Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
      Digg this story   Add to del.icio.us  
FOCUS on Microsoft: Securing NT - Installing and Securing Part 4
SecurityFocus 2001-08-16

Installing and Securing Windows NT 4.0

Getting Started
Installing NT
Installing Service Packs and Hotfixes
Installing Drivers, Applications, and Services
Test the Server
Update Repair Information
Modify ACLs on Files and Directories
Create and Modify Registry Keys
Modify Registry Key ACLs
Enable Auditing
Set Account Policies
User Rights
Password Selection and Management

CAUTION: The information contained below is aimed towards securing the NT Operating System. This information represents a "high security" posture and may break or disrupt performance on your own machine. The suggestions listed on this page may not be suitable for your environment. Test all changes on a non-production host before applying them to your production machine. Security-Focus is not responsible for any damage that may result from applying these suggestions.

Modify ACLs on Files and Directories

18
Among the files and directories to be protected are those that make up the operating system software itself. Set directory permissions to all subdirectories and existing files, as shown in the following list, immediately after Windows NT is installed. Be sure to apply permissions to parent directories before applying permissions to subdirectories.

DIRECTORY

LOCAL GROUP

PERMISSIONS

C:\ (or System Drive)

Administrators:
CREATOR OWNER:
Authenticated Users:
System:

Full Control
Read
Read
Full Control

\TEMP

Administrators:
SYSTEM:
CREATOR OWNER:
Authenticated Users:

Full Control
Full Control
Full Control
Full Control

\Program Files

Administrators:
Account Operators
Backup Operators
Server Operators
CREATOR OWNER:
Authenticated Users:
SYSTEM:

Full Control
Special (All)(None)
Special (All)(None)
Special (All)(None)
Read
Read
Full Control

\Program Files\NTReskit

Administrators:
SYSTEM:

Full Control
Full Control

\WINNT

Administrators:
CREATOR OWNER:
Authenticated Users:
SYSTEM:

Full Control
Full Control
Read
Full Control

Now, within the \WINNT tree, apply the following exceptions to the general security:

DIRECTORY

LOCAL GROUP

PERMISSIONS

\WINNT\REPAIR

Administrators:
SYSTEM:

Full Control
Full Control

\WINNT\SYSTEM32\CONFIG

Administrators:
CREATOR OWNER:
Authenticated Users:
SYSTEM:

Full Control
Full Control
List
Full Control

\WINNT\SYSTEM32\SPOOL

Administrators:
CREATOR OWNER:
Authenticated Users:
System Operators:
SYSTEM:

Full Control
Full Control
Read
Change
Full Control

\WINNT\COOKIES
\WINNT\FORMS
\WINNT\HISTORY
\WINNT\OCCACHE
\WINNT\PROFILES
\WINNT\SENDTO
\WINNT\Temporary Internet Files

Administrators:
CREATOR OWNER:
Authenticated Users:
System:

Full Control
Full Control
Add
Full Control

You may wish to apply ACLS to the specific files listed below:

FILES

LOCAL GROUP

PERMISSIONS

\Boot.ini
\Ntdetect.com
\Ntldr

Administrators:
SYSTEM:

Full Control
Full Control

\Autoexec.bat
\Config.sys

Administrators:
SYSTEM:
Authenticated Users:

Full Control
Full Control
Read

Policy Editor (\winnt\poledit.exe)
Registry Editor (regedit) (\winnt\regedit.exe)
ACL Control (\winnt\system32\cacls.exe)
File Conversion (\winnt\system32\convert.exe)
DHCP Admin (\winnt\system32\dhcpadmin.exe)
Event Viewer (\winnt\system32\eventvwr.exe)
IIS Installation (\winnt\system32\inetins.exe)
User Manager (local) (\winnt\system32\musrmgr.exe)
NT Backup (\winnt\system32\ntbackup.exe)
RAS Administrator (\winnt\system32\rasadmin.exe)
Emergency Disk (\winnt\system32\rdisk.exe)
Registry Editor (regedt32) (\winnt\system32\regedt32.exe)
Remote Boot Manager (\winnt\system32\rplmgr.exe)
Server Manager (\winnt\system32\srvmgr.exe)
System Key (\winnt\system32\syskey.exe)
System Editor (\winnt\system32\sysedit.exe)
Trivial FTP (\winnt\system32\tftp.exe)
User Manager (domain) (\winnt\system32\usrmgr.exe)
Disk Administrator (\winnt\system32\windisk.exe)
WinMSD (\winnt\system32\winmsd.exe)
WINS administrator (\winnt\system32\winsadmin.exe)

Administrators:
SYSTEM:

Full Control
Full Control

Rollback.exe (may be located anywhere on hard drive)

Delete this file

<< PREVIOUS INDEX NEXT >>

Download Links

Securing Windows NT Installation
Self Extracting Word Document (75k)
Microsoft

SecurityFocus Shell Script for Securing NT
by Security Focus

Microsoft Security Advisories
Microsoft



SecurityFocus accepts Infocus article submissions from members of the security community. Articles are published based on outstanding merit and level of technical detail. Full submission guidelines can be found at http://www.securityfocus.com/static/submissions.html.
    Digg this story   Add to del.icio.us  
Comments Mode:







 

Privacy Statement
Copyright 2008, SecurityFocus