# Securing your Microsoft Machine

**URL:** <https://forums.speedlife.net/t/securing-your-microsoft-machine/62335>\
**Category:** NYSpeed Off Topic\
**Created:** [February 2, 2009, 2:44pm UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335 "2009-02-02T14:44:36Z")\
**Posts on this page:** 20\
**Page:** 6

<div class="post-metadata">

**Author:** ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)\
**Post date:** [May 9, 2013, 7:16am UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/101 "2013-05-09T07:16:57Z")

</div>

> [@ProgRocker](#):
>
> As far as AV goes, you have to think about it from a normal user standpoint. Does it protect against all threats…nah…not even close. Most users suck and click everything in sight, download whatever, and go to weird sites. IF there is a shinny icon down by their clock telling them it’s ok, they feel better. If it stops some of the infections it might not be bad to have.

Realistically AV doesn’t stop current attacks.

Drive by attacks with Java 0day, IE 0day, etc

Semi targeted phishing attacks and this isn’t even getting into targeted attacks

My point was running EMET would stop most 0day since its stop exploits from getting around built in Windows anti exploitation techniques.

If you look at the amount of time you spend dealing with viruses/malware and weighing it against spending two weeks building a more secure base image you usually find it being worth while.

---

<div class="post-metadata">

**Author:** ![ProgRocker](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/progrocker/32/5434_2.png) [@ProgRocker](https://forums.speedlife.net/u/ProgRocker)\
**Post date:** [May 9, 2013, 7:30am UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/102 "2013-05-09T07:30:15Z")

</div>

> [@LZ](#):
>
> Realistically AV doesn’t stop current attacks.
> 
> Drive by attacks with Java 0day, IE 0day, etc
> 
> Semi targeted phishing attacks and this isn’t even getting into targeted attacks
> 
> My point was running EMET would stop most 0day since its stop exploits from getting around built in Windows anti exploitation techniques.
> 
> If you look at the amount of time you spend dealing with viruses/malware and weighing it against spending two weeks building a more secure base image you usually find it being worth while.

Some A/V will stop the results of these exploits…SOME of the results, not all. I really want to push for removing Java from our machines at work. I even have a script that removes all versions V. 7 and below. Problem is, that some user NEED websites that us Java. Also patching, testing, and pushing out updates to machines in our domain is incredibly time consuming.

Our base image that we use is considered bare metal. It doesn’t even include drivers or software. So in that sense, it’s fairly secure.

---

<div class="post-metadata">

**Author:** ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)\
**Post date:** [May 9, 2013, 7:33am UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/103 "2013-05-09T07:33:47Z")

</div>

If you guys currently use a proxy its pretty easy to filter Java and white list known external applications and block everything else.

You could probably review currently logs and see what jar files are being loaded etc

It’s a lot less work 🙂

---

<div class="post-metadata">

**Author:** ![ProgRocker](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/progrocker/32/5434_2.png) [@ProgRocker](https://forums.speedlife.net/u/ProgRocker)\
**Post date:** [May 9, 2013, 7:37am UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/104 "2013-05-09T07:37:15Z")

</div>

^ That part would be out of my realm.

---

<div class="post-metadata">

**Author:** ![boardjnky4](https://avatars.discourse-cdn.com/v4/letter/b/96bed5/32.png) [@boardjnky4](https://forums.speedlife.net/u/boardjnky4)\
**Post date:** [May 9, 2013, 8:14am UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/105 "2013-05-09T08:14:06Z")

</div>

> [@LZ](#):
>
> If you guys currently use a proxy its pretty easy to filter Java and white list known external applications and block everything else.
> 
> You could probably review currently logs and see what jar files are being loaded etc
> 
> It’s a lot less work 🙂

Implementing technology is easy. Dealing with the fallout BLOWS.

---

<div class="post-metadata">

**Author:** ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)\
**Post date:** [May 9, 2013, 8:21am UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/106 "2013-05-09T08:21:18Z")

</div>

> [@boardjnky4](#):
>
> Implementing technology is easy. Dealing with the fallout BLOWS.

I have played in all realms of IT I understand the suck

The proxy thing I suggested works really well from customer feed back I have been getting. They were able to review a few months of proxy logs and figure out all valid apps block everything else and this was with very large companies.

It’s honestly to the point with most companies understand being secure will cause some pain but its a necessity for a successful business. Most of the companies I work with are F500 however its trickling down to smaller companies now.

---

<div class="post-metadata">

**Author:** ![ProgRocker](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/progrocker/32/5434_2.png) [@ProgRocker](https://forums.speedlife.net/u/ProgRocker)\
**Post date:** [May 9, 2013, 8:46am UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/107 "2013-05-09T08:46:28Z")

</div>

> [@LZ](#):
>
> I have played in all realms of IT I understand the suck
> 
> The proxy thing I suggested works really well from customer feed back I have been getting. They were able to review a few months of proxy logs and figure out all valid apps block everything else and this was with very large companies.
> 
> It’s honestly to the point with most companies understand being secure will cause some pain but its a necessity for a successful business. Most of the companies I work with are F500 however its trickling down to smaller companies now.

In my anti-virus logs a lot of what comes through it Java exploits. As far as patching and upgrading, etc. goes. Java is one of the worst fucking apps to deal with.

---

<div class="post-metadata">

**Author:** ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)\
**Post date:** [May 9, 2013, 8:52am UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/108 "2013-05-09T08:52:58Z")

</div>

Days since last Java 0day [http://java-0day.com/](http://java-0day.com/)

---

<div class="post-metadata">

**Author:** ![boardjnky4](https://avatars.discourse-cdn.com/v4/letter/b/96bed5/32.png) [@boardjnky4](https://forums.speedlife.net/u/boardjnky4)\
**Post date:** [May 9, 2013, 11:08am UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/109 "2013-05-09T11:08:16Z")

</div>

> [@LZ](#):
>
> I have played in all realms of IT I understand the suck
> 
> The proxy thing I suggested works really well from customer feed back I have been getting. They were able to review a few months of proxy logs and figure out all valid apps block everything else and this was with very large companies.
> 
> It’s honestly to the point with most companies understand being secure will cause some pain but its a necessity for a successful business. Most of the companies I work with are F500 however its trickling down to smaller companies now.

I like to think that we are a pretty large/major organization. After all, we are a top 10 hospital/health system and just had a nobel prize winner. Even still, the fallout of implementing big brother-like controls in a “University” environment (which is bullshit, because our hospitals and health system size crushes the university) is mind-boggling.

arrgghh, i’ve probably already said too much

---

<div class="post-metadata">

**Author:** ![ProgRocker](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/progrocker/32/5434_2.png) [@ProgRocker](https://forums.speedlife.net/u/ProgRocker)\
**Post date:** [May 9, 2013, 11:29am UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/110 "2013-05-09T11:29:51Z")

</div>

> [@boardjnky4](#):
>
> I like to think that we are a pretty large/major organization. After all, we are a top 10 hospital/health system and just had a nobel prize winner. Even still, the fallout of implementing big brother-like controls in a “University” environment (which is bullshit, because our hospitals and health system size crushes the university) is mind-boggling.
> 
> arrgghh, i’ve probably already said too much

In a similar environment. If you’re like my place of employment, there’s also political shit. “Oh make him full admin”, “Don’t put AV on his machine”…blah blah blah.

---

<div class="post-metadata">

**Author:** ![TradersBASE](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/tradersbase/32/5321_2.png) [@TradersBASE](https://forums.speedlife.net/u/TradersBASE)\
**Post date:** [May 9, 2013, 1:03pm UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/111 "2013-05-09T13:03:03Z")

</div>

> [@ProgRocker](#):
>
> In a similar environment. If you’re like my place of employment, there’s also political shit. “Oh make him full admin”, “Don’t put AV on his machine”…blah blah blah.

UGGGGGG. Political exemptions FTL! I wonder how many compromised networks stem from these bullshit exemptions. It always seems the people that “need admin” end up breaking shit and demand you drop everything to help them fix **their** fuckup.

---

<div class="post-metadata">

**Author:** ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)\
**Post date:** [May 10, 2013, 1:32pm UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/112 "2013-05-10T13:32:33Z")

</div>

DLP - [http://securityreactions.tumblr.com/post/50091088474/dlp](http://securityreactions.tumblr.com/post/50091088474/dlp)

---

<div class="post-metadata">

**Author:** ![boardjnky4](https://avatars.discourse-cdn.com/v4/letter/b/96bed5/32.png) [@boardjnky4](https://forums.speedlife.net/u/boardjnky4)\
**Post date:** [May 10, 2013, 1:33pm UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/113 "2013-05-10T13:33:55Z")

</div>

that is the most accurate representation of DLP that I have ever seen. I wish that a gif was printable, so that I could post that on my wall.

---

<div class="post-metadata">

**Author:** ![ProgRocker](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/progrocker/32/5434_2.png) [@ProgRocker](https://forums.speedlife.net/u/ProgRocker)\
**Post date:** [May 16, 2013, 5:28am UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/114 "2013-05-16T05:28:59Z")

</div>

Looking at deploying Google Chrome Enterprise (yes it’s seperate), it comes with some ADMX templates too. There is an option to block javascript and allow certain sites. Pretty awesome.

