The Original Airstream E-mail List
Archive Files
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [A/S] A WiFi question
Turn off file and printer sharing.
Turn off file and printer sharing.
Turn off file and printer sharing.
Yeah, it's that important.
Then uninstall the NETbeui protocol entirely. Microsoft uses it to
broadcast file and printer shares across a network. It isn't routable,
but will pass through a wireless, Ethernet, or dial-up connection.
Remove it. You don't need it.
Kudos for the firewall.
Just remember that for Windows the effectiveness of your software
firewall depends on the insecure Microsoft TCP/IP stack internal to the
operating system. It isn't perfect, but it is fairly effective.
Real firewalls run on separate pieces of hardware and fully inspect each
packet before allowing it to pass into the secured safe side of the
firewall. They're really good (and dirt cheap). A small consumer router
(or other cable Internet or DSL Internet sharing device) is *not*
(though manufacturers call them that) a real firewall, it is a NAT
device (network address translation). It won't statefully inspect
packets, can't automatically respond to intrusion attempts, can't reject
tampered with packets, and can't handle the routing of complex
applications effectively. (The firewall acts as a router too.)
In the software firewall case, the crook is already inside the house, if
he can discover a Windows security flaw, he is in and around the
firewall. The key phrase here being "Windows security flaw". Yeah, there
are a lot of them. Still. Post SP2. Windows is still just plain
insecure. (I try to use it as little as possible.)
If anyone is interested in more on this or cheap firewalls that are
secure, grab me off list (it's probably off-topic, but Hunter can weigh
in here).
They are cheap and easy to set up, and dead easy to maintain. Even on
dial-up you'll get hit by intrusion attempts. In one dial-up session a
year ago I logged over a thousand attempts to break into my system. I
was using a hardware firewall on dial-up (yep,they can be used on
dial-up or any other access method) at the time, and laughed off the
attempts. But people can and do get nailed no matter what kind of
connection they use to access the Internet.
I am glad the person who discovered your printer share was nice enough
to do the usual white-hat thing and give you a warning with a test page.
Rick Kunath
WBCCI #3060