom stuff into httpd.conf. Restart Apache service.

    148. GHOST MACHINE. Never have to reinstall again.

    --
    -- If god wanted me to have a sig, he'd have given me a sense of humor.
  10. NSA's guide or NIST's? by Danathar · · Score: 3, Insightful

    Since NSA already has a guide for Securing WinXP...which part of the government is authoritative on recommendations?

    Here is the link to the page for NSA's Windows XP security Guide (And others)

    http://www.nsa.gov/snac/downloads_winxp.cfm?Menu ID =scg10.3.1.1

  11. Re:Obvious by Kjella · · Score: 4, Insightful

    2. I don't run executable content I get through email unless I know the source and am expecting the file. Outlook has not auto run scripts in years now. (...) The other is that I don't download software of dubious origin.

    Last I checked, IE ran executable code automagically due to a buffer overflow late last year, not sure if there are any such bugs this year.

    Anyway, I realize what you're trying to say but it is still a poor situation. It's like saying "Yeah, I drive a crappy and hazardous car with poor brakes, but I'm a good driver and drive defensively so I don't get into any accidents anyway."

    And regardless of how obvious it may seem to you, it is not common sense. It's your computer knowledge. Don't confuse common sense with logic. It is logical to you because you know how a computer works. It is not logical to a person that doesn't know what's ihside that beige box, and has no idea what an OS is or does. And that really have no idea what is nor should be happening when they open a file.

    People have no clue what makes up a "dubious" origin. Hell, RealPlayer counts as dubious in my book (once a villain, always a villain), while an OSS project who has no corporate backing, not knowing any of the coders, is usually less dubious. How do you know which are reputable companies? Knowledge, which implies that it is not common sense.

    Kjella

    --
    Live today, because you never know what tomorrow brings