Franske ITC-2000 Security Lab: Difference between revisions

From ITCwiki
Jump to navigation Jump to search
(Created page with "=Manage Windows Users and Groups= # Open the "Computer Management" control panel # Click on the "Users" option under "Local Users and Groups" # You should now see a listing of...")
 
No edit summary
Line 24: Line 24:
# Click "Cancel" to close the Users group window.
# Click "Cancel" to close the Users group window.
# Close the computer management window
# Close the computer management window
=Manage File and Folder Permissions=
=Manage Windows Firewall=
# Open the Windows Firewall from inside the "System and Security" control panel
# Click the "Allow a program of feature through Windows Firewall" link on the left side of the screen.
#* This window provides a basic interface to the Windows Firewall. Programs and features can be allowed through the firewall by placing a check mark to the left of the program or feature and then checking one or both boxed to the right providing access when your computer is connected to Home/Work or Public networks. Explore the current settings and determine what programs or features are currently allowed through the firewall on your system.
# Press the back button to return to the general Windows Firewall control panel window
# Click the "Advanced settings" link on the left side of the window
# Right click on the first "File and Printer Sharing (Echo Request - ICMPv4-In)" rule and select "Properties"
# Explore how this rule was created
## Click the "Advanced" tab and check which profiles this rule applies to
## Click the "Customize..." button in the "Interface types" section and see what interface types this rule applies to, then click OK to close this window
## Click the "Programs and Services" tab and check which programs and services the rule applies to.
## Click the "Protocols and Ports" tab and then the "Customize" button in the ICMP settings section and check to see which ICMP messages the rule applies to
# Close all windows
=Manage Anti-Malware Software=

Revision as of 00:48, 30 October 2014

Manage Windows Users and Groups

  1. Open the "Computer Management" control panel
  2. Click on the "Users" option under "Local Users and Groups"
  3. You should now see a listing of all users on your system in the right hand pane of the window.
  4. One way that attackers may exploit your system is by using account credentials which you are not in need of. One such example is the default "Guest" account.
    1. To disable this account right click on the account name and choose properties.
    2. Place a check mark nets to the "Account is disabled" option
    3. Click the "OK" button
    4. Notice that the Guest account icon is now different than active accounts on the system
  5. Create a new user account through the computer management window
    1. Right click on an open area in the user listing pane of the window and select "New User..."
    2. Create a new user with "ITC Limited" as the username and full name.
    3. Set the password for the user to "Password01!!"
    4. Make sure that the "User must change password at next login" box is unchecked and the "Password never expires" box is checked.
    5. Click "Create"
  6. Create a new group through the computer management window
    1. Click on the "Groups" option under "Local Users and Groups" in the left side pane of the window
    2. Right click on an open area in the group listing pane of the window and select "New Group..."
    3. Create a new group named "ITC Limited"
    4. Click the "Add..." button and enter the user name "ITC Limited" and click "OK" to add the ITC Limited user to the new group
    5. Click the "Create" button to create the group
  7. Open the "Users" group by double clicking on the group name
  8. Notice that the ITC Limited user is automatically added as a member of this group as well.
  9. Click "Cancel" to close the Users group window.
  10. Close the computer management window

Manage File and Folder Permissions

Manage Windows Firewall

  1. Open the Windows Firewall from inside the "System and Security" control panel
  2. Click the "Allow a program of feature through Windows Firewall" link on the left side of the screen.
    • This window provides a basic interface to the Windows Firewall. Programs and features can be allowed through the firewall by placing a check mark to the left of the program or feature and then checking one or both boxed to the right providing access when your computer is connected to Home/Work or Public networks. Explore the current settings and determine what programs or features are currently allowed through the firewall on your system.
  3. Press the back button to return to the general Windows Firewall control panel window
  4. Click the "Advanced settings" link on the left side of the window
  5. Right click on the first "File and Printer Sharing (Echo Request - ICMPv4-In)" rule and select "Properties"
  6. Explore how this rule was created
    1. Click the "Advanced" tab and check which profiles this rule applies to
    2. Click the "Customize..." button in the "Interface types" section and see what interface types this rule applies to, then click OK to close this window
    3. Click the "Programs and Services" tab and check which programs and services the rule applies to.
    4. Click the "Protocols and Ports" tab and then the "Customize" button in the ICMP settings section and check to see which ICMP messages the rule applies to
  7. Close all windows

Manage Anti-Malware Software