Security Basics mailing list archives

RE: Secure installation of Windows XP?


From: "Crawley, Jim" <Jim.Crawley () yrbrands com>
Date: Tue, 2 May 2006 08:26:53 +1000

 
        My answer has already been given (don't connect it to the
internet or if you're really paranoid, any network until all patches, AV
& firewall are installed and configured), however I thought I'd regale
everyone with a little tale that once happened to me a few years back.

        One of my colleagues was setting up a machine to create a new
ghost image on.  Standard install, he had kicked it off then got tied up
in a few things.  The next morning I noticed a lot of virus activity on
the network.  Started searching out the machine, couldn't for the life
of me find it.  It had a name that didn't comply to our standards.  All
I could get was the network card make & model from the mac address.

        It ended up being the machine my colleague started working on.
The reason we hadn't suspected it was because the install wasn't even up
to the stage where it configures the network card.  We pushed the
install through out of curiosity, windows couldn't even load network
card drivers for it anyway yet this machine still managed to get
infected.

        Just goes to show, initial boot through to fully patched &
protected system, leave it in a standalone environment.


-----Original Message-----
From: Thomas Jespersen [mailto:front243 () stofanet dk] 
Sent: Sunday, 30 April 2006 8:16 AM
To: security-basics () securityfocus com
Subject: Secure installation of Windows XP?

Hi,

I hear stories of how a new Windows XP system is infected within
minutes. So I wonder, what is the procedure to install Windows XP in a
safe way?

PS : In case there are any other Danes on the list, I posted a similar
question on a Danish security newsgroup, but I got very conflicting
responses, so I just want to know the opinion of this list.

------------------------------------------------------------------------
-
This List Sponsored by: Webroot

Don't leave your confidential company and customer records un-protected.

Try Webroot's Spy Sweeper Enterprise(TM) for 30 days for FREE with no
obligation. See why so many companies trust Spy Sweeper Enterprise to
eradicate spyware from their networks.
FREE 30-Day Trial of Spy Sweeper Enterprise

http://www.webroot.com/forms/enterprise_lead.php
------------------------------------------------------------------------
--


-------------------------------------------------------------------------
This List Sponsored by: Webroot

Don't leave your confidential company and customer records un-protected.
Try Webroot's Spy Sweeper Enterprise(TM) for 30 days for FREE with no
obligation. See why so many companies trust Spy Sweeper Enterprise to
eradicate spyware from their networks.
FREE 30-Day Trial of Spy Sweeper Enterprise

http://www.webroot.com/forms/enterprise_lead.php
--------------------------------------------------------------------------


Current thread: