WebCCTV Installation Manual
66
Version 4.3 Series
6.2.1
6.2
Security policy
At the start of this section, let’s reiterate the basic premise of the WebCCTV security policy:
We will lock down WebCCTV as much as possible, leaving as few places as possible where
an attack could occur, and securing the remaining places as much as possible.
“Locking down” the machine means that we will try to prevent malicious attacks on
WebCCTV by not giving attackers (hackers, viruses, etc) the possibility to exploit weaknesses
in the system.
WebCCTV uses the Microsoft Windows XP Embedded operating system. Like any other
operating system including Linux and other Unix variants – or any software for that matter –
this operating system is not perfect. It contains certain weaknesses that could be used to get
unauthorized access to the machine.
Generally speaking, Windows XP (Embedded) is a very safe operating system when
administered correctly. There are several ways outlined in this section to increase security.
Have secure passwords.
Leave WebCCTV in operator mode as much as possible.
Keep the system up to date via Windows Update.
Secure the network access.
Make sure that any other access doesn’t cause problems.
Contrary to popular belief, most attacks on computer systems are not brute-force attacks by
extremely skilled people on a weak operating system. Instead, most attacks exploit
vulnerabilities that were created “from the inside”. This implies that you have control over the
situation and can prevent attacks by rigorously securing the machine and being careful when
handling it. In the next paragraphs, you can find out how to do this.
Password policy
The very first thing that you should do when unpacking WebCCTV, is to
change the Administrator password!
The default password for Administrator account on new WebCCTV units is “webcctvnvr” and
for Operator is “quadrox” (lower case letters).
Default passwords should be changed as soon as possible, preferably even before WebCCTV
is put on the network. Otherwise attackers can gain access to the system using easily
retrievable passwords. It’s like locking the door, but leaving the key in the lock.
To avoid passwords leaking out of the organization or being retrieved otherwise, follow these
guidelines:
Publish passwords to as few people as possible. The fewer people knowing the
password, the less chance of it ending up in the wrong hands.
Содержание WebCCTV
Страница 1: ...WebCCTV Installation Manual Let s make things safer...
Страница 83: ...WebCCTV Installation Manual 83 Version 4 3 Series 8 Appendices...
Страница 87: ...WebCCTV Installation Manual 87 Appendix C Version 4 3 Series...
Страница 88: ...WebCCTV Installation Manual 88 Version 4 3 Series...
Страница 89: ...WebCCTV Installation Manual 89 Version 4 3 Series...
Страница 90: ...WebCCTV Installation Manual 90 Version 4 3 Series...