Web Security
You are offering your IP address to the entire world at this very
moment.
Make sure you are not offering access to your private data at the
same time.
YOUR IP ADDRESS IS PUBLIC
Accessing the Internet is a security risk.
When you are connected to the Internet, an IP address is used to identify your
PC. If you don't protect yourself, this IP address can be used to access your
computer from the outside world.
A fixed IP address is a larger security risk.
If you're using a modem with a dial-up connection, you will get a new IP
address every time you connect to Internet.
With an ADSL or cable connection users sometimes keep the same IP address for
several months, this represents an increased security risk.
If you have a fixed IP address, you give potential Internet crackers all the
time they need to search for entrances to your computer, and to store and share
(with other crackers) information they might find about your unprotected private data.
Your Network Shares
Personal computers are often connected to a shared network. Personal
computers in large companies are connected to large corporate networks. Personal
computers in small companies are connected to a small local network, and
computers in private homes often share a network between family members.
Most often networks are used to share resources like printers, files and disk
storage.
When you are connected to the Internet, your shared resources can be
accessed by the rest of the world.
A Common Windows Security Problem
Unfortunately, many Microsoft Windows users are unaware of a common security
leak in their network settings.
This is a common setup for network computers in Microsoft Windows:
- Client for Microsoft Networks
- File and Printer Sharing for Microsoft Networks
- NetBEUI Protocol
- Internet Protocol TCP/IP
If your setup allows NetBIOS over TCP/IP, you have a security problem:
- Your files can be shared all over the Internet
- Your logon-name, computer-name, and workgroup-name are visible to others.
If your setup allows File and Printer Sharing over TCP/IP, you also have a
problem:
- Your files can be shared all over the Internet
Computers that are not connected to any network can also have dangerous
network settings because the network settings were changed when Internet was
installed.
Solving the Problem
For Windows 2000 users:
You can solve your security problem by disabling NetBIOS over TCP/IP:
- Open Windows Explorer
- Right-click on My Network Places
- Select: Properties
- Right-click on Local Area Network
- Select: Properties
- Select: Internet Protocol TCP/IP
- Click on Properties
- Click on Advanced
- Select the WINS tab
- Select Disable NetBIOS over TCP/IP
- Click OK
If you get the message: "This connection has an empty......", ignore the message and click on YES to
continue, and click OK to close the other setup windows.
You should restart your computer after the changes.
For Windows 95, 98, or ME users:
You can solve your security problem by disabling NetBIOS over TCP/IP:
- Open Windows Explorer
- Right-click on My Network Places
- Select: Properties
- Select: Internet Protocol TCP/IP
- Click on Properties
- Select the NetBIOS tab
- Uncheck: Enable NetBIOS over TCP/IP
- Click OK
You must also disable the TCP/IP Bindings to Client for Microsoft Networks and File and Printer
Sharing:
- Open Windows Explorer
- Right-click on My Network Places
- Select: Properties
- Select: Internet Protocol TCP/IP
- Click on Properties
- Select the Bindings tab
- Uncheck: Client for Microsoft Networks
- Uncheck: File and Printer Sharing
- Click OK
If you get a message with something like: "You must select a
driver.........", ignore the message and click on YES to
continue, and click OK to close the other setup windows.
If you still want to share your Files
and Printer over the network, you must use the NetBEUI protocol instead of the
TCP/IP protocol. Make sure you have enabled it for
your local network:
- Open Windows Explorer
- Right-click on My Network Places
- Select: Properties
- Select: NetBEUI
- Click on Properties
- Select the Bindings tab
- Check: Client for Microsoft Networks
- Check: File and Printer Sharing
- Click OK
You should restart your computer after the changes.
Protect Your Server
iisPROTECT provides a complete range of password protection, authentication
and user management solutions:
iisPROTECTasp: Protect areas of your web site and require username and
password. Grant/deny any users/groups on a per resource basis. Extensive Web
Interface for user/group admin, use any DB backend, store custom data, set user
start/end dates, email users, audit logins.
iisPROTECT: Protect all web site files including images, databases,html,ASP
etc. Protect entire directories, users / groups independent from Windows accounts,
complete web administration, does not require cookies or any programming.
Complete turn key solution.
iisPROTECTquota: All of the features of iisPROTECT plus: prevent concurrent
logins and password cracking attempts, set quotas on hits, logins, kb per user.
Read more about
iisPROTECT.
Computer Joke
Customer: Will clicking on "Remember Password" help me
remember my password?
Reliable, affordable, feature-rich web hosting!
Take the uncertainty out of Web hosting and let
GoDaddy.com
put service, performance and value back in. No matter which
hosting type or plan you choose, your site receives 24/7
maintenance and protection in our world-class data center. Plus,
you get the expert, friendly service you deserve, from the
world's largest hostname provider.
With three plans to choose from and
prices starting at just $4.99 per month, GoDaddy.com is sure to have a plan that's
right-sized and right-priced just for you!
All plans feature FREE 24x7 setup, FREE 24x7 monitoring, best-
of-breed routers, firewalls and servers, 24x7 onsite physical security
and access to our exclusive Go Daddy Hosting Connection, THE place
to install over 30 FREE applications. Virtual Dedicated and Dedicated
Server plans also available.
Visit GoDaddy.com today.
Virtual Dedicated, Dedicated Server and unlimited plans also available.
Save 10% on web hosting - Enter code w3tenoff at checkout
|
|
Get Your Diploma!
W3Schools' Online Certification Program is the perfect solution for busy
professionals who need to balance work, family, and career building.
The HTML Certificate is for developers who want to document their knowledge of HTML, XHTML, and CSS.
The JavaScript Certificate is for developers who want to document their knowledge of JavaScript and the HTML DOM.
The XML Certificate is for developers who want to document their knowledge of XML, XML DOM and XSLT.
The ASP Certificate is for developers who want to document their knowledge of ASP, SQL, and ADO.
The PHP Certificate is for developers who want to document their knowledge of PHP and SQL (MySQL).
|
|