Security configurations, may 2015

Trolleri

New member
Local time
7:59 PM
Messages
6
What are your up-to-date ideas on how to secure a clean install of Windows 7 the most? :devil:

Discussion 1 - Internal configurations:
Besides constantly updating the system, using a regular user account instead of an administrator account for everyday use, setting UAC settings to maximum, and securing the web browser (https://www.us-cert.gov/publications/securing-your-web-browser#Mozilla_Firefox), do you recommend a "fsutil behavior set encryptpagingfile 1" or maybe use BitLocker to encrypt the whole system drive entirely. Any other ideas on how to secure the system?

Discussion 2 - Third party security programs:
What programs and add-ons do you recommend? Will a local antivirus program ever be as good as virustotal.com or metascan-online.com? I believe the real security is in a proactive element. Comodo Internet Security is a good choice, and free (Results and comments - www.matousec.com). Regarding Firefox, I am a fan of Ghostery as well as Adblock Plus add-ons, but is it worth to install the NoScript add-on as well? In Windows firewall, is it worth to block all incoming connections, including those in the list of allowed programs, or should I simply use the firewall Comodo supplies?

My intentions for the system is all-round use, and I will be using Redo to make complete images of the system drive. While I try to keep the number of installed programs at a minimum, Secunia PSI counts around 50 programs currently installed on my system.
 

My Computer

Computer type
Laptop
OS
Windows 7 Professional

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom assembled by me :}
OS
Win-7-Pro64bit 7-H-Prem-64bit
CPU
i7-5930K 2nd i9-9940x both water blocked VRM's too
Motherboard
ASUS SABERTOOTH X99 2nd ASUS x299 Apex
Memory
Trident-z 3200C14 2nd Trident-z 3600C16
Graphics Card(s)
EVGA 1080ti ftw3 2nd Titan Xp both water blocked
Sound Card
Built-in Realtek
Monitor(s) Displays
1-AOC G2460PG 24"G-Sync 144Hz/ 2nd 1-ASUS VG248QE 24" 144Hz
Screen Resolution
1920 x 1080 144Hz
Hard Drives
2-Samsung M.2 Evo & Evo Plus
2-Samsung 850 EVO 500GB SSD's/ 3-2.5 W.D. Black 1tb-&3-1tb/3-3.5 WD Black 1tb hdd's
PSU
EVGA SuperNOVA 1000-P2 2nd 1200-P2
Case
2-Corsair Obsidian Series 450D Black ATX Mid Tower
Cooling
Custom water loops
Keyboard
Logitech G710+/ 2nd Logitech G910
Mouse
2-RedDragon M901 Perdition 16400 dpi Gaming mouse = wired
Internet Speed
Comcast Ping 19ms 89.31mbps download speed 6.12mbps upload
Antivirus
Malwarebytes Pro/ Superantispyware Pro
Browser
FireFox & Pale moon
Other Info
2nd ASUS X299 Apex/Intel i9-9940x with Custom water loop/7H-Prem-x64/Corsair 450D case/Ram Trident-z 3600C16 4x8gb / Samsung970Evo plus 500gb SSD/Dual ssd EZ swap evo/PSU EVGA SuperNova 1200w-P2 80+Platinum/GPU Titan Xp /8-ML-140 on push-pull on 2-280GTX rads
Thanks for the link about anti-virus. Instead of waiting for any suite to be able to detect the malware once the damage is done, I am however more interested in how to secure the system itself, and avoid malware in the first place. Maybe Windows 7 have some hidden functions to tighten the security?
 

