Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 43 guests online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Other
Security Best Practices at Home
EH-Net
May 22, 2013, 08:23:50 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Other
(Moderator:
don
) >
Security Best Practices at Home
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Security Best Practices at Home (Read 7173 times)
0 Members and 1 Guest are viewing this topic.
T_Bone
Full Member
Offline
Posts: 199
Security Best Practices at Home
«
on:
November 01, 2010, 01:50:48 PM »
Hi Guys
I was reading an article by Keatron Evans called "Information security at home" (
http://resources.infosecinstitute.com/information-security-at-home/
) and decided to create my own list by by adding a few more pointers and wanted to know what suggestions you guys may have in expanding it further?
Standard Best Practices
1. If wireless in use, ensure WPA or WPA2 with AES encryption with a passphrase of more than 20 characters in length
2. Turn off DHCP and statically assign an address to each machine
3. Enable MAC Address Filtering on Router/Access Point and only allow devices MAC Addresses
4. Keep Access Point away from Windows and Doors
5. Keep upto date with latest security patches (OS and all other applications running)
6. Ensure Anti-virus software and Anti-malware software is installed and up to date
7. If possible browse directly to websites that you wish to shop or logon to by entering the URI into the address bar. Do not click on links sent via email or from within forums etc but if you have to, verify the links!
8. Don’t use REAL credit cards, and certainly not your bank card to shop online. Use a prepaid Visa/Mastercard/American Express to do all your online shopping
9. When using Myspace, Twitter, Facebook. Don’t accept friends you don’t know. Don’t EVER click on links that people post in their status updates. These could easily be links to malicious sites or data.
10. Use an account with the least amount of privileges required. There is no need to browse the internet using an account with Admin rights!
11. Ensure that websites which use a secure communications channel (HTTPS) have a valid certificate. If the browser complains that the certificate is untrusted, DO NOT ignore it and go ahead, verfiy the certificate.
12. Ensure Firewall on Router and PCs are switched on
13. Keep Router Firmware upto date
Advanced Best Practices
For those that are more paranoid or want to be even more secure:
1. Use a browser that supports the "No-Script" add-on. Being honest it can be a bit of a pain to configure correctly but if you choose to use it do not browse the internet and "trust everything"
2. Use 2 separate Virtual Machines. Ensure all the above steps on each VM machine where applicable and use one strictly for sensitive applications such as banking etc and the other for general browsing of the internet.
Security Away from Home
Ok, strictly speaking this may not come under home security but just had to mention the following:
1. DO NOT browse to any websites that require a logon to access sensitive information whilst connected to any public networks (in coffee shops, trains, internet cafe's etc) whether the connection is wireless or not unless connected to a corporate network via a VPN.
2. Bear in mind that a lot of websites will often encrypt the login functionality, but once logged into the website will not use a secure cookie. Therefore the users cookie and session can be sniffed as it will all be in clear.
Please feel free to add
Logged
chrisj
Hero Member
Offline
Posts: 1163
Re: Security Best Practices at Home
«
Reply #1 on:
November 01, 2010, 02:16:48 PM »
Quote
1. DO NOT browse to any websites that require a logon to access sensitive information whilst connected to any public networks (in coffee shops, trains, internet cafe's etc) whether the connection is wireless or not unless connected to a corporate network via a VPN.
Depends on how that VPN is set up. My corporate network uses split tunneling. Anything for our network goes over VPN everything else, goes over you're regular internet connection.
Personally I push everything over my ssh connection to a server at home, and then do it all from there. VNC over SSH isn't hard. It's not perfect either. But for the few things it's not good enough for, I use the ssh connection as a proxy (for Youtube and the like).
Logged
OSWP, Sec+
H1t M0nk3y
Hero Member
Offline
Posts: 864
Re: Security Best Practices at Home
«
Reply #2 on:
November 02, 2010, 07:38:43 AM »
Quote
2. Turn off DHCP and statically assign an address to each machine
3. Enable MAC Address Filtering on Router/Access Point and only allow devices MAC Addresses
4. Keep Access Point away from Windows and Doors
These three points cannot even stop script kiddies!!!
They could give a false sense of security...
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
dante
Jr. Member
Offline
Posts: 58
Re: Security Best Practices at Home
«
Reply #3 on:
November 02, 2010, 09:10:39 AM »
Quote from: H1t M0nk3y on November 02, 2010, 07:38:43 AM
Quote
2. Turn off DHCP and statically assign an address to each machine
3. Enable MAC Address Filtering on Router/Access Point and only allow devices MAC Addresses
4. Keep Access Point away from Windows and Doors
These three points cannot even stop script kiddies!!!
They could give a false sense of security...
H1t M0nk3y is right. I assume turning off DHCP is to defend against ARP poisoning. Assigning static address to machines does not defend against arp poisoning but static arp tables does. Hope that was implied.
Logged
chrisj
Hero Member
Offline
Posts: 1163
Re: Security Best Practices at Home
«
Reply #4 on:
November 02, 2010, 09:23:53 AM »
actually, I think that number 2 is meant so if the person connects to the network they won't get an address.
How ever the same steps used to get past 3, can be used to get past 2.
* edited: self-edit to take out actual steps. (chrisj)
monitor network, get useful information, continue un-stopped.
«
Last Edit: November 02, 2010, 09:25:24 AM by chrisj
»
Logged
OSWP, Sec+
T_Bone
Full Member
Offline
Posts: 199
Re: Security Best Practices at Home
«
Reply #5 on:
November 02, 2010, 05:43:12 PM »
You guys are right, but the intent of the list is to help people minimise exposure. Obviously using wireless in the first place increases the threat level dramatically but unless your home network is being directly targeted I would probably say with the number of "open" wireless networks out there happily issuing IPs via DHCP it may put off some script kiddies!
Logged
MindOverMatter
Jr. Member
Offline
Posts: 62
Re: Security Best Practices at Home
«
Reply #6 on:
November 02, 2010, 06:12:59 PM »
I guess it is a "best practice", but we are covered by our CC companies and banks who can quickly investigate (not always) and reimburse us etc.. I've personally never had a problem and shopped online for years and years.
8. Don’t use REAL credit cards, and certainly not your bank card to shop online. Use a prepaid Visa/Mastercard/American Express to do all your online shopping
Logged
A+, Network+, Security+, CIW Associate, CCNA, C|EH
eth3real
Sr. Member
Offline
Posts: 309
Re: Security Best Practices at Home
«
Reply #7 on:
December 22, 2010, 02:17:07 PM »
I used to have my wireless access point's SSID as Jess, my first name. I didn't really see it as a big deal since nobody knew who I was, it used WPA2 and did not broadcast the SSID (I know that people could still sniff out the SSID).
Well, one of my neighbor's did eventually sniff out my SSID. Shortly after I got my CEH certification package and put the sticker on my window, my neighbor approached me and said "hey, you must be Jess. You have the only WiFi network I can't break into here!". He was using BackTrack 2 at the time. Of course I don't approve of breaking into people WiFi networks, but I thought that was kind of amusing. I never used my name as my SSID again because of this, and I also took the sticker down.
On a side note, at one point I was leeching off of a neighbors open WiFi, until I started scanning the network and found all kinds of personal info available as a shared drive from a Mac. When I found it, I quickly told him about it (it was easy to found out which apartment he lived in from the documents), and I think he just unplugged his router because I never saw it again.
WiFi, in my opinion, is one of the biggest flaws in home networking, unless you know how to do it right. A lot of people like to just use it the way it comes out of the box, there are probably a dozen 'linksys' or 'netgear' access points in my neighborhood.
As far as coffee shops WiFi, I think it's pretty safe, especially if the sites you go to have valid SSL certificates. If I do something involving sensitive personal information, I'll tunnel over SSH, and I feel extra safe with that. I'd honestly be more worried about someone shoulder surfing.
Logged
Put that in your pipe and grep it!
tturner
Sr. Member
Offline
Posts: 432
Re: Security Best Practices at Home
«
Reply #8 on:
December 22, 2010, 03:00:49 PM »
I just want to point out that cloaking your SSID may actually foster insecurity, or at the very least create privacy concerns.
What do I mean? Surely hiding the SSID is security by obscurity at the very least which is poor security alone but good to provide an additional layer nonetheless, right?
I understand the sentiment but disagree and here's why.
Reason 1 - Consider Karma, you know that fun tool that answers to wireless probe requests for network X and says "Oh! Oh! that's me! that's me! here I am, connect to me!" Congrats, you've just opened yourself to an AP impersonation attack
Reason 2 - It doesn't actually provide any real security and creates complacence due to a false sense of security. Sure you've hidden it from random passersby and Netstumbler users but who are the real threats? if you are cloaking your SSID you are also probably using decent encryption and changed default passwords, and maybe even robust authentication depending on your geekitude. The threats that concern me are the skilled, dedicated attackers with a malicious objective. not the guy trying to leech free wifi. That skilled attacker is not going to stumble his way through my neighborhood, he's going to use Kismet or something similar and sniff the connection strings right out of the air and he's going to have my SSID either way.
Reason 3 - When you hard code the SSID in your config you are advertising your network SSID to anyone sniffing these connections as you walk the preferred network list probing for that hardcoded network. Ever hear of wigle.net? It's fun stuff. You can search for the GPS coordinates and mapping data for a given SSID or for networks within a certain geographical area.
