Impact of Bad User Practices on Information Security - An Empirical Study in the Microsoft Windows Ecosystem
摘要
Disabled security mechanisms in Windows 7, 10, and 11 operating systems increase the risk of cyber-attacks. The massive use of this operating system, the evolution of software, and its costs have encouraged the widespread use of pirated software, exposing users to security risks due to malware. Although Microsoft has strengthened security during its releases, intentionally turning off antivirus and firewalls, for example, leaves systems vulnerable. This study aims to measure the impact caused by poor cybersecurity practices by Microsoft Windows users. We implemented a platform based on Kali Linux and programmed algorithms in Shell Scripts to achieve this. We used Metasploit as an exploit development tool to exploit known vulnerabilities in Windows for the SMB protocol. We also use Villain to generate a backdoor in Windows 10 using controlled virtual environments. The results reveal how turning off the firewall or antivirus compromises and exposes user privacy. Likewise, this study urges us to refrain from running untrustworthy code and raise user awareness about the dangers of pirated software.