19.06.2014 Views

Windows Server 2003 Recommended Baseline Security

Windows Server 2003 Recommended Baseline Security

Windows Server 2003 Recommended Baseline Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>Windows</strong> <strong>Server</strong> <strong>2003</strong><br />

<strong>Recommended</strong> <strong>Baseline</strong> <strong>Security</strong> (ITSG-20)<br />

4.4.3.3 Accounts: Limit local account use of blank passwords to console logon only<br />

machine\system\currentcontrolset\control\lsa\limitblankpassworduse=4, 1<br />

The ‘limitblankpassworduse’ registry value determines if local accounts with blank passwords<br />

can be used to logon remotely. The setting ‘1’ disallows accounts with blank passwords to logon<br />

remotely. This ensures remote access requires an account name and password.<br />

4.4.3.4 Accounts: Rename administrator account<br />

NewAdministratorName = "johnsmith"<br />

The ‘NewAdministratorName’ keyword sets the local administrator account name. The setting<br />

‘johnsmith’ renames the local administrator account to johnsmith. Renaming the local<br />

administrator account makes it difficult for an attacker to misuse it.<br />

NOTE:<br />

This keyword should be omitted if a policy to rename the Administrator account on<br />

each system is enforced. If not, then at a minimum change it from ‘johnsmith’ to a<br />

local value.<br />

4.4.3.5 Accounts: Rename guest account<br />

NewGuestName = "janesmith"<br />

The ‘NewGuestName’ keyword sets the local guest account name. The setting ‘janesmith’<br />

renames the local guest account to janesmith. Renaming the account makes it more difficult for<br />

an attacker to misuse it.<br />

NOTE:<br />

This keyword should be omitted if a policy to rename the Guest account on each<br />

system is enforced. If not, then at a minimum change it from ‘janesmith’ to a local<br />

value.<br />

4.4.3.6 Audit: Audit the access of global system objects<br />

machine\system\currentcontrolset\control\lsa\auditbaseobjects=4, 0<br />

The ‘auditbaseobjects’ registry setting determines if access to global system objects is audited.<br />

The setting ‘0’ disables audit access to global objects.<br />

4.4.3.7 Audit: Audit the use of Backup and Restore privilege<br />

machine\system\currentcontrolset\control\lsa\fullprivilegeauditing=3, 0<br />

The ‘fullprivilegeauditing’ determines if the system will audit the Backup and Restore privilege.<br />

The setting ‘0’ disables the audit of Backup and Restore privilege.<br />

<strong>Server</strong> Policy Files March 2004 57

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!