Tuesday, February 23, 2010

Shouls You Have A Clean Bowl Movement

WINDOWS XP vs. Windows 7

Windows 7 protects you he better than Windows XP? How
Windows 7 stands out there for Windows XP on Security? Is it really safer? How does he defend against modern attacks? The responses on this issue.
Windows XP was designed at a time when the Web was still a primarily textual universe accessible to the privileged few. At the time, we designed the new system without really taking into account the implications that might ensue in terms of safety. Internet, its viruses and malware and its now its cybercriminals came radically change our perception of security.
The email that changed everything
In 2002, a very famous e-mail Bill Gates on "Trustworthy Computing" (Trusted Computing) would literally revolutionize development at Microsoft. Suddenly, one after the other, all developers now had to undergo training on hacking techniques and methodologies to produce code more robust and secure.
For several months they gathered to inspect parts of Windows source code which they were responsible to determine the risks of attack and what to do. This effort led Microsoft to two decisions: leave the Service Pack 2 for Windows XP, SP2 fully dedicated safety and reduce even the release of Windows Vista (codenamed Longhorn).
developments based on safety
Since then, Microsoft developments follow very specific rules known as the SDL (Security Development Lifecycle). Vista was the first Microsoft operating system to benefit from this new philosophy.
And it is now admitted that Vista is a highly secure, this security effort has mainly meant a sharp decline in public for whom these measures were viewed more as nuisances than as a daily ADDITION security.
Cybercriminals will no longer attack the OS
Windows 7 has the same rigor of development, but also three years of maturity. The protections are still there but they are less disruptive.

There is absolutely no comparison between the effectiveness of the protection of Windows 7 and the protection of Windows XP. It is estimated that only a few seconds to a XP SP1 to be infected without any user action. Infection of a Windows 7 is proving far more difficult for all cyber criminals and all creators of malware.

was already true with Vista. At that point, in recent months, cybercriminals are got their fortunes by attacking the accompanying Software (QuickTime, Flash, Adobe PDF Reader) rather than the system itself and multiplying attacks based on social engineering to bring users a bit naive or too eager to commit the irreparable. Less costly methods and faster than finding fault in a highly secure system. They come together to steal private information or install on the PC user tools (including security) that serve as artificial gateways.
Foundations healthier

Windows 7 multiplies the defenses in the heart of the core. If it was a breeze in XP to pervert the system and insert a rootkit (unauthorized access) can cover up absolutely all traces of malicious activities, the operation is much more complex including Windows 7 in 64 bits.
be found in Windows 7, as security PatchGuard 3 (Kernel Patch Protection), ASLR (Address Space Layout Randomization) or the signature required of drivers (64-bit), all designed to make the creation of rootkits much more complex .

Certainly the creation of such malicious code is possible as demonstrated Blue Pill or VBootkit 2.0. But it tends to be limited to "technical demonstrators, as there is a fundamental difference between developing a code of demonstration and actually be able to physically deploy thousands of machines (VBootkit requires direct physical access to the machine and his CD player for example).
rules and warnings not to lose sight
All these indicators lead to three general rules that the user must keep in mind:
- 64-bit Windows is more secure and safer than Windows 32-bit
- Many Threats like rootkits can not settle sustainably without administrative rights;
- Many threats can not move without "assistance" from the user.
But these rules also lead to three warnings in parallel:
- Rootkits are a subset of malicious code and the subset least common Windows;
- There may be malicious code compatible with 64 editions bit Windows 7;
- All malicious code do not need administrative rights to operate: and Trojans that steal information by ports 80 or 21 do not need to elevate user privileges to steal your identity. What
should remember
other words, Windows 7 will not be immune from malpractice by cybercriminals. Therefore, it is better not to move from a security suite. However, numerous engineering controls make installation permanent malware and system compromise much more complex and therefore more rare. The UAC
New Look
Introduced with Vista, the UAC (User Account Control alert or user account) is probably the safety function the most poorly perceived. It must be said that at the time of the release of Vista, it produced an incredible amount of alerts. A number had been reduced with Vista SP1 and drop even with Windows 7 without even modify the new settings added by Microsoft.
Recall the role of UAC
But what does UAC mean? It is a set of technologies designed to reduce the default rights of users and particularly those who are directors. In theory, a typical application does not need rights to run and move forward. In practice, unfortunately, many applications allow themselves greater rights when triggering alerts privilege elevation, more known as UAC warning.
Microsoft hoped that UAC would force developers to create applications more in line with good programming rules. It did not happen and it is the users who were the main victims. Even if the UAC alerts are now less frequent, they are still present. But they do occur, essentially, that when installing an application or a pilot, a sport that is theoretically not daily.
the late UAC alerts? Windows 7 UAC

