19.06.2014 Views

Windows Server 2003 Recommended Baseline Security

Windows Server 2003 Recommended Baseline Security

Windows Server 2003 Recommended Baseline Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Unclassified ITSG for <strong>Windows</strong> <strong>Server</strong> <strong>2003</strong><br />

4.4.3.41 Network access: Do not allow anonymous enumeration of SAM accounts<br />

machine\system\currentcontrolset\control\lsa\restrictanonymoussam=4, 1<br />

The ‘restrictanonymoussam’ registry value determines if anonymous enumeration of SAM<br />

accounts is permitted. The setting ‘1’disallows anonymous enumeration of SAM accounts. The<br />

enumeration maps account names to a corresponding SID. When the SID is known, local Guest<br />

and Administrator accounts are exposed. Once identified, they are open to password guessing<br />

attacks.<br />

4.4.3.42 Network access: Do not allow anonymous enumeration of SAM accounts and<br />

shares<br />

machine\system\currentcontrolset\control\lsa\restrictanonymous=4, 1<br />

The ‘restrictanonymous’ registry value determines if anonymous enumeration of SAM accounts<br />

and shares is permitted. The setting ‘1’ disallows anonymous enumeration of SAM accounts and<br />

shares. The enumeration maps account names to a corresponding SID. When the SID is known,<br />

local Guest and Administrator accounts are exposed. Once identified, they are open to password<br />

guessing attacks.<br />

4.4.3.43 Network access: Do not allow storage of credentials or .NET Passports for<br />

network authentication<br />

machine\system\currentcontrolset\control\lsa\disabledomaincreds=4, 1<br />

The ‘disabledomaincreds’ registry value determines if passwords, credentials or Microsoft .NET<br />

passports are saved after initial domain authentication. The setting ‘1’ does not perform the save.<br />

4.4.3.44 Network access: Let Everyone permissions apply to anonymous users<br />

machine\system\currentcontrolset\control\lsa\everyoneincludesanonymous=4, 0<br />

The ‘everyoneincludesanonymous’ value determines what additional permissions are granted for<br />

anonymous connections to a computer. The setting ‘0’ grants no additional permissions to<br />

anonymous users. This ensures unauthenticated users do not inherit the rights of the ‘everyone’<br />

group.<br />

4.4.3.45 Network access: Named Pipes that can be accessed anonymously<br />

machine\system\currentcontrolset\services\lanmanserver\parameters\nullsessionpipes=7,<br />

The ‘nullsessionpipes’ value defines anonymous access to named pipes. The empty setting<br />

disallows anonymous access to named pipes. This ensures all system access is authorized.<br />

64 March 2004 <strong>Server</strong> Policy Files

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!