---

<div class="post-metadata">

**Author:** ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)\
**Post date:** [May 16, 2013, 5:39am UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/115 "2013-05-16T05:39:01Z")

</div>

Never heard of it most companies lean on internet explorer pretty hard because of legacy/other applications.

post up how it works out

---

<div class="post-metadata">

**Author:** ![boardjnky4](https://avatars.discourse-cdn.com/v4/letter/b/96bed5/32.png) [@boardjnky4](https://forums.speedlife.net/u/boardjnky4)\
**Post date:** [May 16, 2013, 5:43am UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/116 "2013-05-16T05:43:50Z")

</div>

I’ve never heard of chrome enterprise either.

---

<div class="post-metadata">

**Author:** ![ProgRocker](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/progrocker/32/5434_2.png) [@ProgRocker](https://forums.speedlife.net/u/ProgRocker)\
**Post date:** [May 16, 2013, 5:59am UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/117 "2013-05-16T05:59:56Z")

</div>

I’m pretty sure the Chrome app itself may be the same. It does come as an .msi file which typically is easier to work with in a windows environment as far as deploying goes.

> **[Google Chrome Enterprise  |  Chrome Enterprise
       | ...](https://cloud.google.com/chrome-enterprise/)**
>
> Chrome Enterprise enables IT admins to manage Chrome OS-powered devices and gain secure access to business data and apps through Chrome Browser.

I love the fact that Chrome stars settings that are pushed through Group Policy:  
 ![http://img.photobucket.com/albums/v398/Thorguitarist/pic1_zpse46f9db1.jpg~original](http://img.photobucket.com/albums/v398/Thorguitarist/pic1_zpse46f9db1.jpg~original)

Two different types of policies for Chrome…obviously by the picture, ones users can change (like the homepage) and ones they can’t  
 ![http://img.photobucket.com/albums/v398/Thorguitarist/pic2_zps7111da3b.jpg~original](http://img.photobucket.com/albums/v398/Thorguitarist/pic2_zps7111da3b.jpg~original)

Here’s a good chunk of some of the settings you can push out.

 ![http://img.photobucket.com/albums/v398/Thorguitarist/Untitled-3_zps846f2eba.jpg~original](http://img.photobucket.com/albums/v398/Thorguitarist/Untitled-3_zps846f2eba.jpg~original)

Some of the more security “intense” settings:  
 ![http://img.photobucket.com/albums/v398/Thorguitarist/Untitled-4_zps6337bed3.jpg~original](http://img.photobucket.com/albums/v398/Thorguitarist/Untitled-4_zps6337bed3.jpg~original)

Now some didn’t get applied, and I think that’s due to me having Chrome already configured on my end and not making some policies mandatory.

---

<div class="post-metadata">

**Author:** ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)\
**Post date:** [May 16, 2013, 6:08am UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/118 "2013-05-16T06:08:05Z")

</div>

Chrome is still the most secure web browser I wish more places would adopt it.

Actually Google hired the company I work for to do an independent security analysis of all the popular browsers.

> **[Cyber Security Solutions | Optiv](https://www.optiv.com)**
>
> Optiv is the most advanced, trusted partner for cyber security solutions, providing a full suite of information security services and solutions.

I still suggest taking sometime to look at EMET 4.0 Beta for desktops 🙂

> **[Introducing EMET v4 Beta](https://blogs.technet.microsoft.com/srd/2013/04/18/introducing-emet-v4-beta/)**
>
> Great news!  Today we are proud to announce a beta release of the next version of the Enhanced Mitigation Experience Toolkit (EMET) – EMET 4.0.  Download it here: http://www.microsoft.com/en-us/download/details.aspx?id=38761 EMET is a free utility...

---

<div class="post-metadata">

**Author:** ![ProgRocker](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/progrocker/32/5434_2.png) [@ProgRocker](https://forums.speedlife.net/u/ProgRocker)\
**Post date:** [May 16, 2013, 6:09am UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/119 "2013-05-16T06:09:55Z")

</div>

Agreed. Also I think it just works the best UI and feature wise. I read awhile ago that for most Java exploits, Chrome is the only browser that prompts the “Are you sure you want to run this plug-in” message.

---

<div class="post-metadata">

**Author:** ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)\
**Post date:** [May 16, 2013, 6:21am UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/120 "2013-05-16T06:21:41Z")

</div>

It depends on the version of Java/Browser now.

By default applets would auto run if they were signed…If they were not signed they would prompt.

There were a handful of Java 0day exploits that would bypass this entire process and auto run.

Now everything is supposed to prompt to execute but signed applets have a blue box vs some other color for unsigned.

 ![http://i.imgur.com/3lIgKWN.jpg](http://i.imgur.com/3lIgKWN.jpg)

It’s funny how many people select the “I accept the risk” and then click run

[Previous page](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335.md?page=5)

[Next page](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335.md?page=7)
