Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Windows File Sharing: Facing The Mystery
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
turning off Windows FW when running ZAP »
« This one is starting to wear me out.....  
AuthorAll Replies

ghost16825
Use security metrics
Premium
join:2003-08-26

reply to Daniel
Re: Windows File Sharing: Facing The Mystery

Great article. But just one point I'd like to make which I didn't see. Sure, Steve Gibson sensationalises things and has little in the way of helpful factual information. But the main reason why these services are dangerous, is usually not for their file enumeration ability nor their file sharing capabilities. It's the fact that they are (often by default) a running service with open ports as a consequence - which by itself implies that they will inevitably be vulnerable to buffer overflows from certain created input. Plus the fact that these services are difficult to "turn off" completely on Windows machines. And this goes for almost any service with remote functionality, including those on UNIX machines. (Unix has had its share of RPC security issues). Most security issues arise not because of the functionality or abuse of the functionality itself, but from input bounds-checking issues which allow buffer overflows and consequently malware to be executed remotely.
--
Admin of the Kerio 2x-like open source project:
http://sourceforge.net/projects/kerio/
http://kerio.sourceforge.net/


Daniel
Premium,MVM
join:2000-06-26
Pleasanton, CA
clubs:

said by ghost16825 See Profile:

Great article. But just one point I'd like to make which I didn't see. Sure, Steve Gibson sensationalises things and has little in the way of helpful factual information. But the main reason why these services are dangerous, is usually not for their file enumeration ability nor their file sharing capabilities. It's the fact that they are (often by default) a running service with open ports as a consequence - which by itself implies that they will inevitably be vulnerable to buffer overflows from certain created input.
Definitely. The focus here, however, was to say on the networking side of things with a slant towards security. In other words, I wanted to discuss the file sharing technologies themselves and not go into the much larger subject of securing a Windows machine in a more general sense.

I was going to go down that path, but it would have become much more than a couple hours woth of article in a hurry. I wrote most of this while watching some little Panda movie on T.V. with my girlfriend. That wouldn't be possible if I had expanded the scope any. Thanks for the comments though; I see what you mean.
--
dmiessler.com - grep understanding knowledge
Forums » Up and Running » Security » Securityturning off Windows FW when running ZAP »
« This one is starting to wear me out.....  


Monday, 09-Nov 20:49:50 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [70] VoIP Over 3G Still Not Working For iPhone
· [65] Verizon Keeps Swinging At AT&T
· [32] Bill Would Force ISPs To Block Financial Scams
· [18] Mediacom Hints At 50, 100 Mbps Speeds
· [13] Clearwire To Get Another $1.5 Billion
· [9] 15 States Have Now Gotten Broadband Mapping Money
· [5] AT&T Launching New 7.2 Mbps 3G Modem
· [2] Monday Morning Links
Most people now reading
· 60 Minutes piece on cyber security last night [Security]
· Framed for child porn 151; by a PC virus [Security]
· Google Has Acquired Gizmo5 [VOIP Tech Chat]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· My cat is reluctant to exercise. [General Questions]
· Divorce advice... [General Questions]
· Know when to run! [Home Repair & Improvement]
· Blown out Ballasts [Home Repair & Improvement]
· How in the world am I going to get into college? [General Questions]
· [WIN7] Outlook express under Windows 7? [Microsoft Help]