For instance, I spend a lot of time in airports. Let's say I was to sniff the SSID of travelling public and find say "John Chapman's Network" I look it up on wigle.net and find out where John lives. He's not home. Sweet! Maybe I will look him up on Facebook and find out if he has a wife and kids or if there is details about travel plans or pictures of their big screen tv. Awesome! Let's drive to his house and rob him blind. Obviously I would never do that as I'm an ethical professional but you get the point. What if the SSID was for "Pornhouse Internet Cafe" or "Chicken ranch"? I'm sure the mythical private investigator following me on behalf of my wife would love to report those as well!
Cloaking is bad. Friends don't let friends cloak wireless.
Logged
Certifications:
CISSP, CISA, GPEN, GWAPT, GAWN, GCIA, GCIH, GSEC, OPSE, CSWAE, CSTP, VCP
WIP: OSWP, GSSP-JAVA, GXPN
Udacity on hold, again. I suck.
http://sentinel24.com/blog
@tonylturner
http://bsidesorlando.org
hell_razor
Jr. Member
Offline
Posts: 90
Re: Security Best Practices at Home
«
Reply #9 on:
December 22, 2010, 03:59:50 PM »
Since rainbow tables are generated with SSIDs, I would suggest using a randomly generated SSID of sufficient length (depends on wireless vendor) and then a strong passphrase (randomly generated as well perhaps). I would expect that to be good enough for home networks.
Logged
A+, Network+, Server+, CISSP, GSEC, GCIH, GPEN, GCIA, GISP, GCFW
eth3real
Sr. Member
Offline
Posts: 309
Re: Security Best Practices at Home
«
Reply #10 on:
December 22, 2010, 04:01:50 PM »
Quote from: tturner on December 22, 2010, 03:00:49 PM
Reason 1 - Consider Karma, you know that fun tool that answers to wireless probe requests for network X and says "Oh! Oh! that's me! that's me! here I am, connect to me!" Congrats, you've just opened yourself to an AP impersonation attack
Isn't everyone with a preshared key vulnerable to that, anyway, if there are clients probing to connect to saved networks?
Quote from: tturner on December 22, 2010, 03:00:49 PM
Reason 2 - It doesn't actually provide any real security and creates complacence due to a false sense of security. Sure you've hidden it from random passersby and Netstumbler users but who are the real threats? if you are cloaking your SSID you are also probably using decent encryption and changed default passwords, and maybe even robust authentication depending on your geekitude. The threats that concern me are the skilled, dedicated attackers with a malicious objective. not the guy trying to leech free wifi. That skilled attacker is not going to stumble his way through my neighborhood, he's going to use Kismet or something similar and sniff the connection strings right out of the air and he's going to have my SSID either way.
If an advanced user can get your SSID either way, than you are only protecting yourself from basic users, but not making yourself more susceptible to advanced attaackers.
Quote from: tturner on December 22, 2010, 03:00:49 PM
Reason 3 - When you hard code the SSID in your config you are advertising your network SSID to anyone sniffing these connections as you walk the preferred network list probing for that hardcoded network. Ever hear of wigle.net? It's fun stuff. You can search for the GPS coordinates and mapping data for a given SSID or for networks within a certain geographical area.
For instance, I spend a lot of time in airports. Let's say I was to sniff the SSID of travelling public and find say "John Chapman's Network" I look it up on wigle.net and find out where John lives. He's not home. Sweet! Maybe I will look him up on Facebook and find out if he has a wife and kids or if there is details about travel plans or pictures of their big screen tv. Awesome! Let's drive to his house and rob him blind. Obviously I would never do that as I'm an ethical professional but you get the point. What if the SSID was for "Pornhouse Internet Cafe" or "Chicken ranch"? I'm sure the mythical private investigator following me on behalf of my wife would love to report those as well!
If you don't put your name in your SSID, would that even be an issue? Again, that could happen even if you don't hide your SSID.
Don't get me wrong, I don't recommend hiding your SSID as a kind of defense against attackers, but does it really make you less secure than if it is broadcasting?
Logged
Put that in your pipe and grep it!
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
Gates
: Isabelle Marant if you're|a really wonderful|pc|whether you are having a lesson
(0) by
ddogs42zm
News Items and General Discussion About EH-Net
: 1000 страшно пол
(0) by
quohaphoday
GPEN - GIAC Certified Penetration Tester
: Karen Millen Outlet as an example SFTP
(0) by
dtree28yt
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(27) by
don
Greetings
: Hi from the UK
(2) by
n37sh@rk
Network Pen Testing
: AIX Vulnerability Assessments
(2) by
ras76
Tutorials
: Need guidance
(9) by
hanyhasan
Programming
: Finished Python Course in Codecademy now what?
(15) by
hanyhasan
Network Pen Testing
: Ruby on Rails Vulnerabilities / Attacks in BackTrack 5 r3
(0) by
SUdoctstudent
Network Pen Testing
: De-ICE 1.140 released!
(2) by
superkojiman
General Certification
: CPT Practical Submission
(1) by
UNIX
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
Web Applications
: Nessus and Nikto
(4) by
Seen
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.