Firewall Wizards mailing list archives

Re: Newspaper Article about Cable Modem security


From: Frederick M Avolio <fred () avolio com>
Date: Thu, 28 Oct 1999 18:58:49 -0400

At 08:09 AM 10/28/99 -0700, Neil Ratzlaff wrote:
My uneducated impression is that cable modems are much like an unswitched,
unfiltered LAN, and therefore subject to the perils mentioned in that
article.
I think a little bit of Fear might prompt users to protect themselves  --
sort
of like the early days of spam.  I try to avoid M$Windows, but if they do
share
by default, users really are wide open.  ... So can someone please tell me
what is incorrect or misleading in this article?

Nothing really is misleading, except that Windows 98 does NOT come up with file and print sharing out of the box. Some people do set up systems this way at home, on home networks. In a 2 PC network it makes sharing so very easy. Then they get cable and forget to change their settings (default workgroup named "Workgroup," no passwords, etc. Of course, network neighborhood will show your machine even if it is locked down... kind of like ruptime information.

The vulnerability is real. I was at The Internet Security Conference and stayed at the Seaport Hotel. The Seaport has a LAN with connectivity to the Internet. I plugged in... got an address... and immediately clicked on Network Neighborhood. :-) I'm sure none of those machines I saw and the NT domains I saw were wide open. But they were all there. I could have targeted particular vendors (since they used their company name as their domain name and it stayed with the mobile PC).



Fred
Avolio Consulting
16228 Frederick Road, PO Box 609, Lisbon, MD 21765, US
+1 410-309-6910 (voice) +1 410-309-6911 (fax)
http://www.avolio.com/



Current thread: