
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 44
Administratorsgroup.WindowsNTServer, likeotheroperatingsystems,allows
privilegeduserswhoareadministratorsaccesstoallresourcesinthesystem.For
installationsthatwantenhancedsecurity,strongencryptionofaccountpassword
derivativeinformationprovidesanadditionallevelofsecuritytoprevent
Administratorsfromintentionallyorunintentionallyaccessingpasswordderivatives
usingRegistryprogramminginterfaces.
ThisfilehasbeenpostedtothefollowingInternetlocation:
ftp://ftp.microsoft.com/bussys/winnt/winntpublic/fixes/usa/nt40/hotfixespostsp2/secf
ix/”
8
Step6Strengthentheaccountandauditsettings.
ThisisthestepthatIaddtothelistbasedoninformationprovidedbythearticle
“TechnicalReference:NTServer4.0HardeningGuide”
9
.
Anidealpasswordpolicyshouldincludetheelementslistedbelow:
n Enforcepassworduniquenessbyrememberinglastpasswords6
n Minimumpasswordage:2
n Maximumpasswordage:42
n Minimumpasswordlength:10
n Complexpasswords:Enabled
n Usermustlogontochangepassword:Enabled
n AccountlockoutpolicyAccountlockoutcount:5
n LockoutaccounttimeforeverResetlockoutcountafter:720minutes
“Complexpasswords”requiresthatyoudeploypassfilt.dll,aspecialDLLfilethat
comeswiththeNTservicepacks.Belowisanextractofthedescriptionofthisfile
fromtheKBarticle161990:
“MicrosoftWindowsNT4.0ServicePack2introducesanewDLLfile(Passfilt.dll)
thatletsyouenforcestrongerpasswordrequirementsforusers.Passfilt.dllprovides
8
http://support.microsoft.com/default.aspx?scid=kb;ENUS;q143475
9
http://screamer.mobrien.com/Manuals/MPRM_group/security.htm
Comentarios a estos manuales