19.06.2014 Views

Windows Server 2003 Recommended Baseline Security

Windows Server 2003 Recommended Baseline Security

Windows Server 2003 Recommended Baseline Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>Windows</strong> <strong>Server</strong> <strong>2003</strong><br />

<strong>Recommended</strong> <strong>Baseline</strong> <strong>Security</strong> (ITSG-20)<br />

4.7.3 Other <strong>Security</strong> Related Settings<br />

4.7.3.1 NoNameReleaseOnDemand (NetBIOS)<br />

machine\system\currentcontrolset\services\netbt\parameters\nonamereleaseondemand=4, 1<br />

The ‘nonamereleaseondemand’ value determines if a system releases its NetBIOS name upon a<br />

name-release request. The setting ‘1’ prevents a system from releasing the NetBIOS name, other<br />

than to WINS servers. This reduces information it provides to an unauthorized user.<br />

4.7.3.2 Enable the computer to stop generating 8.3 style filenames<br />

machine\system\currentcontrolset\control\filesystem\ntfsdisable8dot3namecreation=4, 1<br />

The ‘ntfsdisable8dot3namecreation’ value determines if a system will generate 8.3 file names.<br />

The setting ‘1’ prevents the 8.3 filename format. Generation of 8.3 file makes the task of name<br />

guessing easier for an attacker. Disabling this ensures only the full name is used to reference<br />

files.<br />

4.7.3.3 NoDriveTypeAutoRun<br />

machine\software\microsoft\windows\currentversion\policies\explorer\nodrivetypeautorun=4,2<br />

55<br />

The ‘nodrivetypeautorun’ value determines if autorun is enabled on connected drives. The<br />

setting ‘255’ disables autorun for all drives on the system. This ensures privileged users do not<br />

run unapproved software. Without restrictions, unapproved software may run inadvertently.<br />

4.7.3.4 The time in seconds before the screen saver grace period expires (0<br />

recommended)<br />

machine\system\software\microsoft\windowsnt\currentversion\winlogon\screensavergraceperi<br />

od=4, 0<br />

The ‘screensavergraceperiod’ value determines the amount of time (in seconds) to enforce the<br />

screen saver password. The setting ‘0’ enforces password lock with no time delay. This provides<br />

an immediate lock when the idle threshold is reached.<br />

4.7.3.5 Warning Level<br />

machine\system\currentcontrolset\services\eventlog\security\warninglevel=4, 90<br />

The ‘warninglevel’ value determines the maximum amount of security logs before a warning<br />

event is triggered. The setting ‘90’ triggers a warning when the <strong>Security</strong> log reaches 90%<br />

capacity. This will afford sufficient time to reset the log and determine reasons for the warning.<br />

<strong>Server</strong> Policy Files March 2004 101

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!