My Computer

Computer type
Laptop
OS
Windows 7 Professional
Hi,
Read the thread it's a rabbit hole of information don't let the title throw you off,
Start at the end if you wish :)
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom assembled by me :}
OS
Win-7-Pro64bit 7-H-Prem-64bit
CPU
i7-5930K 2nd i9-9940x both water blocked VRM's too
Motherboard
ASUS SABERTOOTH X99 2nd ASUS x299 Apex
Memory
Trident-z 3200C14 2nd Trident-z 3600C16
Graphics Card(s)
EVGA 1080ti ftw3 2nd Titan Xp both water blocked
Sound Card
Built-in Realtek
Monitor(s) Displays
1-AOC G2460PG 24"G-Sync 144Hz/ 2nd 1-ASUS VG248QE 24" 144Hz
Screen Resolution
1920 x 1080 144Hz
Hard Drives
2-Samsung M.2 Evo & Evo Plus
2-Samsung 850 EVO 500GB SSD's/ 3-2.5 W.D. Black 1tb-&3-1tb/3-3.5 WD Black 1tb hdd's
PSU
EVGA SuperNOVA 1000-P2 2nd 1200-P2
Case
2-Corsair Obsidian Series 450D Black ATX Mid Tower
Cooling
Custom water loops
Keyboard
Logitech G710+/ 2nd Logitech G910
Mouse
2-RedDragon M901 Perdition 16400 dpi Gaming mouse = wired
Internet Speed
Comcast Ping 19ms 89.31mbps download speed 6.12mbps upload
Antivirus
Malwarebytes Pro/ Superantispyware Pro
Browser
FireFox & Pale moon
Other Info
2nd ASUS X299 Apex/Intel i9-9940x with Custom water loop/7H-Prem-x64/Corsair 450D case/Ram Trident-z 3600C16 4x8gb / Samsung970Evo plus 500gb SSD/Dual ssd EZ swap evo/PSU EVGA SuperNova 1200w-P2 80+Platinum/GPU Titan Xp /8-ML-140 on push-pull on 2-280GTX rads
I am however more interested in how to secure the system itself, and avoid malware in the first place. Maybe Windows 7 have some hidden functions to tighten the security?
In Win 7 Pro you have SRP(Software Restriction Policies) that is a great protection! Read this: http://www.sevenforums.com/system-security/359832-best-protection-against-malware.html

Encrypting page file, sure, I've done that. And disabled hibernate.

Bitlocker or other full drive encryptions are mainly to protect against physical theft of the PC. For a home PC that's maybe not that important. But why not?
I use a fingerprint boot program + encryption of certain folders with the Windows built-in EFS.

About NoScript, it has an option to allow Scripts globally, which is followed by the word "(dangerous)". That dangerous mode is the default mode in all popular browsers. It's not named dangerous for nothing.
And since FF also doesn't have any sandbox I run it with Sandboxie.

I think Ghostery does a great job together with NoScript so I have no need for an adblocker.

What else? An anti-exploit like EMET, MBAE(Malwarebytes) or HitmanPro.Alert 3

You shouldn't trust any anti-virus product too much. Nor Virustotal. Use good, multiple and different security layers. For example as mentioned above ;)
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
HP Elitebook 8540p
OS
Windows 7 Pro 32
CPU
Intel(R) Core(TM) i5 CPU M 540 @ 2.53GHz
Motherboard
Hewlett-Packard 1521
Memory
4,00 GB (Usable 2,98)
Graphics Card(s)
NVIDIA NVS 5100M
Sound Card
NVIDIA High Definition Audio
Screen Resolution
1600x900
Hard Drives
INTEL SSDSA2CW120G3
Antivirus
F-Secure Internet Security
Browser
IE, Firefox, Opera
Other Info
Sandboxie,
SRP (Software Restriction Policy),
EMET (Enhanced Mitigation Experience Toolkit),
WFC (Windows Firewall Control by BiniSoft),
Malwarebytes Premium
Thank you for your great suggestions Tookeri. I will look a bit into Software Restriction Policies :)
 

My Computer

Computer type
Laptop
OS
Windows 7 Professional
If you don't want to waste many hours of your time, do this:
1. Keep your system partition small, and image it.
2. Back up important data to an external hard drive, then unplug it.
3. Don't buy anti-virus software. Just use MSE.
4. If ANYTHING seems unusual or suspicious about how your computer is acting - restore your image.

Takes 5 minutes.
 

