Running code is exploitable code – if you can interact with it you can exploit it. That’s why I disable any service that I won’t be using – prioritizing those that listen to ports (NetBIOS.) Even something innocent looking like Print Spooler can be exploited – that’s how Stuxnet elevated privileges.

So, here’s a list that works for me and it might work for you to. I suggest you look these up before disabling.

Active X Installer

Printer Spooler

Server

TCP/IP NetBios Helper

Workstation

Windows Media Player Network Sharing Service

HomeGroup Provider



blog comments powered by Disqus

Published

17 July 2012

Categories

Tags