How not to get hacked: Microsoft

Powered by SC Magazine
 

Microsoft pushed security to the front of its Tech.Ed agenda on the Gold Coast this week, holding a developer and technical support session aimed explaining the easiest routes to hack attack on any IT network.

Microsoft pushed security to the front of its Tech.Ed agenda on the Gold Coast this week, holding a developer and technical support session aimed explaining the easiest routes to hack attack on any IT network.

Jesper Johanssen, enterprise security architect in the security, business and technology unit at Microsoft, told Tech.Ed attendees there were 10 easy ways to get any IT network hacked. First of all, don't patch anything. Then, run unhardened applications and services.

"All the interesting attacks these days happen through the applications," he said.

Johanssen said many vendors were more or less on top of any potential for operating system attack but few had much clue about how to best harden applications. "That's critically important," he said.

Companies should also avoid using an administrator account everywhere on the network. "That's a wonderful way for the bad guys to get it. You should be using least privilege. Different administrator access for everything."

Johanssen claims special insight into the way a hacker's mind operates. One of his previous tasks at Microsoft was going around figuring out how to attack Microsoft's networks.

He said organisations should avoid opening up lots of holes in their firewalls if they really wanted to be secure. However, in most cases that was simply unavoidable because companies often need to use the internet and allow traffic through.

"Opening port 80 -- that's the same as turning off your firewall really," he said. "Firewalls are pretty meaningless today because they're layer four, they block ports. Whereas the interesting things happen in layer nine or elsewhere."

He was less than positive about SSL VPN for the same reason. Organisations should install IPSec, which worked quite differently. "SSL VPN? That's not VPN. It's a giant hole in your firewall," Johanssen said.

Further, many organisations let all the clients and servers communicate, which he said was generally unnecessary. "That's what I call a Kum Bay Ah network --all the Windows machines getting together to sing 'Kum Bay Ah'."

Far better to only permit clients to talk to servers and vice versa if an organisation wanted to reduce the risk of getting hacked, he said.

Companies should restrict users from downloading applications from the internet but should also cut down the internal traffic. Outbound traffic should also be restricted, Johanssen said.

Meanwhile, passwords -- or, even better, passphrase -- should be unique for each user and each password-protected part of the network. Even if users wrote them down, it was far better that they used a set of unique passwords, Johanssen said.

Another trick was not to use high-level service accounts in many places. That invited risk because once that service account was cracked, it gave lots of further possibilities to the hacker, he said.

Last of all, never assume everything is OK, he said. "You live a lot longer in this business if you have a healthy level of paranoia," Johanssen said.

Attention to those issues was more likely to keep out attackers than buying "cheap" software from certain of Microsoft's "rivals", Johanssen said.

Fleur Doidge travelled to Tech.Ed on the Gold Coast as a guest of Microsoft.

 
 
 
Top Stories
Westpac committed to core banking plan
[Blog post] Now with leadership.
 
The True Cost of BYOD - 2014 survey
Twelve months on from our first study, is BYOD a better proposition?
 
Photos: Unboxing the Magnus supercomputer
Pawsey's biggest beast slots into place.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest articles on BIT Latest Articles from BIT
Pass on carbon tax savings, warns ACCC
Jul 24, 2014
The ACCC is warning businesses that supply "regulated goods" to pass on any cost savings ...
Have customers that won't pay debts?
Jul 10, 2014
The ACCC and ASIC have updated their advice when it comes to collecting debts.
Carpet cleaner faces court over online testimonials
Jul 4, 2014
The ACCC has initiated proceedings against A Whistle (1979) Pty Ltd, the franchisor of Electrodry...
You can now get 15GB of free online storage using Microsoft OneDrive
Jun 25, 2014
Cloud storage has reached both the capacity and price where it's a viable alternative to local ...
Another clever trick you can perform with Xero
Jun 25, 2014
Here is another way to reach out to particular subsets of your customers using Xero.
Latest Comments
Polls
What is delaying adoption of public cloud in your organisation?







   |   View results
Lock-in concerns
  29%
 
Application integration concerns
  3%
 
Security and compliance concerns
  27%
 
Unreliable network infrastructure
  9%
 
Data sovereignty concerns
  22%
 
Lack of stakeholder support
  3%
 
Protecting on-premise IT jobs
  4%
 
Difficulty transitioning CapEx budget into OpEx
  3%
TOTAL VOTES: 1137

Vote