View Single Post
  #4  
Old February 10th, 2006, 10:10 AM
Thermodyne's Avatar

Thermodyne Thermodyne is offline
Lieutenant Colonel
 
Join Date: Dec 2000
Location: DC Burbs USA
Posts: 1,460
Thanks: 0
Thanked 1 Time in 1 Post
Thermodyne is on a distinguished road
Default Re: Hijacked PC\'s Being Held For Ransom

1) Don’t use an account with administrative privileges for everyday activities.
2) Don’t open email from unknown senders.
3) Don’t use IE with low security settings. Better yet, don’t use IE.
4) Do use antivirus and keep it up to date. Symantec is still one of the best out there; just don’t get the version with all of the extra crap.
5) Do keep your system patched.
6) Do use a firewall of some sort. Hardware is better than software, but software is better than nothing.
7) Do set windows to require a Ctrl, Alt, and Del at log on.
8) Do put a complex password on the admin account and turn off administrative shares.
9) Do rename the admin account.


This sounds like an old TSR exploit, but could also be some type of root kit. Many home systems have a null admin password and administrative shares turned on. So some punk scans his local WAN subnet for computer names and with a whack-whack computername admin logon with no password gets right into your root drive. Sound easy? It is, and it’s hard for the average person to keep a system locked down. I’ve said it before and I’m saying it again. A hardware firewall is your best defense. Even if you let the system become a bot, the stand alone firewall will still prevent the hacker from making use of your system.
__________________





Think about it
Reply With Quote