Sunday, January 14, 2007

Connecting unpatched system to the internet

Did you know, if you fresh install windows XP or you bring a computer with preinstalled windows XP (doesn't hold for windows XP with SP2 integrated) from the store and you connect it to the internet, it will most likely be infected in just a couple of minutes, even though you won't even touch the keyboard or the mouse!

Why? A lot has been written about that:
http://news.com.com/Study:+Unpatched+PCs+compromised+in+20+minutes/2100-7349_3-5313402.html

http://aroundcny.com/technofile/texts/tec082904.html
http://www.techworld.com/security/news/index.cfm?NewsID=5535

How to defend yourself? Read the great tutorial from the sans's institute:
http://www.sans.org/reading_room/whitepapers/windows/1298.php (PDF file, 1,18 MByte)


Windows XP SP2 turned on the firewall by default, so it eliminated that problem. But you can still see users installing windows XP with SP1 after the infection, and wondering, why are they being infected again. And they surely believe the Windows Update is just another Microsoft invention, so they could spy on them using pirated version of windows.

No comments: