Windows Services - PowerPoint PPT Presentation

1 / 12
About This Presentation
Title:

Windows Services

Description:

Windows Services are programs that run in the background and provide some ... Messenger. Portable Media Serial Number ? Remote Registry. Secondary Logon ? Server ? ... – PowerPoint PPT presentation

Number of Views:23
Avg rating:3.0/5.0
Slides: 13
Provided by: robert390
Category:
Tags: services | windows

less

Transcript and Presenter's Notes

Title: Windows Services


1
Windows Services
  • Security Seminar
  • March 1, 2006

2
Windows Services
  • Windows Services are programs that run in the
    background and provide some functionality or
    service. They can be running even if there is no
    one logged into the machine.

3
Why do we care?
  • Unneeded services should be disabled, as they are
    just another vector that an attacker could
    potentially utilize to compromise security.
  • Administrators need to be aware of common
    services in order to spot out-of-place services.

4
Example
  • http//www.frsirt.com/english/advisories/2006/0417
  • UPnP problems (SSDP)

5
Helpful tools
  • Services snap-in
  • Autoruns (http//www.sysinternals.com)
  • Tasklist
  • sc
  • delserv

6
Enumerating Information
  • Services snap-in
  • Name
  • Status
  • Executable path and options
  • Privilege/User to execute under
  • Action to take if/when there is service failure
  • Dependencies for service

7
Automatic, Manual, Disable?
  • Automatic Starts by itself
  • Manual User can start the service
  • Program can start the service if needed
  • Disable Service cannot be started

8
Enumerating Information Cont.
  • Autoruns
  • Allows one to easily associate a service with
    its entry in the registry
  • See the permissions on a service
  • Tasklist
  • net command(s)
  • sc command

9
Simple Attacks - simplified
  • Install a service to perform some task
  • Modify existing service to perform task
  • Use existing service to elevate privileges

10
Attacks a bit more in depth
  • trick
  • Poor permissions - http//www.cs.princeton.edu/su
    dhakar/papers/winval.pdf
  • Svchost obfuscation
  • Etc.

11
Services to Disable
  • Help and Support
  • Messenger
  • Portable Media Serial Number ?
  • Remote Registry
  • Secondary Logon ?
  • Server ?
  • System Restore Service?
  • Themes
  • Wireless Zero Configuration
  • SSDP Discovery Service
  • ?

12
Resources
  • http//www.microsoft.com/technet/prodtechnol/windo
    wsserver2003/technologies/management/svrxpser_7.ms
    px
  • http//www.theeldergeek.com/services_guide.htmSer
    vices
  • http//www.sysinternals.com/
  • http//cio.uiowa.edu/itsecurity/
Write a Comment
User Comments (0)
About PowerShow.com