How Hard Is It To Hack A Pc

35
How hard is How hard is it it to hack a to hack a PC PC ? ?

Transcript of How Hard Is It To Hack A Pc

Page 1: How Hard Is It To Hack A Pc

How hard is itHow hard is it to hack a PC to hack a PC??

Page 2: How Hard Is It To Hack A Pc

Securing your desktop PCSecuring your desktop PC

using using Windows XP SP2Windows XP SP2

Itai AlmogItai AlmogSoftware development EngineerSoftware development EngineerSecurity Business and Technology UnitSecurity Business and Technology UnitMicrosoft CorporationMicrosoft [email protected]@microsoft.com

Page 3: How Hard Is It To Hack A Pc

AgendaAgenda

The world of hacking is changing

Windows XP SP2

Tips for securing your PC

Page 4: How Hard Is It To Hack A Pc

The World of Hacking is ChangingThe World of Hacking is Changing

Number of attacks is increasing

Hackers are getting smarter

Motivation: pride money

Worms & Viruses aremore sophisticated

Looks Familiar?Looks Familiar?

Page 5: How Hard Is It To Hack A Pc

Microsoft is ChangingMicrosoft is Changing

Security is our No. 1 priority!Security is our No. 1 priority!

Secure by Secure by designdesignCode inspectionCode inspection

Threat modelingThreat modeling

Penetration testingPenetration testing

Secure by defaultSecure by defaultMost secured configuration out-of-the-boxMost secured configuration out-of-the-box

Reduced attack surfaceReduced attack surface

Page 6: How Hard Is It To Hack A Pc

Infection MethodsInfection MethodsUse opened ports on unsecuredunsecured computers

Not everyone uses a firewall

Via email attachments, Active X, “save&run”Many users fall for these tricks

Exploit vulnerabilities on unpatchedunpatched computersNot everyone installs patches

Not enough time to installDays between patch and Days between patch and

exploitexploit

Sasser

Sasser

151151180180

331331

Blaster

Blaster

Welchia/ Nachi

Welchia/ Nachi

NimdaNimda

2525

SQL Slammer

SQL Slammer

1717

Page 7: How Hard Is It To Hack A Pc

Securing Windows XPSecuring Windows XPMake it more resilient to attacks

Even if updates are not installed!

Make it easier to secureEasier security management

Help the user do what’s right for him

Page 8: How Hard Is It To Hack A Pc

Windows XP Service Pack 2Windows XP Service Pack 2

Page 9: How Hard Is It To Hack A Pc

Windows XP Service Pack 2Windows XP Service Pack 2

Page 10: How Hard Is It To Hack A Pc

Network ProtectionNetwork Protection

New Windows Firewall

Blaster

Blaster Sasser

Sasser

Page 11: How Hard Is It To Hack A Pc

Network ProtectionNetwork ProtectionOn by default!

Boot time security

Exception list

“Shielded” mode

Scope restrictions

Page 12: How Hard Is It To Hack A Pc

Windows FirewallWindows Firewall

Page 13: How Hard Is It To Hack A Pc

Network ProtectionNetwork Protection

Inbound connection alert

Page 14: How Hard Is It To Hack A Pc

Network ProtectionNetwork Protection

Exceptions

Page 15: How Hard Is It To Hack A Pc

Network ProtectionNetwork Protection

Per interface policy

Page 16: How Hard Is It To Hack A Pc

Network ProtectionNetwork ProtectionGroup policy

Page 17: How Hard Is It To Hack A Pc

Network ProtectionNetwork ProtectionRPC & DCOM restrictions ( )

Messenger service is disabledLooks familiar?

Blaster

Blaster

Page 18: How Hard Is It To Hack A Pc

Windows XP Service Pack 2Windows XP Service Pack 2

Page 19: How Hard Is It To Hack A Pc

IE Security EnhancementsIE Security Enhancements

Pop-up blocker

Page 20: How Hard Is It To Hack A Pc

IE Security EnhancementsIE Security EnhancementsAdd on manager

Page 21: How Hard Is It To Hack A Pc

Information bar Information bar Pop-up blockerPop-up blockerAdd on managerAdd on manager

Page 22: How Hard Is It To Hack A Pc

IE Security EnhancementsIE Security EnhancementsCrash detection

Windows restrictions

Local zone lockdown

Zone elevation block

Page 23: How Hard Is It To Hack A Pc

Windows XP Service Pack 2Windows XP Service Pack 2

Page 24: How Hard Is It To Hack A Pc

Email & IM EnhancementsEmail & IM EnhancementsBlock unsafe Email & IM attachments(using AES)

Page 25: How Hard Is It To Hack A Pc

Email & IM EnhancementsEmail & IM EnhancementsBlock external html content

Page 26: How Hard Is It To Hack A Pc

Windows XP Service Pack 2Windows XP Service Pack 2

Page 27: How Hard Is It To Hack A Pc

Buffer Overrun ProtectionBuffer Overrun ProtectionWindows XP Service Pack 2 binaries are hardened (/GS)

“No Execute” (NX) hardware level protection

Page 28: How Hard Is It To Hack A Pc

Windows XP Service Pack 2Windows XP Service Pack 2

Page 29: How Hard Is It To Hack A Pc

Simplified ManagementSimplified Management

Windows Security Center

Page 30: How Hard Is It To Hack A Pc

Simplified ManagementSimplified ManagementNew Windows Update (ver 5.0)

Page 31: How Hard Is It To Hack A Pc

Before Service Pack 2Before Service Pack 2

Blaster

Blaster

Page 32: How Hard Is It To Hack A Pc

After Service Pack 2After Service Pack 2No ExecuteNo Execute

Lower PrivilegeLower PrivilegeWindows UpdatesWindows Updates

RPC RestrictionsRPC RestrictionsFirewallFirewall

Blaster

BlasterBlaster

Blaster

Page 33: How Hard Is It To Hack A Pc

Use a firewallUse a firewallUse a firewallUse a firewall

Update Windows and applicationsUpdate Windows and applicationsUpdate Windows and applicationsUpdate Windows and applications

Don’t open unsafe attachmentsDon’t open unsafe attachmentsDon’t open unsafe attachmentsDon’t open unsafe attachments

Use an Anti-Virus softwareUse an Anti-Virus softwareUse an Anti-Virus softwareUse an Anti-Virus software

Don’t install unsafe ActiveXDon’t install unsafe ActiveXDon’t install unsafe ActiveXDon’t install unsafe ActiveX

Deploy XP Service Pack 2Deploy XP Service Pack 2

What you should doWhat you should do

Page 34: How Hard Is It To Hack A Pc

ResourcesResourcesDownload Windows XP Service Pack 2 RC2www.microsoft.com/technet/prodtechnol/winxppro/sp2preview.mspx

Microsoft Israel Windows XP Service Pack 2 Home Pagewww.microsoft.com/israel/windowsxp/sp2

Windows XP Service Pack 2 - Information for IT Prohttp://www.microsoft.com/technet/prodtechnol/winxppro/maintain/winxpsp2.mspx

Windows XP Service Pack 2 - Information for Developersmsdn.microsoft.com/security/productinfo/xpsp2/default.aspx

Page 35: How Hard Is It To Hack A Pc

Get Secured!Get Secured!