10 mistakes in infrastructure that hackers can exploit to steal your data.

- Firewall / incorrect network access configuration disabled
Firewalls are important tools, but the Windows Firewall, in particular, is often incorrectly configured.
- Very simple passwords and security questions
Organizations and employees almost always reuse passwords. These passwords typically include some variation of the company name and a number, such as a year or month. IT departments should monitor for the presence of such passwords and continue to provide employee security training.
- There is no network separation
Network segregation can be both a blessing and a curse. It offers greater control over what employees have access to and allows IT to set rules to restrict traffic between different subnets, reducing exposure to security incidents. However, it can also involve VLAN, security limits, and administrative overhead.
- Missing SMB signature
Organizations should do the following to avoid attacks in this area:
- Set SPNs for services to avoid NTLM
- Using Kerberos authentication
- SPN target name validation requirement
- Enable SMB signing
- Enable port filtering
- Code execution prevention (but don't forget that this attack exploits administrative accounts)
- Unusual code execution allowed
Common file formats that contain malware are .exe, .dll, .vbs, and .docm files along with PDF. On Windows machines, you can enable SafeDllSearchMode for additional protection.
- There is no whitelisting.
Code execution prevention is a must. PowerShell is a key hacking tool, so potential solutions to mitigate attacks would be to block it or use the Just Enough Administration service. Organizations can also check where users are getting white access from with accesschk.exe -w.users c: windows.
- Old protocols or protocols with default settings
SNMPv3 addresses are a user-based system for access control and a means for properly authenticating users. Organizations should also ensure that ODBC drivers have a secure networking layer built into them.
- Trusting in solutions without knowing how to break them
The best administrators will never use a service if they don't know how to break it. Almost every solution has a backdoor.
- Misuse of account management services and privileged accounts
Account password management services are located in the registry, which is available online and offline. Privileged users sometimes have more access than necessary.
- Using hipster tools
Security budgets are increasing dramatically, as is the risk of adopting shiny new tools that may not be fully vetted. Sometimes we have different types of tools that we need to trust, but most of them end up getting lost. We spend so much on various tools that may not be the best.
