PPRuNe Forums - View Single Post - Protecting the computer from viruses
View Single Post
Old 5th June 2006 | 09:44
  #32 (permalink)  
Mac the Knife

Plastic PPRuNer
25 Anniversary
 
Joined: Sep 2000
Posts: 1,902
Likes: 0
From: Rochechouart, France
Originally Posted by Saab Dastard
And yes, I know you call it root, or SU
Actually no. One of the first things I do on a Windows machine is to change the name of the "root" account from Administrator to something else.

Note for anyone who doesn't know, the "root" account in Windows is given the default name of Administrator, but you can change this to anything you like - this is a good security practice, since if you know the name of an account and can always count on there being one called Administrator then you're halfway to getting in. And many Administrator accounts have a blank password or something trivial like "admin". Theoretically Windows disallows network logons to the Administrator account if the password is blank but in practice it doesn't always seem to!

This of course leads to a cruel honey-trap!

1) Change to name of the root account from Administrator to something else.
2) Create a new, VERY limited account with the name of Administrator (since there is no longer an account called Administrator you are allowed to do this).
3) Either leave the PW blank on this new account or set it to something silly like "admin" that is easily guessed.
4) Monitor login attempts for this account with a tripwire since they'll all be hack attempts.

This is hilarious, as hackers login as Administrator, laugh at you and congratulate themselves, but then find out that they can't do anything

[To change the name of Administrator, run the Group Policy editor and go to Local Computer Policy/Computer Configuration/Windows Settings/Security Settings/Local Policies/Security Options and there it is: Rename administrator account]
Mac the Knife is offline