How to solve the impact of hacker attacks

Source: Internet
Author: User

Here is an example:

The website of the US security think tank Stratfor Global Intelligence has been attacked by hackers in the past week. On Thursday evening, a hacker posted a large amount of user data on the website. The data published by hackers include 75 thousand name, address, credit card number, and password, and the data comes from all customers who have paid for the Stratfor service. Other data includes the 0.86 million user names, email addresses, and passwords that have registered the website.

The attack was initiated by Anonymous, a member of the hacker group. This attack left Stratfor in an embarrassing situation because security issues are the main research area of the think tank. Anonymous earlier announced 50 thousand credit card numbers from Stratfor customers.

In the future, Anonymous may publish more data on the Stratfor website. On Monday, Anonymous spokesman Barrett Brown said the real target of the attack was to publish 3.3 million emails from Stratfor employees to intelligence sources and customers.

Anonymous has not published these emails. Therefore, Stratfor cannot determine whether the worst case has passed, and the organization is trying to solve the impact of this hacker attack.

The Stratfor website was cracked last Saturday when hackers left their own information on the website. On Twitter, hackers said they have obtained sensitive customer information and emails from the company because the information is not encrypted. Stratfor subsequently published the event on Facebook and YouTube and provided paid users with information protection measures.

As mentioned above, how can we solve the impact of hacker attacks? Let's talk about:

1. Cancel folder hiding sharing open registration editor and go

HKEY-LOCAL-MACHINE \ SYSTEM \ CurrentControlset \ Sevices \ Lanmanworkstation \ parameters, create a dual-byte value named auto‑wks, set it to 0, and then restart the computer, in this way, the sharing is canceled.

Ii. Reject malicious code

(1) Run IE and click "tools/Internet Options/security/Custom Level" to define the security level as "Security Level-high ", set "Disable" for 2nd and 3 times in "ActiveX controls and plug-ins", set "prompt" for other items, and click "OK, when you use IE to browse the Web page, it can effectively avoid code attacks in malicious web pages.

(2) disable the Guest account. It is best to set a password for it.

Click "start", click "Control Panel" in "Settings", click "User Account", click "Guest", and select "disable Guest account". OK is complete.

(3) Disable null connection. The first method is to modify the registry: open the Registry HKEY-LOCAL-MACHINE \ SYSTEM \ CurrentControlSet \ Control \ Lsa and change the key value of DWORD Value RestrictAnonymous to 1.

3. You can simply hide the IP address and proxy will be available at the top and bottom of the URL,However, the agent's network speed will be slow. If you prefer to access the Internet, it is best not to act as a proxy, affecting the speed. I will not demonstrate it here.

4. Prevent Trojans
Delete all the suspicious programs prefixed with "Run" under "HKEY-LOCAL-MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run" in the registry, you can see in "data" where they are installed on the computer and delete useless items. I have rising here.

5. Do not return emails from strangers

Set IE Security.

This step must be done well. If your Internet is not good, it will be easier to get up and running. If you do not have my computer in this step, you can do it as follows: activeX controls and Applets have strong functions, but there are also hidden dangers of exploitation. Malicious Code on webpages is usually a small program written using these controls, as long as the web page is opened, it will run. Therefore, to avoid malicious web page attacks, we only need to prohibit the running of these malicious code. IE provides many options for this. The specific setting steps are: "Tools"> "Internet Options"> "Custom Level". We recommend that you disable ActiveX control and related options.

In addition, in the security settings of IE, we can only set "Internet, local Internet, trusted sites, restricted sites". However, microsoft hides the Security Settings of "My Computer" here. By modifying the Registry to enable this option, we can have more options when dealing with ActiveX controls and Applets, it also has a greater impact on the security of local computers.

If you do not have a "my computer" chart, the following is a specific method: click "Start Menu", enter "regedit.exe" in the pop-up dialog box, open the Registry Editor, click "+", and expand: HKEY-CURRENT-USER \ Software \ Microsoft \ Windows \ CurrentVersion \ InternetSettings \ Zones \ 0, find the "DWORD" value "Flags" in the right window ", the default key value is hex 21 (decimal 33). Double-click "flags". In the displayed dialog box, change the key value to "1" to close the registry editor, open IE, click "Tools"> "Internet Options"> "security", and you will see an additional "my computer, here you can set his security level and set its security level to a higher level, so that the prevention is better. On the contrary, change to 21 and then go back. Haha No

Vi. Specific audit policy methods:

Console> Administrative Tools> Local Security Policy> Audit Policy, right-click the following items, and select security.

Audit Policy Change: Successful, failed; Audit Logon Time: Successful, failed; Audit Object Access: failed; Audit Object Tracking: Successful, failed; Audit Directory Service Access: failed; audit privilege usage: failed; Audit System Events: Successful, failed; Audit Account Logon Events: Successful, failed; Audit Account Management: Successful, failed.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.