Re: TCP/IP and Viruses

From: Robert Moir (bofh_at_mvps.org)
Date: 10/17/04


Date: Sun, 17 Oct 2004 22:48:16 +0100

scott wrote:
> so if the ip, subnet are correct, but the gateway and dns ip's are
> wrong, a pc is still at risk?
>
> i don't understand how a pc can be at risk if it can't connect to
> internet.

- if the internet (or any compromised host on an internal network) can
connect to it then its at risk. The best you can hope for from a
misconfigured host is that it subsequently is unable to route traffic and
hence can't spread the rot any further.

> if this is true, how can a user setup a pc and get virus software on
> it without taking a risk?

By hopefully not connecting to an unprotected network without first
installing protection.

> what i mean is there will always be some
> time between setup and anti-virus install from the domain controller
> on the network.

If you've got a domain controller on the network then hopefully you've also
got a firewall or a router performing NAT at least or some other kind of
filtering going on too. And you can make critical patches and security
related configuration changes part of your baseline install.

-- 
-- 
Rob Moir, Microsoft MVP for servers & security
Website - http://www.robertmoir.co.uk
Virtual PC 2004 FAQ - http://www.robertmoir.co.uk/win/VirtualPC2004FAQ.html
Kazaa - Software update services for your Viruses and Spyware.


Relevant Pages

  • Re: Is VMS losing the Financial Sector, also?
    ... the web from the server. ... I suggested using only localhost or a private network but, ... In the Army we call that Risk Management and it can be applied to ... I was talking about business laptops that are locked down. ...
    (comp.os.vms)
  • Re: Security Risk?
    ... You're allowing him physical access to your lan...what do you think the risk ... Put a multiport router in front of you internet connection...connect him/her ... > network domain will he pose a security risk to our network if he were to ...
    (microsoft.public.windows.server.sbs)
  • Re: Risk Ranking...
    ... get his book The Tao of Network Security Monitoring. ... I had the same problem as you when I was trying to come up with some risk ... The vulnerability must be exploited locally. ... If a piece of malware is a blended threat (able to exploit multiple ...
    (Security-Basics)
  • RE: Risks associated to branch office IPSec devices
    ... with malware on it from the internet, ... We saw an ENTIRE STATE network do this. ... I have just come across a doubt about branch office VPN devices. ... if this really represents a risk: ...
    (Pen-Test)
  • Re: IPMSG.EXE
    ... > based network messeging program ipmsg.exe downloaded from some site.I ... If you have a large number of users who are circumventing a security policy, ... "keep doing this and you risk being fired". ...
    (microsoft.public.security)