In very recent news you have likely heard of someone putting infected USB drives into mailboxes, although this is happening in Australia it is still incredibly relevant no matter where in the world you may be. It is always in good practice to never, and I mean never, plug in a random USB thumb drive you might have found out in the wild. This is one of the tried and true methods that gets malware installed on your computer because of a built-in “feature” of Windows called AutoPlay in addition to AutoRun, and also because most people will think one of two things:
- Oh, free thumb drive!
- Oh, someone might have lost this, let me see if their name or contact information is on it!
The best course of action is to just throw them away. But, in the off chance that you do put a USB thumb drive in your computer, you better hope that AutoPlay and Autorun is disabled. That is what I’m going to show you how to configure today on standalone workstations and on a domain with Group Policy.
Continue reading “Disabling AutoPlay and Autorun”
Continue reading “Force JS Files to Open in Notepad”
One of the most effective ways to protect your company and its computers is to implement the blocking of macros in Microsoft Office documents (this includes: Word, PowerPoint, Excel, Publisher, Outlook, Access, and Visio). Blocking macros is a relatively straight-forward and simple process as it can be done via Group Policy, and that is what I will be covering in this post.
Continue reading “Blocking Office 2010 Macros”
First of all, I’d like to welcome you to my blog. Obviously you’ve come here for some reason, that likely being your want or need for facts or opinions on Information Security (InfoSec). Well, you have come to the right place.
Now let me provide an introduction: My name is James Montour, I am a Systems Administrator that presently works for a financial institution. I’ve worked as a Systems Administrator officially for just about 2 years now, with miscellaneous IT work done prior. I technically have no formal IT education, with the exception of a Computer Programming certificate I received… Funnily enough, my two degrees are actually both in Video Production. Everything that I know in terms of IT, InfoSec, etc. has been self taught. Just to add some extra context to the information that I will be posting here, I run a primarily Windows dominated corporate network, with a few Linux servers for things like documentation, knowledge base, and network monitoring.
The purpose of this blog is to share my knowledge and experiences relating to creating, operating, and maintaining a Windows-based corporate network. The primary topics I will cover are security hardening, group policy, active directory management, and general best practices. If these things sound interesting to you, then you are in the right place.