.
Since Microsoft has added a warning in Windows 7 that defines the level of protection, and thus the level of alert that you want to give the UAC. Those who find these alerts too bulky, can and eliminate them by reducing the safety of the system, however. The idea here is not always leave the UAC to its lowest level, but rather to allow users the right to adjust depending on the case.
When you install your machine with all its applications and drivers, reduce the level to remove the UAC alerts. Once your machine is actually operating, raise the level of UAC. For that, go in the User Account Control Panel and select Modify control settings of the user account.
UAC defense mechanism the system must understand that
UAC is not a warning mechanism, it is also a defense mechanism. The good news is that now Windows 7 (and unlike Vista), suppression of alerts UAC does more disabling related protection. Notably, the method "protected" from Internet Explorer (which prevents infections by the web extend beyond user profile) remains active even when the user "No Warning" is selected.

Our advice: turn down the UAC warning the first days after the system installation time to set your environment, your devices and software. Once stabilized environment, raise the level of UAC. A little warning time to time, that is not too serious and it can be very informative!
Truths and myths about administrator accounts
Windows 7 as Vista, the old profile "administrator" is disabled by default. Found on 01net. An article to retrieve and revive the "Super Administrator".
Should we revive the "Super Administrator"?

super-administrator

Wake and use the administrator profile is a real bad idea! It is certainly a return to the comfort of XP, but it actually a return to the hell of XP, a hell where all threats find their way. The users have stopped complaining about the number of viruses and infections that had Windows XP.
Security has a price. Under Vista this award was judged unacceptable. Windows 7, UAC has been sufficiently silenced so that it is no longer a handicap. Certainly, there is a plethora of threats that find their way onto the PC even when the administrator is disabled. But is this sufficient reason to further open the door wide?
administrative rights without administrator
This is not because the authentic account administrator no longer exists by default, there are more users with administrative rights. In fact, the first user account created during installation is an account type "Administrator reduced" (technically it is not the administrator account itself but to an account belonging to the group of administrators).
other words, by default when you install Windows 7 or when you purchase a PC preinstalled with Windows 7, the first account has installed or preinstalled good administrator privileges.
The role of UAC in there?

User Account Control

The UAC is there to ensure that these "directors cut" by default have limited privileges. In other words, an application (including malicious code), launched on those accounts only run with standard user rights.
If the application needs more rights (for example moving to driver or service installed in the system folders or placed on an area autorun at startup), it will automatically trigger a UAC alert! If the user then grant the privilege elevation, the worst becomes feasible.
What does it mean?
We must be aware that, by default, there is actually Windows 7 users with administrator rights even if they are limited by the UAC.

For the user, an alert user should not be perceived as a nuisance than a warning of attempts to change the system. But there is no valid reason for a Web page, "Keygen," a video or an image requires elevated privileges. The appearance of the alert UAC should in the vast majority of cases result in a refusal of the user!
If in doubt, and if you really want to run this code makes you doubt as envy, think virtual machines (Windows Virtual PC, VirtualBox, VMWare Workstation or Parallels Desktop) or coverages as the "Green Zone" of Kaspersky.
addition UAC and protections installed in the foundation system, Windows 7 has three other defensive curtain:
- An excellent two-way firewall;
- The Windows Defender anti-malware;
- Windows Update.
An excellent two-way firewall as standard

-way firewall.

Let the loud and clear: Windows 7 has an excellent firewall. It remains to define what is meant by firewall. If one considers that the treatment is over leaks intrusion detection and thus a layer of intelligence above the firewall, the firewall in Windows 7 is probably what is best. Indeed, it is totally transparent, totally customizable, because hyperrapide hyperintégré system, active from the first seconds of life of the system even before network connections are mounted. In addition, it automatically adjusts to network types (the role of the famous dialog box that asks the user if he is home, office or a public place whenever a new connection is detected).
Also with Windows 7, Microsoft has installed a number of APIs to enable secure security vendors to build their own layers of intrusion prevention (IPS) and intelligence leak control over the firewall of the system rather than trying to systematically replace. Hopefully some publishers actually focus on this possibility, which does not seem the case today. In Windows Defender
MSE

Defender.

version 7 of Windows Defender has been redesigned to integrate better into the Maintenance Center (see below). The engine is also more compact and consumes less resources which helps improve overall performance of the operating system.
noted however that, for all those who refuse to invest in a security suite (which we do not advocate), it seems particularly appropriate when installing Microsoft Security Essentials, a new free antivirus Microsoft. MSE is actually a supercharged version of Windows Defender. It takes place in the heart of Windows 7 when installing.
Windows Update is a security!
Today, the majority of infections are carried out by navigating Web sites compromised. The technique used, the Drive By Download, running on the fly and without the knowledge user, all kinds of malware that attempt to infiltrate the system with known faults.
The simple fact of having a really day (including in the PDF reader, Quicktime, Flash) is the best defense against threats. And Windows Update is the best way to keep its system up to date. The disabling is one of the worst mistakes made by many users who fear so paranoid pseudo "surveillance" of their PCs by Microsoft.
Action Center has a role in security

Action Center.

One of the most significant innovations of Windows 7 is the elimination of unnecessary alerts and Security Center to benefit the Action Center (roughly translates Action Center on the French versions). It gathers all alerts related to system stability, its security, its preservation and maintenance. Minor problems will cease to produce alerts and everything will be grouped and listed in the new center for each of the problems with drafts of solutions or aid. Parental control

Inaugurated in Vista, Parental Controls is now at the heart of the system. The idea: Every child has their own login on the family PC. Parents can then assign each child time to use the PC as well as applications for which it is entitled. They can automatically ban games discouraged by the age of the child, but also prevent the use of illegal software downloads.
However, unlike Vista, the Web browser control disappears. The remote function is now the option "Windows Live Family" to download separately and apart from the navigation control can also monitor (without the spying) online activities of children and its corresponding e-mail and Windows Live Messenger.
not forget IE8 and its internal safety
Although often maligned, Internet Explorer 8 also incorporates numerous safety features. They are of average efficiency for all those who spend their lives poking on the net, but they provide a living wage for novices. The main navigational safety are protected mode (which only limited infections user profile and not the rest of the system), new restrictions on use of ActiveX, the phishing filter and the filter Smart Filter to monitor downloads. Besides
navigation mode "InPrivate" which is not safety but comfort for users who want to be discreet as they share their computer with others.
Good surprises with the backups

Safeguard Mechanism.

Good news, Microsoft has continued to play stingy! Functions by backup disk image and previous versions were present only on the professional versions of Vista. They are now present on the Home Premium and the public therefore has a protective assembly.
Namely, a true safeguard mechanism (DVD or external hard drive) of the entire PC. If you buy a new PC, use it from day to maintain an image of your PC as it was originally.

previous versions.

enlarge
previous versions is a feature that allows users to find documents or files as they were several hours or days before. It therefore allows to recover a modified document by mistake. Other safety
useful for the general public
System Restore (System Restore) functional gains in wealth. The technology that restores the system to a previous state (to fight against bugs, installation failed or infection) provides more details on possible consequences of this setback (which software will find themselves impacted by example).

biometric recognition is now a layer of the system and not an extension. We gain in security, but also simplicity of implementation. Now when you install Windows 7 on a PC with a fingerprint reader, it is automatically recognized and supported by the biometric functions.
bonuses for businesses
Windows 7 also brings a lot of features for businesses.

BitLocker To Go allows you to encrypt USB drives and removable drives to secure data on removable media and therefore easy to misplace.

DirectAccess technology is probably the biggest failure of Windows 7. It can re-imagine the security perimeter of the enterprise. It overcomes the VPN and rethink security not in terms of network topology, but in terms of user rights. For the user, there is no difference between being in the walls of the enterprise or be outside. Everything is transparent and user experience remains the same.