My Computer

Computer Manufacturer/Model Number
Home Built
OS
Windows 7 Ultimate x64
CPU
QuadCore Intel Core i7 920, 2666 MHz (20 x 133)
Motherboard
Asus P6T
Memory
6134 MB (DDR3-1333 DDR3 SDRAM)
Graphics Card(s)
(2 - SLI) NVIDIA GeForce GTS 250 (1024 MB)
Sound Card
Onboard Realtek ALC888/1200 @ Intel 82801JB IC
Monitor(s) Displays
HDMII
Screen Resolution
1280 x 800
Hard Drives
Crucial M4 (64 GB SSD)
WD Caviar Blacks
WD5001AALS-00J7B1 ATA Device (465 GB)
WD5001AALS-00J7B1 ATA Device (465 GB)
WD5001AALS-00L3B2 ATA Device (465 GB)
WD Elements USB External (250 GB)
PSU
Corsair 550
Case
iStarUSA S-10000BL Black
Yes, I will do harddrive imaging with Redo, which can recover the system partition even if Windows cannot boot.

I also decided to try Epic Browser, since Firefox is not sandboxed, and Epic supports the only plugins I use. Epic have Adblock Plus included in the browser itself, and is accessed through the umbrella icon.
 

My Computer

Computer type
Laptop
OS
Windows 7 Professional
I think Epic is more about privacy so still no sandbox I assume.

I use Firefox with private browsing mode always on, and I've made these tweaks(mostly privacy related). Click button to view.
 
browser.cache.disk.enable = false
browser.cache.disk_cache_ssl = false
browser.cache.memory.enable = false
browser.cache.offline.enable = false
browser.safebrowsing.enabled = false
browser.safebrowsing.malware.enabled = false
browser.sessionstore.privacy_level = 2 (default=0)
browser.urlbar.trimURL = false
datareporting.healthreport.uploadEnabled = false
dom.battery.enabled = false // fingerprinting
dom.event.clipboardevents.enabled = false
dom.indexedDB.enabled = false
dom.network.enabled = false // fingerprinting
dom.storage.enabled = false
geo.enabled = false
geo.wifi.uri = localhost
media.peerconnection.enabled = false //WebRTC
network.cookie.cookieBehavior = 1 (no 3rd party)
network.dns.disablePrefetch = true
network.http.sendRefererHeader = 0 (default=2)
network.http.sendSecureXSiteReferrer = false
network.predictor.enabled = false //prefetch
network.prefetch-next = false
webgl.disabled = true (or in NoScript)


Another great thing with Firefox + Sandboxie is that I disable all plugins. If I need to enable one when run through Sandboxie it means it's only temporary. When I close the sandboxed browser and it deletes the sandbox contents all changes are discarded. So next time I open the browser all plugins remain disabled. Plugins are high risk objects when it comes to exploits.

And NoScript doesn't just block scripts, but also plugins and attempts to access local resources like your router etc.
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
HP Elitebook 8540p
OS
Windows 7 Pro 32
CPU
Intel(R) Core(TM) i5 CPU M 540 @ 2.53GHz
Motherboard
Hewlett-Packard 1521
Memory
4,00 GB (Usable 2,98)
Graphics Card(s)
NVIDIA NVS 5100M
Sound Card
NVIDIA High Definition Audio
Screen Resolution
1600x900
Hard Drives
INTEL SSDSA2CW120G3
Antivirus
F-Secure Internet Security
Browser
IE, Firefox, Opera
Other Info
Sandboxie,
SRP (Software Restriction Policy),
EMET (Enhanced Mitigation Experience Toolkit),
WFC (Windows Firewall Control by BiniSoft),
Malwarebytes Premium
Ok. My mistake, I'm always thinking of Firefox when it comes to browsers ;)

You can use Sandboxie for free, no problem! It shows a 5 second window once every day. And some blocked features. But no important ones, at least not for me.
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
HP Elitebook 8540p
OS
Windows 7 Pro 32
CPU
Intel(R) Core(TM) i5 CPU M 540 @ 2.53GHz
Motherboard
Hewlett-Packard 1521
Memory
4,00 GB (Usable 2,98)
Graphics Card(s)
NVIDIA NVS 5100M
Sound Card
NVIDIA High Definition Audio
Screen Resolution
1600x900
Hard Drives
INTEL SSDSA2CW120G3
Antivirus
F-Secure Internet Security
Browser
IE, Firefox, Opera
Other Info
Sandboxie,
SRP (Software Restriction Policy),
EMET (Enhanced Mitigation Experience Toolkit),
WFC (Windows Firewall Control by BiniSoft),
Malwarebytes Premium
Back
Top