AppLocker is another major function. It defines a strict programs that may or may not be installed and run on the user workstations. This facilitates the control of licensing and adds a layer of security against trying to run code on the machine.

Audit functions have also been widely expanded. Now they can trace all changes made by specific users or specific groups but also to easily understand and demonstrate why a person has access to specific information or why access to information was denied to such person. Examples
by doing
Windows XP and Windows 7 are not equal before the Internet threats. Here is how in practice one and one behave when faced with different attacks. Loïc Duval


Windows XP and Windows 7 are not equal when it comes to Internet threats. Here is how practical either behave against different attacks today.
First case: infection Rogue Rogue

infection
Windows XP.

By visiting a website from a Google search on the name of a star, a pop-up was displayed with a false desktop with a fake scan in the background and a false security alert . Internet Explorer displays an alert box with a strange message.
The strange thing is that the alert does not go away until the user clicks Cancel. His only solution is to turn off his PC. Most users opt for OK, so in desperation and saw the PC with a new tool "Internet Antivirus Pro". This tool is totally imaginary threats 14 (the installation is new) but also serve as a gateway to cyber criminals.

infection Rogue
Windows 7.

Windows 7, things happen a little differently. The page with the fake scan alert is displayed and the Internet Explorer. But when the user clicks Cancel, things left there.
If the user clicks fooled and install IE8 will display a security warning with the Cancel button preselected. If the user selects still run the code, the UAC warning appears (note that a good antivirus, MSE understood, would meanwhile intervened to indicate the download of malicious code). Again the UAC warning suggests default select "NO" to the installation. If the user insists further, this code is still not happen to run: unable to take the final protection of the core, it will be declared incompatible.
Second case:

phishing attack phishing.

We receive e-mail, text in French pretty scary from a French bank stating that our account may have been hacked and that it must immediately follow the link provided to enter coordinates and change our code security. This is a phishing attack from the most traditional.
Suppose this e-mail us really worried. Windows XP comes with IE6 default that has no phishing filter. It then accesses without regard to a site that looks like two drops of water at the site of our bank, but that is only intended to steal our IDs.
Windows 7 was equipped with IE8 which has a filter phishing and prevents us from accessing the site. Filter IE8 is effective for most broadcast spam. Most suites are more reactive. In all cases, remain vigilant against such e-mails that try to frighten you just to entice you into a trap.
Third case: a trojan on a site

Trojan. In seeking

videos on the web, we came across a link that encourages us to download a new beta version of the Flash Player to better enjoy the videos. Intrigued, we click the link to start downloading the beta version. The SmartFilter
IE8 then comes into action to inform us that this file is dangerous. There is widespread enough that Microsoft has declared in its SmartFilter database of threats and not download. It is true that for several weeks, many sites ask users to install Flash (although it is already installed), issued by a Flash site that contains an installer and modified with a Trojan. Under XP with IE7 or IE6, the infection would have occurred without any warning.
Fourth case: a spyware on a key

Spyware.

We try to run a program from a USB key. Windows XP installation passes without flinching, but quickly invade the screen pop.
Windows 7, when we double click on the program, UAC will trigger an alert stating that this program is potentially dangerous. We'll also launch and execution. An alert indicates a potentially dangerous program has been detected and must be deleted. This was recognized by a spyware Windows Defender.
Fifth case of threats to the hard

various threats.

A friend passes us an external hard drive. At a regular scan, Windows Defender identifies the presence of malicious code on the disk and report through the Action Center. When the scans are not performed regularly, the Action Center will notify you and invite you to schedule. Windows Defender remains limited in its sensing field.
On the same disk, Microsoft Security Essentials identified seven other malicious code!
In other cases the infection will go ahead
The tests we have conducted show several things:
- Windows 7 is more impervious to malware in its 64-bits in its 32-bit version;
- Many are malware inoperative on Windows 7, even if we force their execution. However, some manage to settle and make crash the system to reboot. It must then reboot in safe mode to clean the infection
- Most facilities unbeknownst to the user fail when one is in standard user profile;
- The base defenses raise the level protection but are not sufficient for users who practice hacking or intensive exploration of the Web. It remains imperative Windows 7 to add an antivirus or security suite.

0 comments:

Post a Comment